The CIRMP obligation is now two-tiered. Nine asset classes carry a second, more prescriptive layer on top of everything they already owed.
The Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (LIN 26/075) were registered on 9 June 2026 and commenced the following day. They do not replace the CIRMP Rules 2023. They amend them, inserting a new section 4A that carves out a set of asset classes and applies additional requirements to them.
The mechanics matter. Section 4A(3) requires a CIRMP for an affected asset to comply with both the baseline and the enhanced requirements. Section 4A(4) resolves any conflict in favour of the enhanced requirement. If you operate one of these assets, your existing CIRMP is now a partial document.
The nine asset classes in scope
Section 4A(1) lists the asset classes subject to the enhanced requirements. Everything outside this list stays on the baseline rules.
The definition that quietly does the most work
The amended Rules define a critical system as any system, including operational technology or enabling systems, that forms critical components vital to the delivery of the asset function, or the compromise or degradation of which could have a relevant impact on the asset.
Operational technology is now named in the definition. Every enhanced obligation that attaches to critical systems, and that is most of them, reaches into the OT estate by design. A CIRMP that documents controls for email, endpoints and cloud services while treating the control system environment as out of scope is not a thin CIRMP. It is one that does not address the systems the definition points at.
A new class of material risk: Section 6A adds four additional material risks that affected entities must address. Impairment of the asset that could prejudice the social stability, economic stability, national security or defence of Australia. Compromise arising from or connected with foreign ownership, control or influence. Offshore or remote access to critical components. And offshore or remote access to business critical data. The last two catch a lot of ordinary outsourcing arrangements that were never framed as a security risk.
Essential Eight maturity level one is no longer enough. The enhanced table sets level two, and that is a budget event.
Under the baseline CIRMP Rules, an entity choosing the Essential Eight had to meet maturity level one. Section 8A(3) of the amended Rules replaces that table for affected assets, and the conditions attached to three of the five frameworks are the substance of the change.
| Framework | Condition |
|---|---|
| AS ISO/IEC 27001:2023 | No maturity condition stated |
| Essential Eight Maturity Model (ASD) | Maturity level two |
| NIST Cybersecurity Framework 2.0 | No maturity condition stated |
| Cybersecurity Capability Maturity Model v2.1 (US DOE) | Maturity Indicator Level 2 |
| 2023 AESCSF Framework Core (AEMO) | Security Profile 2 |
Section 8A(4) allows an equivalent framework, but only equivalence to items 2, 4 or 5 in that table, and only including the relevant maturity condition. You cannot use the equivalence provision to argue your way below level two.
The distance between Essential Eight maturity level one and level two is not a documentation exercise. Level two brings application control on workstations, multi-factor authentication for privileged access, meaningful patch cadences, centralised logging, and restrictions on Microsoft Office macros that are genuinely enforced. In an OT environment where patching windows are measured in quarters and vendor support agreements dictate what can be touched, level two across the full scope of critical systems is a multi-year programme with capital attached. Our view on what each maturity step actually costs is set out in our analysis of Essential Eight maturity progression.
Two other things in section 8A deserve attention. Subsection 8A(2) requires processes to address failure to patch in a timely manner, failure to replace legacy systems or mitigate risks from redundant, unsupported, obsolete or discontinued technology, and the deployment or use of advanced, novel or emerging technology in ways that could prejudice the asset. That last limb reaches artificial intelligence in both directions, covering AI you deploy and AI used against you. Note also that the table specifies AS ISO/IEC 27001:2023, not the 2022 version referenced in the baseline rules, so anyone certified against the earlier edition should confirm their position. If you are weighing frameworks, our comparison of ISO 27001 and the Essential Eight covers the trade-offs, and we work with both ISO 27001 and NIST CSF programmes.
The three-month figure is real. How you classify it matters less than most commentary suggests, because both readings point the same way.
Section 8C deals with lateral movement hazards, defined as a hazard where a computer is used to move between systems to critical systems, or between two critical systems, in a way that could compromise the asset.
The mandatory obligation is in subsection 8C(2). Affected entities must maintain a process or system to inventory critical systems and their connections, recover and restore critical systems after an incident, ensure the continued availability of the asset while rebuilding, and so far as reasonably practicable minimise or mitigate lateral movement risk. That much is not optional.
Subsections 8C(3) and 8C(4) do something different. They provide that implementing network segregation which meets six specified elements is taken to be the action that minimises or eliminates the material risk. The six elements are segregation between critical systems and between critical systems and other computers, operational independence from other internet-connected computers, the ability to remain operational for at least three months while other computers are in a state of restoration or recovery, logical access controls on traffic between systems, central logging and routine review of access logs on those communication paths, and least privilege across computers that connect to critical systems.
Where the readings differ. Published summaries of the enhanced rules describe the three-month figure differently, some as a hard requirement and some as no mandated duration at all. Read the provisions above and you can see why. The duration is specified in terms, and it sits inside a provision that deems compliance rather than one that imposes a duty directly. We are not lawyers and we are not going to tell you which characterisation a court would prefer. What we will say is that the choice of label does not change what an operator should do, and the section below explains why.
The counter-argument deserves a hearing. Where an instrument sets out a prescribed way to discharge an obligation, a regulator may reasonably treat that path as the expected baseline and look closely at an entity that chose something else. On that view the stricter reading is loose about the drafting but close to right about enforcement. It also points to the same conclusion.
The commercial consequence is the part worth taking to a board, and it is the same under either reading. If you implement the six elements, the question is answered by the instrument and you can point at it. If you do not, subsection 8C(2) still applies and its test is what is reasonably practicable, which has no defined content. You would be demonstrating that your alternative was reasonable at the moment you least want to be arguing methodology, which is after an incident, in front of a regulator holding your board-approved CIRMP and your annual report.
That is why the classification debate is largely academic for planning purposes. The path that looks optional is the one that leaves you carrying an undefined evidentiary burden. Treat the six elements as the target, and treat any departure from them as a decision your board makes knowingly and records, not a gap you discover later.
For most operators, three months of genuine operational independence is the hardest thing in the entire instrument. It is not a firewall rule. It means the critical system keeps running with no dependency on directory services, licensing servers, time sources, historians, remote vendor access, patch distribution or cloud management planes that live on the other side of the boundary. Very few organisations know whether they can do this, because very few have tried. Breach simulation and recovery testing is the only way to convert that assumption into evidence, and the answer is usually uncomfortable the first time.
Section 8B is built the same way as 8C, and it only applies if your chosen framework does not already require phishing-resistant MFA.
Section 8B is conditional. It applies where an entity complies with a framework under section 8A(3) or 8A(4) that does not itself require phishing-resistant multi-factor authentication controls. If your framework already mandates it, section 8B does not add a separate obligation.
Where it does apply, subsection 8B(3) requires the CIRMP to outline the systems and networks where phishing-resistant MFA is required to authenticate access to internet-connected computers and critical systems, privileged and unprivileged access to critical components, and remote access to applications, systems or services. Subsections 8B(4) and 8B(5) then provide the deemed-compliance path: implement phishing-resistant MFA for those systems, and centrally log, monitor and routinely review both successful and unsuccessful authentication attempts.
The logging limb is the one that catches people. Implementing hardware-backed authentication is a procurement exercise with a known cost. Centrally logging and routinely reviewing failed MFA attempts across an estate that includes engineering workstations and vendor remote access is an operational commitment that continues indefinitely. The requirement is not the token. It is the monitoring that proves the token is working.
Critical workers now need an AusCheck background check or a Negative Vetting 1 clearance. There is a documented exception, and it is where most operators will end up.
Section 9A(4) sets the suitability test. A critical worker may be assessed as suitable only if they have been the subject of an AusCheck background check and then assessed as suitable by the responsible entity, or they hold a relevant security clearance at Negative Vetting 1 level or higher at the time they were identified as a critical worker. Where the check supports ongoing access to critical components, it must be repeated at least every five years.
Applied literally across a distributed asset with contractors, system integrators, vendor field technicians and maintenance crews, that is an enormous administrative undertaking with a long lead time. Which is why subsection 9A(3)(a)(ii) matters.
The documented exception: Where a critical worker is unable to meet the requirements in subsection 9A(4), the entity may still permit access if it has outlined in the CIRMP the risk associated with employing that worker and the actions taken, or that will be taken as soon as reasonably practicable, to minimise or eliminate the risk to the asset. This is a real and workable path. It is also a path that puts named residual risk in a board-approved document, which is precisely the point.
Section 9A(2) sits alongside this and covers access management rather than vetting: unauthorised or unsupervised access to critical components, compromise or misuse of credentials and privileged access, access by persons who are not critical workers, and the handling of incoming and outgoing critical workers. This subsection carries the shorter 12-month grace period, so it is the personnel obligation to move on first.
Section 9A(6) adds a maintenance duty for the clearance route. Before a clearance lapses, the entity must ensure the person has either revalidated it or undergone an AusCheck check and been reassessed. Clearance expiry is now an access control event, which means someone has to own the calendar.
Section 10A moves supply chain from a vendor list to a mapped dependency model with a stated tolerance for outage.
Section 10A(2) requires entities to map their supply chain for major suppliers and critical components. Subsection 10A(3) then requires the CIRMP to identify risks that may affect the availability, integrity, reliability or confidentiality of critical components or compromise business critical data, and to identify the maximum acceptable outage for the asset or any of its critical components arising from supply chain disruption.
Maximum acceptable outage is a defined term in the amended Rules, meaning the maximum period a critical component, service or other thing can be unavailable without unreasonably disrupting the asset. Committing to that number in a board-approved document is a meaningful act. It is a stated tolerance that can be compared against what actually happened, and most organisations have never written one down for a supply chain dependency.
The vendor assessment obligation in subsections 10A(4) and 10A(5) requires, for each existing or proposed major supplier, identification of the legislative or other legal requirements the supplier is subject to in relation to FOCI risks, any restrictions or sanctions affecting the relevant jurisdiction, the access, influence and control the supplier has over the asset through its product or service, and whether those factors together present a material risk or could exceed a maximum acceptable outage.
