Manegy

Is Your Client a Critical Infrastructure Operator? What the Enhanced CIRMP Rules 2026 Mean for Your Supply Chain Security

15 July 2026

Technology

SHARE

Is Your Client a Critical Infrastructure Operator? What the Enhanced CIRMP Rules 2026 Mean for Your Supply Chain Security

Australia's Enhanced Critical Infrastructure Risk Management Program Rules 2026 came into force on 10 June 2026, significantly tightening security obligations for operators of critical electricity, gas, water, and other essential infrastructure. The direct obligations sit with those operators — but for the IT providers, facilities managers, logistics operators, and other businesses that support Australia's critical infrastructure sector, the knock-on effect is real. This article explains what has changed, whether your business is likely to be in scope, and what to prepare before a questionnaire arrives.



Why Tier-1 operators are now scrutinising their suppliers


The Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 — registered on 9 June 2026 — represent the most significant tightening of Australia's critical infrastructure security framework since the SOCI Act's baseline obligations took effect in 2023. The rules apply to responsible entities across nine designated asset classes, including critical electricity, gas, liquid fuel, water, broadcasting, domain name systems, and freight infrastructure, among others.


The direct obligations sit with the operators of those assets — not with their suppliers. But the rules are structured in a way that makes third-party risk unavoidable for Tier-1 operators to address. A Critical Infrastructure Risk Management Program (CIRMP) must now cover four hazard domains: cyber and information security, personnel security, supply chain risks, and physical and natural hazards. Operators cannot satisfy their supply chain obligations without examining the security posture of the vendors, service providers, and contractors they rely on.


The supply chain provisions carry a grace period of approximately 24 months from commencement — placing the first hard compliance deadline around mid-2028. But responsible entities are expected to begin planning immediately, and many are already doing so. For their suppliers, that means security questionnaires and vendor assessments are likely to arrive well before any statutory deadline.


In some cases — particularly where clients operate under heightened national security obligations — questions about your ownership structure or foreign affiliations may also arise. If this is relevant to your situation, specialist advice is the recommended next step.



Is your business in scope? — which suppliers face the most scrutiny


The Enhanced CIRMP Rules do not create a list of regulated suppliers. Whether your business is affected depends on what you provide, what access you have, and how closely your operations are connected to the delivery of critical infrastructure services. The following categories are examples of businesses that may find themselves in scope, depending on the specific nature of their engagement.

Supplier Category

Specific Examples

Key Security Focus for CIRMP

IT & Technology

Managed Service Providers (MSPs), Cloud/SaaS vendors, Data hosting providers

Remote access, system integration, credential management

Physical Access

Facilities managers, Maintenance contractors, Logistics

Site access controls, staff vetting, subcontractor management

Operationally Sensitive

Data processors, strategic consultants, critical parts suppliers

Data handling, operational business continuity, information security

If you are unsure whether your business is likely to be in scope, reviewing the nature of your access and speaking with your client directly is the most reliable starting point.



What to prepare before the questionnaire arrives


There is no single standard that Australian suppliers are required to meet under the Enhanced CIRMP Rules — the obligations sit with your clients, not with you. But if your business provides services to a critical infrastructure operator, the practical question is not whether you will be assessed, but when. Preparing in advance puts you in a significantly stronger position than scrambling to respond once a questionnaire lands.


1. Understand your exposure


Start by mapping your own position in the supply chain. Which of your clients operate critical infrastructure — directly or indirectly? What access does your business have to their systems, facilities, or data? Understanding the nature and depth of that relationship will help you anticipate what questions are likely to come, and prioritise where to focus your preparation.


2. Know where you stand on the Essential Eight — but don't aim for perfection


The Essential Eight is the cyber security framework most commonly referenced in Australian government and critical infrastructure contexts. Tier-1 operators subject to the Enhanced CIRMP Rules are themselves required to achieve Maturity Level 2 across recognised frameworks. That does not mean your clients will require the same of you — but understanding where your organisation sits against the Essential Eight is a useful baseline for any security conversation.


The Australian Cyber Security Centre's Essential Eight assessment guidance is available at cyber.gov.au. If you have not assessed your organisation against the Essential Eight before, Maturity Level 1 is a reasonable place to start.


3. Document your cyber security policies


Security questionnaires consistently ask for documented evidence of policies and processes — not just assertions that they exist. At a minimum, review whether your organisation has documented policies covering:

  • Access control and user account management

  • Patch management and software updates

  • Data handling and storage

  • Acceptable use of systems and devices

If these are undocumented or out of date, addressing that is a higher priority than any technical uplift.


4. Prepare your incident response basics


Most vendor security assessments will ask what your organisation does when something goes wrong. A documented incident response process — even a simple one — is more defensible than none. At a minimum, this should cover how a security incident is identified, who is notified internally, and how clients are informed if their data or systems may be affected.


5. Know what access you have — and who holds it


Compile a clear record of which staff in your organisation hold access to client systems, facilities, or data — and at what level. Access that is broader than necessary, or held by staff who have changed roles, is a common finding in vendor reviews and straightforward to address in advance.


6. Be ready to describe your ownership structure


In some client engagements — particularly those involving heightened national security considerations — questions about your ownership structure or the affiliations of key personnel may arise. Having a clear, factual description of your business's ownership ready is a simple step that avoids unnecessary delays in a review process. If foreign ownership or control is a factor in your business, speaking with a specialist adviser before a review commences is worthwhile.



Your obligations under the Enhanced CIRMP Rules are indirect — but the practical impact on your business is real. The strongest position you can be in when a security questionnaire arrives is one where the answers already exist: documented policies, a clear understanding of your access footprint, and a basic view of your cyber security maturity.


None of the steps in this article require specialist security expertise to begin. For more complex questions — including formal security assessments, Essential Eight uplift, or advice on ownership and foreign affiliation matters — consult a qualified cyber security or legal adviser.


Official sources:




Last updated: July 2026



SHARE

Latest

Technology

Australian Cyber Threats Hit Every 6 Mins: 2026 Security Guide for Back-Office Teams

Cyber threats targeting Australian organisations are increasing in both frequency and impact — and the data shows that s...

Australian Cyber Threats Hit Every 6 Mins: 2026 Security Guide for Back-Office Teams
HR

Australia’s Right to Disconnect: Employer Guide for HR & Managers (2026 Rules & Award Terms)

The right to disconnect now applies to all Australian private sector employers. For managers and HR teams, the practical...

Australia’s Right to Disconnect: Employer Guide for HR & Managers (2026 Rules & Award Terms)
Finance & Accounting

Permanent $20,000 Instant Asset Write-Off (FY2026-27): ATO Rules & Eligibility for Small Business

For more than a decade, Australian small businesses have navigated the $20,000 instant asset write-off as a temporary me...

Permanent $20,000 Instant Asset Write-Off (FY2026-27): ATO Rules & Eligibility for Small Business
Technology

AI in the back office: how Australian businesses are using it in 2026, and what your organisation needs to have in place

AI tools are already present in most Australian workplaces — including in Finance, HR, and Business Support functions —...

AI in the back office: how Australian businesses are using it in 2026, and what your organisation needs to have in place
HR

Same Job, Same Pay (RLHAOs) in 2026: A Compliance Checklist for Host Employers using Labour Hire

Same Job, Same Pay orders have been legally operative since November 2024, and the first year of enforcement delivered p...

Same Job, Same Pay (RLHAOs) in 2026: A Compliance Checklist for Host Employers using Labour Hire
advertisement