Regulatory Timeline
Key dates in Australia's critical infrastructure cyber security regulatory landscape.
-
SOCI Act receives Royal Assent
Security of Critical Infrastructure Act 2018 established the Register of Critical Infrastructure Assets and initial positive security obligations.
Regulation -
SLACIP Act commences
Security Legislation Amendment (Critical Infrastructure Protection) Act 2022 expanded SOCI to 11 sectors, introduced CIRMP obligations, and established government assistance powers.
Regulation -
CIRMP Rules 2023 commence
Critical Infrastructure Risk Management Program Rules prescribe the minimum requirements for CIRMPs, including the all-hazards approach and specific hazard vectors.
Regulation -
First CIRMP annual reports due
Responsible entities must submit their first annual report to the relevant Commonwealth regulator on the status of their CIRMP.
Reporting #all -
CIRMPs must be reviewed and updated
All CIRMPs must have been reviewed and updated at least once within the first 12 months, with evidence of board or governing body approval.
Regulation #all -
TSRMP Rules 2025 commence
Telecommunications Sector Risk Management Program Rules 2025 create additional obligations for responsible entities operating critical telecommunications assets, above CIRMP requirements.
Regulation #telecommunications -
Third CIRMP annual reports due
Third cycle of annual reporting. Regulators expected to increase scrutiny on operating effectiveness, not just design.
Reporting #all -
AESCSF 2025 assessment cycle opens
Energy sector entities begin self-assessments under the updated AESCSF framework. ML1 capability areas remain the baseline.
Framework #energy -
First TSRMP annual reports due
Telecommunications responsible entities must submit their first annual report under the TSRMP Rules to the ACMA.
Reporting #telecommunications -
Enhanced cyber security obligations review
Scheduled parliamentary review of the enhanced cyber security framework provisions, including the effectiveness of Systems of National Significance declarations.
Regulation - Next upcoming
Fourth CIRMP annual reports due
Fourth cycle. Enforcement actions expected for entities that have not demonstrated material improvement in risk management maturity.
Enforcement #all