The regulatory stack

Policy and investment case.

The regulatory stack is widening. The CIRMP cycle is the forcing function. The buyer's pain is real, recurring and budgeted. Every product claim attaches to a named obligation in the regulatory stack.

SOCI Act 2018 plus the ERP amendment

s.30AC and the CIRMP Rules 2023 set the obligation. Part 2B sets the incident reporting clock. The Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024 (No. 100 of 2024, the ERP amendment) commenced Schedules 1 to 4 and 6 on 20 December 2024. Its Schedule 1, Data storage systems that hold business critical data, amends the s.9 definition so a data storage system holding business critical data, owned or operated by the responsible entity, is captured where its compromise could affect the asset. The Act also extended consequence management to all hazards and added a written direction power against a seriously deficient risk management program. The Enhanced CIRMP Rules 2026 commenced 10 June 2026. They tighten the cyber and personnel obligations inside the same four hazard categories, for nine of the thirteen asset classes that carry a CIRMP.

Systems of National Significance and the Essential Eight condition

Systems of National Significance can be required, by written notice from the Secretary, to meet the Enhanced Cyber Security Obligations in Part 2C of the SOCI Act: statutory incident response planning, cyber security exercises, vulnerability assessments and system information. Part 2C names no Essential Eight maturity level. The Essential Eight condition that does bind a CIRMP entity sits in the Rules. The baseline table at s.8(4) names Maturity Level 1. The enhanced table at s.8A(3) item 2 names Maturity Level 2, for the nine enhanced asset classes only, from 10 June 2028.

Cyber Security Act 2024

Part 3 of the Cyber Security Act 2024 (No. 98 of 2024) commenced on 30 May 2025. A reporting business entity must report a ransomware or cyber extortion payment within 72 hours of making it, or of becoming aware one was made on its behalf. The detail sits in the Cyber Security (Ransomware Payment Reporting) Rules 2025 (F2025L00278). That stacks on top of SOCI Part 2B (12 hours for critical, 72 for other) and APRA CPS 234. The obligation surface is widening, not narrowing. The engine's reporting modules are being built to cover both clocks.

Citations verified against legislation.gov.au on 2026-08-27.

See the threat and maturity evidence on /research.

Ready to look inside

See cirmp AI run on a real CIRMP cycle.

Three minutes inside the demo. A live walkthrough on request. You will see what the next CIRMP attestation looks like when it writes itself.

See the live demo Back to overview