Skip to main content
Rules Mate

Who must adopt and maintain a Critical Infrastructure Risk Management Program (CIRMP)?

The applicability test for Adopt and maintain a Critical Infrastructure Risk Management Program (CIRMP) (Home Affairs (SOCI)), computed across 35 industries, 9 business structures and 6 size bands.

Short answer: Only if

Applies when the business has a critical infrastructure asset.

What the obligation is

Covered critical infrastructure entities must adopt a CIRMP addressing cyber, physical, personnel, and supply-chain hazards.

Part 2A of the SOCI Act requires responsible entities for designated critical infrastructure assets to adopt, maintain, comply with, and annually review a written CIRMP. The program must identify hazards (cyber, personnel, physical/natural, supply chain) and document mitigations. Board-approved annual report due within 90 days of the end of each financial year.

The applicability test

Applies when the business has a critical infrastructure asset.

How the regulator frames it: Responsible entities for designated critical infrastructure assets within scope.

What triggers it: Being responsible for a designated critical infrastructure asset.

Jurisdiction: Commonwealth law, so the test is the same in every state and territory.

Which industries are in or out

Outcome across the 35 industries Rules Mate maps (35 of 35: no).

The answer is the same in every industry: no. Industry does not change who must comply.

Business structure and size

Structure does not change the answer across all industries: for every structure the answer is "no".

Size does not change the answer across all industries: at every size band the answer is "no".

Worked examples

Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:

  • Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires a critical infrastructure asset.

Answers that bring it into scope

Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:

  • The business operates a critical infrastructure asset: it then applies (operates a critical infrastructure asset (SOCI Act)).

What you must do, and when

When due
CIRMP in place; annual report within 90 days of FY end.
Frequency
Annual
Evidence to keep
Written CIRMP, board approval, hazard register, annual report.
Status
Current
Priority
High

Penalty for not complying

Maximum penalty: Civil penalties up to $364,000 (1,000 penalty units, body corporate) for CIRMP obligations; $273,000 for the annual report.

Audit or assurance level

Self-assessment. Authority: Security of Critical Infrastructure Act 2018 (Cth) ss30AG, 30AH; CISC 'Responsible Entity CIRMP Annual Report' form.

Frequency: Annual report within 90 days after the end of the Australian financial year.

Who can perform it: Approved by the board, council or other governing body (an attestation). No statutory external audit; CISC describes an independent third-party audit as best practice.

Dates in the compliance calendar

Enforcement examples

Obligations with the same applicability test

Where it sits in the corpus

Rules Mate tracks 9 published obligations tagged "cyber", 4 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated high priority, and is a annual obligation.

Regulator, legislation and tools

Regulated by Cyber and Infrastructure Security Centre — Department of Home Affairs.

Home Affairs (SOCI): Administers the Security of Critical Infrastructure Act 2018 — registration, risk management programs, and mandatory cyber incident reporting for critical infrastructure assets.

SOCI Act: Federal critical infrastructure protection regime.

Free tools that help with this obligation:

Questions

Who must adopt and maintain a Critical Infrastructure Risk Management Program (CIRMP)?
Applies when the business has a critical infrastructure asset.
Do sole traders need to adopt and maintain a Critical Infrastructure Risk Management Program (CIRMP)?
No. Across every industry and every size band, the engine's answer for a sole trader is: no.
Do businesses with 1–5 employees need to adopt and maintain a Critical Infrastructure Risk Management Program (CIRMP)?
No (1–5 employees, turnover $100K–$1M).
When is "Adopt and maintain a Critical Infrastructure Risk Management Program (CIRMP)" due?
CIRMP in place; annual report within 90 days of FY end.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.