11 / 22 / 13
SOCI sectors, critical infrastructure asset classes, and the classes that carry a full CIRMP. Since 10 June 2026, nine of those thirteen also carry enhanced requirements under s.4A of the CIRMP Rules.
SOCI Act 2018 s.9 (C2026C00213) · CIRMP Rules ss.4 and 4A (F2026C00562)
13%
of the cyber security incidents ASD responded to in 2024-25 involved critical infrastructure, out of more than 1,200. Financial services, transport and logistics, and telecommunications were the most-targeted sectors.
ASD Annual Cyber Threat Report 2024-25
22%
of Commonwealth entities reached Essential Eight Maturity Level 2 in 2025, up from 15 per cent. 59 per cent cite legacy technology as a blocker, down from 71 per cent. CIRMP responsible entities sit at Maturity Level 1 under s.8(4), rising to Maturity Level 2 for the nine enhanced classes from 10 June 2028.
The Commonwealth Cyber Security Posture in 2025
See the regulatory stack on /policy.