AESCSF — Australian Energy Sector Cyber Security Framework

The energy sector's cyber security maturity framework, built for operational technology and named as an acceptable cyber framework under the CIRMP Rules.

Developed and maintained through AEMO in collaboration with industry and government, including the Australian Energy Market Operator's cyber security programme.

What it is

The Australian Energy Sector Cyber Security Framework is a cyber security maturity framework built specifically for the Australian energy sector. It was developed through AEMO in collaboration with industry and government, and it exists because generic IT security frameworks handle corporate environments well and operational technology — the control systems that actually run generation, transmission and distribution — poorly.

Maturity is expressed through security profiles layered over a framework core, with Maturity Indicator Levels underneath. Entities target a profile appropriate to their criticality rather than all pursuing the same level.

Its regulatory significance comes from the CIRMP Rules. AESCSF security profiles are named among the cyber security frameworks a responsible entity may adopt to satisfy the CIRMP cyber requirement — the 2023 Rules referenced Security Profile 1 of the AESCSF Framework Core. Under the enhanced CIRMP Rules that commenced in June 2026, affected asset classes step up to level 2 of their chosen framework.

The framework itself is an industry-led maturity assessment rather than a statutory instrument. It becomes binding through the CIRMP Rules and through contractual and market expectations, not on its own.

Who it's for

Energy sector responsible entities

Generation, transmission, distribution and market participants with SOCI Act obligations, for whom AESCSF is the natural choice of cyber security framework under the CIRMP Rules.

Entities captured by the enhanced CIRMP Rules

Much of the energy sector is among the nine designated high-risk asset classes, where the step up to level 2 of the chosen framework is binding with grace periods already running.

Organisations running significant operational technology

Where a generic IT framework leaves the part of the estate that matters most largely unaddressed.

Suppliers to energy entities

Where supply chain obligations flow down, particularly for vendors with access to control system environments.

Why implement it

  • It satisfies the CIRMP cyber requirement for energy entities, in a form built for their environment rather than adapted to it.
  • It addresses operational technology properly. This is the substantive reason to choose it. The control system estate is where energy sector risk concentrates, and most generic frameworks barely reach it.
  • The enhanced rules make the uplift binding. For affected asset classes the step to level 2 is law with a running clock, not a maturity aspiration.
  • Profiles are proportionate. Entities target a profile matched to criticality rather than a single national standard applied uniformly.
  • It is sector-recognised. Assessment results are legible to AEMO, to regulators and to counterparties in a way a bespoke internal maturity model is not.

How implementation works

1. Establish your target security profile

Driven by criticality and by your CIRMP position. Under the enhanced CIRMP Rules, affected asset classes step up to level 2 of their chosen framework, which for most energy entities means SP-2.

2. Assess current maturity

Against the framework core using evidence. Self-assessment is the usual starting point and the usual source of over-optimism.

3. Include operational technology properly

The reason to use AESCSF rather than a generic framework is that it addresses OT. A scope that quietly excludes the control system estate defeats the purpose.

4. Prioritise remediation

Sequenced by risk reduction, with OT constraints respected — patching windows in a generation or distribution environment are not IT patching windows.

5. Evidence and sustain

Maturity claims must be supportable at assessment, and maturity decays without maintenance.

6. Report

Into the annual assessment cycle, and into the CIRMP annual report where the framework is your nominated cyber security framework.

How Soveriq helps

Soveriq assesses against the target security profile using evidence, builds the remediation roadmap with operational technology constraints treated as real constraints rather than obstacles, and prepares the position that supports your CIRMP annual report.

Operational technology is in scope for us. Our team works in OT and control system environments directly — which matters here, because the common failure in energy sector assessments is a scope that quietly stops at the corporate network and leaves the control system estate unexamined. Patching windows, change freezes and availability constraints in a generation or distribution environment are not IT constraints, and we plan around them rather than recommending things that cannot be done.

Where an entity holds ISO 27001, the governance and risk machinery transfers and the work concentrates on sector-specific and OT controls.

On internal review. Where Soveriq has performed the uplift, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.

What the engagement looks like

  • Module 01 — Gap analysis against your target security profile, using evidence rather than self-assessment.
  • Module 02 — Build. Control implementation and the evidence routines that make a profile claim defensible.
  • Module 03 — Internal review ahead of assessment or reporting, subject to the impartiality position above.
  • Module 04 — Representation where AEMO, the CISC or a sector regulator engages directly.
  • Module 05 — Continuous compliance, including the annual assessment cycle.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Common questions

Is AESCSF participation mandatory?

The framework itself is an industry-led maturity assessment rather than a statute. Where it becomes binding is through the CIRMP Rules, which name AESCSF security profiles among the acceptable cyber security frameworks, and through market and contractual expectations.

Which security profile should we target?

Driven by your criticality and your CIRMP position. The 2023 CIRMP Rules referenced Security Profile 1 of the AESCSF Framework Core; the enhanced rules step affected asset classes up to level 2 of the chosen framework. For most energy responsible entities that is the practical answer.

How does it relate to the Essential Eight?

They are alternatives for the CIRMP cyber framework requirement, not complements you must hold both of. AESCSF is sector-specific and covers operational technology in a way the Essential Eight does not. Entities running significant OT usually find AESCSF the better fit.

Does it cover operational technology?

Yes, and that is its main advantage. Generic IT frameworks handle corporate environments well and OT poorly. AESCSF was built for a sector where the control system estate is the thing that matters.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope