Who must comply with Government cyber incident reporting via ASD ACSC?
The applicability test for Government cyber incident reporting via ASD ACSC (ASD), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Only if
Applies when the business has a critical infrastructure asset.
What the obligation is
Federal entities + critical infrastructure report cyber incidents to ASD ACSC.
Federal agencies + Commonwealth-funded entities report cyber incidents to ASD's Australian Cyber Security Centre (ACSC). Mandatory for critical infrastructure under SOCI; voluntary but expected for others. Information sharing supports national threat intelligence.
The applicability test
Applies when the business has a critical infrastructure asset.
How the regulator frames it: Federal agencies + critical infrastructure entities.
What triggers it: Cyber incident with potential impact.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (35 of 35: no).
The answer is the same in every industry: no. Industry does not change who must comply.
Business structure and size
Structure does not change the answer across all industries: for every structure the answer is "no".
Size does not change the answer across all industries: at every size band the answer is "no".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires a critical infrastructure asset.
Answers that bring it into scope
Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:
- The business operates a critical infrastructure asset: it then applies (operates a critical infrastructure asset (SOCI Act)).
What you must do, and when
- When due
- ASAP; statutory 12-72h for SOCI.
- Frequency
- When a triggering event occurs
- Evidence to keep
- ASD ACSC incident report; internal investigation record.
- Status
- Current
- Priority
- High
Penalty for not complying
Maximum penalty: Statutory requirement under SOCI for CI; PSPF compliance for agencies.
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
Obligations with the same applicability test
If this obligation applies to you, so do these 5: the engine uses the same rule for each.
Where it sits in the corpus
Rules Mate tracks 9 published obligations tagged "cyber", 4 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated high priority, and is triggered by events.
Regulator, legislation and tools
Regulated by Australian Signals Directorate (Australian Cyber Security Centre).
ASD: Cyber security guidance and incident response. Publishes the Information Security Manual (ISM), Essential Eight, and Right Fit For Risk requirements for federal subcontractors.
SOCI Act: Federal critical infrastructure protection regime.
Free tools that help with this obligation:
Questions
- Who must comply with Government cyber incident reporting via ASD ACSC?
- Applies when the business has a critical infrastructure asset.
- Does Government cyber incident reporting via ASD ACSC apply to sole traders?
- No. Across every industry and every size band, the engine's answer for a sole trader is: no.
- Does Government cyber incident reporting via ASD ACSC apply to businesses with 1–5 employees?
- No (1–5 employees, turnover $100K–$1M).
- When is "Government cyber incident reporting via ASD ACSC" due?
- ASAP; statutory 12-72h for SOCI.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.