The board-approved risk management programme required under the SOCI Act, covering cyber, personnel, supply chain and physical hazards. Enhanced rules commenced June 2026.
A Critical Infrastructure Risk Management Program is the written, board-approved programme a responsible entity must maintain under the SOCI Act where the obligation applies to its asset. It is the centrepiece of SOCI compliance and where most of the work lives.
The CIRMP must identify and manage material risks to the critical infrastructure asset across four hazard vectors: cyber and information security, personnel, supply chain, and physical and natural hazards. It must meet a recognised cyber security framework, be reviewed at least every 12 months, and be reported to the relevant regulator within 90 days of the end of the financial year — with the annual report approved by the board before submission.
The Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (F2026L00701) were made on 4 June 2026, registered on 9 June and commenced on 10 June 2026, amending the 2023 CIRMP Rules.
They apply to nine designated high-risk asset classes, with much of the energy sector among them, and add obligations around patching and legacy technology, personnel and supply chain security, phishing-resistant multi-factor authentication, and a step up to level 2 of the chosen cyber framework. Grace periods run to roughly mid-2027 and mid-2028 — but the statutory clock started at commencement.
This is a shift from a principles-based programme to structured, evidence-based controls across defined risk areas.
Not every critical infrastructure asset carries the CIRMP obligation. Establishing whether yours does is the first question, and it is answered by asset class rather than by sector alone.
Where the uplift is binding law with grace periods already running. Energy responsible entities feature prominently.
A common position. A programme written to satisfy the original rules and reviewed lightly since is unlikely to meet either the enhanced requirements or the regulator's current enforcement posture.
Still required to submit an annual report explaining the exemption status, with the same penalty exposure for failing to lodge.
Establish whether the CIRMP obligation applies to your asset class, and whether you are among the nine classes captured by the enhanced rules. The grace-period clocks started on commencement, so this is time-sensitive.
Cyber and information security, personnel, supply chain, and physical and natural hazards. Programmes that address only cyber are the most common failure, and the easiest for a regulator to identify.
One of the designated frameworks or an equivalent, evidenced to the required level. Under the enhanced rules this steps up to level 2 of the chosen framework for affected asset classes.
Identifying material risks to the asset and the mitigations applied, with an incident response capability covering detection, containment, response and recovery across all hazard types — not cyber alone.
The programme and the annual report both require governing body sign-off. This is a genuine governance obligation, not a formality.
Reviewed at least every 12 months or on material change, with the annual report submitted within 90 days of financial year end.
Soveriq builds the CIRMP across all four hazard vectors, which is where most programmes are weakest — cyber gets the attention and personnel, supply chain and physical hazards get a paragraph each.
We establish first whether the enhanced rules capture your asset class and where you sit against the grace periods, because that determines whether this is a routine annual review or a genuine uplift programme with a deadline.
Where ISO 27001 is held, it supplies the risk methodology, governance and audit machinery the CIRMP expects across every vector, and we map it rather than rebuilding.
On internal review. Where Soveriq has built your programme, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.
What we will not do. Soveriq does not approve CIRMPs, does not speak for the CISC, and does not promise a regulatory outcome. Board approval is the board's decision and cannot be delegated to a consultant.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
They apply to nine designated high-risk asset classes, with much of the energy sector among them. The rules are F2026L00701, made 4 June 2026, registered 9 June, commenced 10 June 2026. If you are unsure whether your asset class is named, that is the first thing to establish — the grace-period clocks are already running.
Whichever you can actually evidence. ISO 27001 supplies the risk, governance and audit machinery the whole CIRMP expects, not just the cyber vector, which often makes it the more efficient choice. The Essential Eight is the most common. Energy entities frequently use AESCSF security profiles. Note that ASD's Essential Eight retirement will eventually require this reference to be revisited.
Within 90 days of the end of the Australian financial year, approved by the board before submission. A civil penalty applies for failing to lodge.
Yes. Entities exempted from preparing a CIRMP by virtue of holding a certificate of hosting certification must still submit an annual report explaining their exemption status, or face the same penalty exposure.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope