Enhanced CIRMP Rules: What SOCI Supply Chain Obligations Mean for Vendor Procurement

The enhanced CIRMP Rules commenced 10 June 2026. What Australian critical infrastructure entities must now assess about their major suppliers, and by when.
CYBORIUM article header: enhanced CIRMP Rules and supply chain obligations

The enhanced CIRMP Rules commenced on 10 June 2026, and they put your suppliers inside the compliance boundary. Responsible entities for nine classes of critical infrastructure asset must now map major suppliers, assess who holds access and control over critical components, and account for offshore or remote access to business critical data.

Most of the commentary has treated this as a security uplift. It is also a procurement change. The obligations that bite hardest sit in supply chain mapping and major supplier assessment, and those are decided at requirements definition, tender evaluation and contract signature, not in the security operations centre.

What is the SOCI Act?

The SOCI Act is the Security of Critical Infrastructure Act 2018, the Australian law setting security obligations for critical infrastructure assets. It requires responsible entities to register assets, report cyber incidents, and under Part 2A maintain a critical infrastructure risk management program covering cyber, personnel, physical and supply chain hazards.

What are the enhanced CIRMP Rules?

The enhanced CIRMP requirements come from the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026. They build on the baseline CIRMP obligation in Part 2A of the Security of Critical Infrastructure Act 2018, rather than replacing it.

The baseline program already required responsible entities to identify material risks across cyber, personnel, physical and supply chain hazards, and to minimise or eliminate them so far as reasonably practicable. The enhanced rules add new hazard categories, new material risks, and a much more specific set of questions about the organisations you buy from.

Which assets are captured by the enhanced CIRMP?

Section 4A(1) applies the enhanced requirements to responsible entities for nine asset classes:

  • Critical broadcasting assets
  • Critical domain name system assets
  • Critical electricity assets
  • Critical energy market operator assets
  • Critical freight infrastructure assets
  • Critical freight services assets
  • Critical gas assets
  • Critical liquid fuel assets
  • Critical water assets

Entities outside those classes still carry the baseline CIRMP obligation if Part 2A has been switched on for their asset. They are also worth reading the enhanced rules closely, because the supplier questions being asked of energy, water and freight operators will flow down to anyone selling into them.

The enhanced CIRMP compliance dates that matter

Subsection 4A(6) of the instrument does not set flat calendar deadlines. It switches off the new provisions for a grace period, measured in months from commencement for assets that were already critical infrastructure assets, and from the asset’s own start date for anything that becomes one later. For an asset captured on day one the periods land as follows.

  • 10 June 2026. The enhanced CIRMP Rules commence.
  • 12 months, so 10 June 2027. End of the grace period for section 6A and subsections 8A(2) and 9A(2), the new material risks.
  • 24 months, so 10 June 2028. End of the grace period for the rest: sections 8A (other than 8A(2)), 8B, 8C, 9A (other than 9A(2)), 10A and 11A. Section 10A supply chain and major supplier assessment sits in this group.
  • 28 September each year. The CIRMP annual report is due, being 90 days after the end of the Australian financial year.

An asset that becomes a critical infrastructure asset in 2027 gets the same 12 and 24 month clocks running from its own start date, so the dates above are not universal. Two years also sounds comfortable, and it is not, once you account for contract cycles. A five year managed service agreement signed in late 2026 will still be running when the section 10A obligations land, and by then the negotiating room to add evidence rights, jurisdiction disclosure and access controls has gone. Renegotiating mid-term costs money and goodwill. Getting the clauses into the tender costs neither.

What the enhanced CIRMP asks about your suppliers

Section 10A is the provision procurement teams should read first. It requires responsible entities to:

  • Map major suppliers and critical components across the supply chain, so the entity can name what it depends on and who provides it.
  • Assess existing or proposed major suppliers for risk, which puts the assessment inside the sourcing decision rather than after it.
  • Identify supplier access, influence and control over the asset, including where that access is indirect or held by a subcontractor.
  • Consider restrictions, sanctions and other impediments affecting the jurisdictions involved.
  • Identify the legal requirements a supplier is subject to where foreign ownership, control or influence risk applies, under section 10A(5).

That last point does not ask whether a vendor is foreign owned. It asks which laws that vendor must obey, which is a harder question and one that most security questionnaires skip. A vendor can be an excellent operator and still be subject to a foreign disclosure regime that creates a material risk to your asset.

New hazards and material risks under the enhanced CIRMP

Credential compromise and lateral movement

The rules name credential compromise as a hazard where credentials for internet-connected computers or critical components, or remote access to those devices, are used to introduce vulnerabilities. Lateral movement is named separately, covering a user moving between computer systems to reach critical systems.

Both hazards describe how third party access actually fails in practice. The vendor support account with standing privileges, the shared jump host, the remote maintenance path that nobody owns. These are contract artefacts as much as technical ones.

Additional material risks in section 6A

  • Impairment of asset functions that could prejudice social stability, economic stability, national security or defence.
  • Compromise or impairment resulting from foreign ownership, control or influence.
  • Offshore or remote access to critical components.
  • Offshore or remote access to business critical data.

The last two are the ones that catch cloud, managed service and follow-the-sun support arrangements. If a provider’s night shift sits in another country and can reach business critical data, that is now a material risk you have to identify and address, whatever the contract says about data residency.

What the enhanced CIRMP changes in procurement practice

Ask jurisdiction questions in the tender, not the security review

Where the work is performed, which entities in the corporate group can reach the environment, and which legal regimes apply to each of them. Vendors answer these questions accurately when they are scored on them and vaguely when they are not.