This is a jurisdictional and legal analysis, not a security questionnaire. Asking a supplier to complete a control self-assessment does not answer what law that supplier is subject to, or what a foreign government could compel it to do. The Note to subsection 10A(3) points at supplier diversification, redundancy planning and restoration processes as mitigations, which is the drafter signalling that the expected answer to concentrated foreign dependency is a second source, not a stronger contract clause. Our analysis of third-party risk and vendor attack surface covers how to build the underlying dependency map.
Section 11A completes the picture by requiring physical security and natural hazards to be centrally managed, and by requiring entities to consider the physical consequences of all other hazards. The Note gives the example of a cyber incident that opens gates to allow unauthorised access. Cyber and physical can no longer be governed as separate programmes with separate registers.
Most summaries put the cyber obligations in June 2027. The instrument puts the expensive ones in June 2028.
Section 4A(6) sets two grace periods, and the split does not follow hazard categories. It follows specific subsections, which is why the shorthand in circulation is wrong.
Read that split carefully and the planning consequence inverts the usual advice. The nearer deadline covers work that is largely analytical: identifying risks, documenting processes, tightening access management. The further deadline covers the capital programmes. Three months of operational independence, Essential Eight maturity level two across OT, and AusCheck vetting at scale are not 2028 problems that can be started in 2027. They are 2026 programmes with a 2028 completion date.
Assets that become critical infrastructure assets after commencement get the same 12 and 24 month periods measured from the date they become a critical infrastructure asset, not from commencement of the Rules.
The 2025-26 report covers a period in which the rules changed underneath you. Silence on that is now a choice the regulator can see.
Responsible entities must give an annual report on the CIRMP to the relevant regulator within 90 days of the end of the financial year. For the 2025-26 period, the CISC reporting window runs from 1 July 2026 to 28 September 2026. The report must be approved by the board or governing body, which makes it an attestation rather than a document the security team files.
This year's report is unusual because the enhanced rules commenced on 10 June 2026, inside the reporting period. Grace periods mean an affected entity is not yet non-compliant with the enhanced requirements. That is not the same as having nothing to say. A board approving a report that makes no reference to a substantial shift in obligations that landed three weeks before year end is approving a document that will not age well.
Directors of affected entities should be able to answer four questions before they sign.
- Have we determined whether any of our assets fall within section 4A(1), and documented that determination?
- Which framework are we relying on under section 8A(3), and what is the honest gap between our current position and the stated maturity condition?
- Are we taking the deemed-compliance path on segregation and MFA, or the reasonable-steps path, and who decided?
- Do we have a funded plan that reaches the June 2028 obligations, or an intention to build one later?
Two of those questions have no correct answer yet for most operators, and that is fine. A report that states a considered position and a plan is defensible. A report that reproduces last year's language is not, and the difference is visible to a regulator holding several years of submissions from the same entity. The broader SOCI framework, including incident reporting timeframes and Systems of National Significance obligations, is covered in our guide to SOCI Act compliance for energy and critical infrastructure.
The instrument is long, the deadlines are staged, and the useful work in the near term is narrow.
Nobody needs to be compliant with the enhanced rules this year. What is worth doing now is the work that determines how expensive the next two years become.
Days 1 to 30. Confirm in writing whether each of your assets falls within section 4A(1). Inventory your critical systems against the amended definition, including operational technology, and be honest about where the boundary of that inventory currently sits. Identify which framework you rely on under section 8A(3) and assess your real position against the stated maturity condition rather than your last self-assessment.
Days 31 to 60. Test one critical system for operational independence. Not on paper. Disconnect it in a controlled window and find out what breaks, then document the dependency list that emerges. That list is the actual scope of your section 8C programme and it will be longer than expected. In parallel, map your major suppliers and start the FOCI analysis on the three that would hurt most, because that analysis needs legal input and has a long lead time.
Days 61 to 90. Take a decision to the board on the deemed-compliance question for sections 8B and 8C, with costs attached to both paths. Draft the 2025-26 annual report so it states a position on the enhanced rules rather than ignoring them. Establish the personnel access management processes required by subsection 9A(2), since that is one of only three obligations on the June 2027 clock. Set up the risk management cadence that will carry the programme, and run a tabletop exercise against a scenario where a lateral movement hazard forces you to rely on segregation you have not yet built.
We read the instrument, assess your real position against it, and tell you which obligations are worth engineering around.
Cliffside works with critical infrastructure operators on the governance, assurance and evidence problems the enhanced CIRMP rules create. We do not sell CIRMP templates. A template cannot tell you whether three months of operational independence is achievable in your environment, and that is the question that determines your budget.
Our work in this area typically covers security governance and CIRMP development, honest framework gap assessment against Essential Eight maturity level two or ISO 27001, breach simulation and recovery testing to validate segregation assumptions, technical assurance across IT and OT boundaries, and supply chain risk assessment for major suppliers.
If the honest answer is that your existing programme already covers most of this and you need a second opinion rather than an engagement, we will tell you that. If the answer is that your CIRMP stops at the IT boundary and the enhanced rules have just moved the boundary, we will tell you that too.
Book a Consultation or call our team on (02) 8916 6389.