Skip to main content

Regulatory Timeline

Key dates in Australia's critical infrastructure cyber security regulatory landscape.

  1. SOCI Act receives Royal Assent

    Security of Critical Infrastructure Act 2018 established the Register of Critical Infrastructure Assets and initial positive security obligations.

    Regulation
  2. SLACIP Act commences

    Security Legislation Amendment (Critical Infrastructure Protection) Act 2022 expanded SOCI to 11 sectors, introduced CIRMP obligations, and established government assistance powers.

    Regulation
  3. CIRMP Rules 2023 commence

    Critical Infrastructure Risk Management Program Rules prescribe the minimum requirements for CIRMPs, including the all-hazards approach and specific hazard vectors.

    Regulation
  4. First CIRMP annual reports due

    Responsible entities must submit their first annual report to the relevant Commonwealth regulator on the status of their CIRMP.

    Reporting #all
  5. CIRMPs must be reviewed and updated

    All CIRMPs must have been reviewed and updated at least once within the first 12 months, with evidence of board or governing body approval.

    Regulation #all
  6. TSRMP Rules 2025 commence

    Telecommunications Sector Risk Management Program Rules 2025 create additional obligations for responsible entities operating critical telecommunications assets, above CIRMP requirements.

    Regulation #telecommunications
  7. Third CIRMP annual reports due

    Third cycle of annual reporting. Regulators expected to increase scrutiny on operating effectiveness, not just design.

    Reporting #all
  8. AESCSF 2025 assessment cycle opens

    Energy sector entities begin self-assessments under the updated AESCSF framework. ML1 capability areas remain the baseline.

    Framework #energy
  9. First TSRMP annual reports due

    Telecommunications responsible entities must submit their first annual report under the TSRMP Rules to the ACMA.

    Reporting #telecommunications
  10. Enhanced cyber security obligations review

    Scheduled parliamentary review of the enhanced cyber security framework provisions, including the effectiveness of Systems of National Significance declarations.

    Regulation
  11. Next upcoming

    Fourth CIRMP annual reports due

    Fourth cycle. Enforcement actions expected for entities that have not demonstrated material improvement in risk management maturity.

    Enforcement #all