Define major supplier before you need the definition

The rules do not hand you a spend threshold. Set your own criteria based on access to critical components, access to business critical data, and the difficulty of replacing the provider. A low value contract with high access is a major supplier. A large commodity contract with none may not be.

Get subcontractor visibility contractually

You cannot map a supply chain you are not allowed to see. Require disclosure of subcontractors who touch critical components or business critical data, notification before that list changes, and the right to object. Most supply chain mapping stops at the direct supplier, which leaves fourth party risk unmapped.

Make evidence a deliverable

Access reviews, privileged account inventories, remote access logs and assurance reports need to be obtainable on request and in a usable form. An annual attestation letter will not support a board-approved report.

Price the exit at the start

If a supplier becomes an unacceptable risk under section 10A, the response is to replace them. That is only realistic if transition-out assistance, data extraction and knowledge handover were negotiated while you still had competitive tension.

Ransomware payment reporting sits alongside the enhanced CIRMP

Mandatory ransomware and cyber extortion payment reporting under Part 3 of the Cyber Security Act 2024 commenced on 30 May 2025. It applies to businesses with annual turnover above $3 million and to responsible entities for critical infrastructure assets covered by Part 2B of the SOCI Act.

A report is due within 72 hours of making a payment, or of becoming aware that a payment has been made on your behalf. That second limb is the one to plan for. If an incident response retainer, a broker or an insurer can authorise a payment on your behalf, your reporting clock starts when you find out. Contracts with those parties should require immediate notification, and your incident response playbook should name who files the report.

The annual report and who signs it

Section 30AG requires a responsible entity to give the relevant regulator an annual report on its critical infrastructure risk management program within 90 days after the end of the financial year. For the Australian financial year that means 28 September. Where the entity has a board, council or other governing body, that body must approve the report.

Board approval puts supplier risk in front of directors. A director signing that report will reasonably ask which suppliers hold access to critical components, who assessed them, and what happens if one of them fails. Those answers come from procurement records.

What to do in the next twelve months

  1. Confirm whether the enhanced CIRMP applies to you. Check your asset class against section 4A(1) and confirm the status of any pre-commencement declaration.
  2. Build the supplier map now. Critical components, the providers behind them, the access each holds, and the jurisdictions involved. This takes longer than anyone estimates.
  3. Triage contracts by expiry date. Anything renewing before 10 June 2028 is an opportunity to add the clauses without paying a variation.
  4. Write the enhanced CIRMP questions into your standard tender pack. Jurisdiction, subcontractors, remote access, evidence rights, exit assistance.
  5. Close the offshore access question. Establish who can reach business critical data from where, and whether the contract actually constrains it.
  6. Rehearse the payment reporting path. Confirm who can authorise a payment on your behalf and how fast they will tell you.

How CYBORIUM supports enhanced CIRMP procurement

CYBORIUM helps Australian organisations define requirements, test the market, compare providers and produce a decision record that stands up to scrutiny. The approach is independent and vendor-neutral. The client pays no fee to CYBORIUM and contracts directly with the selected provider.

For enhanced CIRMP readiness that can include supplier criticality criteria, jurisdiction and access disclosure requirements, evidence obligations, subcontractor visibility terms, commercial benchmarking and transition-out provisions. CYBORIUM does not sell, deliver, operate, manage or invoice the selected technology.

Related guidance: Vendor and Supplier Risk Management for Enterprise Procurement, APRA CPS 230 third party due diligence, the Cybersecurity Vendor Evaluation Framework and what is changing after the Essential Eight.

Reviewing a supplier or preparing a tender under the enhanced CIRMP? Use CYBORIUM’s cybersecurity evaluation previews to test scope, evidence, pricing and contract terms before you commit.

Frequently asked questions

When did the enhanced CIRMP Rules commence?

They commenced on 10 June 2026. For assets that were already critical infrastructure assets before that date, the new material risks must be addressed by 10 June 2027 and the remaining measures, including supply chain assessment, by 10 June 2028.

Does the enhanced CIRMP replace the existing CIRMP Rules?

No. The enhanced requirements build on the baseline CIRMP obligation under Part 2A of the SOCI Act. The existing program, annual report and board approval requirements continue.

What counts as a major supplier?

The rules require major suppliers to be mapped and assessed without setting a spend threshold. Most entities define the term by reference to access to critical components, access to business critical data, and the difficulty of replacing the provider.

Do these obligations apply to technology vendors themselves?

The obligation sits with the responsible entity for the critical infrastructure asset. In practice it reaches vendors through contracts, tender requirements and evidence requests. Providers selling into these sectors should expect jurisdiction, subcontractor and access questions to become standard.

When is the CIRMP annual report due?

Within 90 days after the end of the Australian financial year, which is 28 September. Where the responsible entity has a governing body, that body must approve the report before it is submitted.

Official sources and update status

Information status: reviewed against publicly available Commonwealth sources on 6 August 2026. The grace periods and section references above were read directly from F2026L00701 as made. Confirm them against the instrument as in force for your asset class before relying on them. This is general information, not legal advice.

Preparing a supplier assessment or a sourcing decision under the enhanced CIRMP? Speak with CYBORIUM about an independent, evidence-led pathway.

Also relevant: telecommunications technology priorities to 2030, and recovery obligations for critical infrastructure, and energy sector technology priorities, and OT and ICS security procurement.

Share this analysis