The energy sector's cyber security maturity framework, built for operational technology and named as an acceptable cyber framework under the CIRMP Rules.
The Australian Energy Sector Cyber Security Framework is a cyber security maturity framework built specifically for the Australian energy sector. It was developed through AEMO in collaboration with industry and government, and it exists because generic IT security frameworks handle corporate environments well and operational technology — the control systems that actually run generation, transmission and distribution — poorly.
Maturity is expressed through security profiles layered over a framework core, with Maturity Indicator Levels underneath. Entities target a profile appropriate to their criticality rather than all pursuing the same level.
Its regulatory significance comes from the CIRMP Rules. AESCSF security profiles are named among the cyber security frameworks a responsible entity may adopt to satisfy the CIRMP cyber requirement — the 2023 Rules referenced Security Profile 1 of the AESCSF Framework Core. Under the enhanced CIRMP Rules that commenced in June 2026, affected asset classes step up to level 2 of their chosen framework.
The framework itself is an industry-led maturity assessment rather than a statutory instrument. It becomes binding through the CIRMP Rules and through contractual and market expectations, not on its own.
Generation, transmission, distribution and market participants with SOCI Act obligations, for whom AESCSF is the natural choice of cyber security framework under the CIRMP Rules.
Much of the energy sector is among the nine designated high-risk asset classes, where the step up to level 2 of the chosen framework is binding with grace periods already running.
Where a generic IT framework leaves the part of the estate that matters most largely unaddressed.
Where supply chain obligations flow down, particularly for vendors with access to control system environments.
Driven by criticality and by your CIRMP position. Under the enhanced CIRMP Rules, affected asset classes step up to level 2 of their chosen framework, which for most energy entities means SP-2.
Against the framework core using evidence. Self-assessment is the usual starting point and the usual source of over-optimism.
The reason to use AESCSF rather than a generic framework is that it addresses OT. A scope that quietly excludes the control system estate defeats the purpose.
Sequenced by risk reduction, with OT constraints respected — patching windows in a generation or distribution environment are not IT patching windows.
Maturity claims must be supportable at assessment, and maturity decays without maintenance.
Into the annual assessment cycle, and into the CIRMP annual report where the framework is your nominated cyber security framework.
Soveriq assesses against the target security profile using evidence, builds the remediation roadmap with operational technology constraints treated as real constraints rather than obstacles, and prepares the position that supports your CIRMP annual report.
Operational technology is in scope for us. Our team works in OT and control system environments directly — which matters here, because the common failure in energy sector assessments is a scope that quietly stops at the corporate network and leaves the control system estate unexamined. Patching windows, change freezes and availability constraints in a generation or distribution environment are not IT constraints, and we plan around them rather than recommending things that cannot be done.
Where an entity holds ISO 27001, the governance and risk machinery transfers and the work concentrates on sector-specific and OT controls.
On internal review. Where Soveriq has performed the uplift, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
The framework itself is an industry-led maturity assessment rather than a statute. Where it becomes binding is through the CIRMP Rules, which name AESCSF security profiles among the acceptable cyber security frameworks, and through market and contractual expectations.
Driven by your criticality and your CIRMP position. The 2023 CIRMP Rules referenced Security Profile 1 of the AESCSF Framework Core; the enhanced rules step affected asset classes up to level 2 of the chosen framework. For most energy responsible entities that is the practical answer.
They are alternatives for the CIRMP cyber framework requirement, not complements you must hold both of. AESCSF is sector-specific and covers operational technology in a way the Essential Eight does not. Entities running significant OT usually find AESCSF the better fit.
Yes, and that is its main advantage. Generic IT frameworks handle corporate environments well and OT poorly. AESCSF was built for a sector where the control system estate is the thing that matters.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope