Is Your Client a Critical Infrastructure Operator? What the Enhanced CIRMP Rules 2026 Mean for Your Supply Chain Security
15 July 2026
TechnologySHARE
Australia's Enhanced Critical Infrastructure Risk Management Program Rules 2026 came into force on 10 June 2026, significantly tightening security obligations for operators of critical electricity, gas, water, and other essential infrastructure. The direct obligations sit with those operators — but for the IT providers, facilities managers, logistics operators, and other businesses that support Australia's critical infrastructure sector, the knock-on effect is real. This article explains what has changed, whether your business is likely to be in scope, and what to prepare before a questionnaire arrives.
Why Tier-1 operators are now scrutinising their suppliers
The Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 — registered on 9 June 2026 — represent the most significant tightening of Australia's critical infrastructure security framework since the SOCI Act's baseline obligations took effect in 2023. The rules apply to responsible entities across nine designated asset classes, including critical electricity, gas, liquid fuel, water, broadcasting, domain name systems, and freight infrastructure, among others.
The direct obligations sit with the operators of those assets — not with their suppliers. But the rules are structured in a way that makes third-party risk unavoidable for Tier-1 operators to address. A Critical Infrastructure Risk Management Program (CIRMP) must now cover four hazard domains: cyber and information security, personnel security, supply chain risks, and physical and natural hazards. Operators cannot satisfy their supply chain obligations without examining the security posture of the vendors, service providers, and contractors they rely on.
The supply chain provisions carry a grace period of approximately 24 months from commencement — placing the first hard compliance deadline around mid-2028. But responsible entities are expected to begin planning immediately, and many are already doing so. For their suppliers, that means security questionnaires and vendor assessments are likely to arrive well before any statutory deadline.
In some cases — particularly where clients operate under heightened national security obligations — questions about your ownership structure or foreign affiliations may also arise. If this is relevant to your situation, specialist advice is the recommended next step.
Is your business in scope? — which suppliers face the most scrutiny
The Enhanced CIRMP Rules do not create a list of regulated suppliers. Whether your business is affected depends on what you provide, what access you have, and how closely your operations are connected to the delivery of critical infrastructure services. The following categories are examples of businesses that may find themselves in scope, depending on the specific nature of their engagement.
Supplier Category | Specific Examples | Key Security Focus for CIRMP |
|---|---|---|
IT & Technology | Managed Service Providers (MSPs), Cloud/SaaS vendors, Data hosting providers | Remote access, system integration, credential management |
Physical Access | Facilities managers, Maintenance contractors, Logistics | Site access controls, staff vetting, subcontractor management |
Operationally Sensitive | Data processors, strategic consultants, critical parts suppliers | Data handling, operational business continuity, information security |
If you are unsure whether your business is likely to be in scope, reviewing the nature of your access and speaking with your client directly is the most reliable starting point.
What to prepare before the questionnaire arrives
There is no single standard that Australian suppliers are required to meet under the Enhanced CIRMP Rules — the obligations sit with your clients, not with you. But if your business provides services to a critical infrastructure operator, the practical question is not whether you will be assessed, but when. Preparing in advance puts you in a significantly stronger position than scrambling to respond once a questionnaire lands.
1. Understand your exposure
Start by mapping your own position in the supply chain. Which of your clients operate critical infrastructure — directly or indirectly? What access does your business have to their systems, facilities, or data? Understanding the nature and depth of that relationship will help you anticipate what questions are likely to come, and prioritise where to focus your preparation.
2. Know where you stand on the Essential Eight — but don't aim for perfection
The Essential Eight is the cyber security framework most commonly referenced in Australian government and critical infrastructure contexts. Tier-1 operators subject to the Enhanced CIRMP Rules are themselves required to achieve Maturity Level 2 across recognised frameworks. That does not mean your clients will require the same of you — but understanding where your organisation sits against the Essential Eight is a useful baseline for any security conversation.
The Australian Cyber Security Centre's Essential Eight assessment guidance is available at cyber.gov.au. If you have not assessed your organisation against the Essential Eight before, Maturity Level 1 is a reasonable place to start.
3. Document your cyber security policies
Security questionnaires consistently ask for documented evidence of policies and processes — not just assertions that they exist. At a minimum, review whether your organisation has documented policies covering:
Access control and user account management
Patch management and software updates
Data handling and storage
Acceptable use of systems and devices
If these are undocumented or out of date, addressing that is a higher priority than any technical uplift.
4. Prepare your incident response basics
Most vendor security assessments will ask what your organisation does when something goes wrong. A documented incident response process — even a simple one — is more defensible than none. At a minimum, this should cover how a security incident is identified, who is notified internally, and how clients are informed if their data or systems may be affected.
5. Know what access you have — and who holds it
Compile a clear record of which staff in your organisation hold access to client systems, facilities, or data — and at what level. Access that is broader than necessary, or held by staff who have changed roles, is a common finding in vendor reviews and straightforward to address in advance.
6. Be ready to describe your ownership structure
In some client engagements — particularly those involving heightened national security considerations — questions about your ownership structure or the affiliations of key personnel may arise. Having a clear, factual description of your business's ownership ready is a simple step that avoids unnecessary delays in a review process. If foreign ownership or control is a factor in your business, speaking with a specialist adviser before a review commences is worthwhile.
Your obligations under the Enhanced CIRMP Rules are indirect — but the practical impact on your business is real. The strongest position you can be in when a security questionnaire arrives is one where the answers already exist: documented policies, a clear understanding of your access footprint, and a basic view of your cyber security maturity.
None of the steps in this article require specialist security expertise to begin. For more complex questions — including formal security assessments, Essential Eight uplift, or advice on ownership and foreign affiliation matters — consult a qualified cyber security or legal adviser.
Official sources:
Cyber and Infrastructure Security Centre (CISC) — SOCI Act regulatory obligations
Federal Register of Legislation — Enhanced CIRMP Rules 2026 (F2026L00701)
Last updated: July 2026
SHARE
