In our previous article here, we examined the six key changes to the Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act) heralded by the Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024 (Cth) (SOCI Amendment Act). Most, but not all, of those changes took effect on 20 December 2024.
The remaining pieces have now fallen into place, with the commencement on 4 April 2025 of:
The Amending Rules amend both the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 (Cth) (CIRMP Rules) and the Security of Critical Infrastructure (Application) Rules (LIN 22/026) 2022 (Cth) (Application Rules).
IN A NUTSHELL
We canvass below the important obligations arising from these three (new or updated) sets of Rules.
Details of the Schedule 5 amendments can be found here. To recap, those amendments consolidate into the SOCI Act security requirements previously dispersed across the SOCI regime and the Telecommunications Act 1997 (Cth) (Telecommunications Act). The Schedule 5 amendments also introduce enhanced security obligations for certain critical telecommunications assets, where prescribed by the TSRMP Rules, in the form of an asset protection obligation (SOCI Act s 30EB) and a related notification obligation (SOCI Act s 30EC). Additionally, they empower the Minister for Home Affairs to direct responsible entities, for any critical telecommunications asset, to stop using or supplying a carriage service (SOCI Act s 30EF).
CIRMP RULES – DATA STORAGE SYSTEMS
The amendments to the CIRMP Rules are intended to ensure that vulnerabilities within non-operational data storage systems are appropriately managed, where such repositories hold (for example) business critical research and development or operational information, where they could in turn threaten critical infrastructure.[1]
The CIRMP Rules now require that responsible entities who are otherwise caught by those rules, and who therefore maintain a critical infrastructure risk management program (CIRMP), must also identify and manage risks to their data storage systems within their CIRMP, where those data storage systems are taken to be “part of” their critical infrastructure asset.
As addressed in our previous article, data storage systems are taken to be “part of” a critical infrastructure asset if they satisfy the following requirements under s 9(7) of the SOCI Act:[2]
The amended CIRMP Rules also explicitly designate, as a material risk for the purposes of an entity’s CIRMP, an impact to the availability, integrity, reliability or confidentiality of the data storage system holding business critical data.[3]
To avoid duplication, where an entity is responsible for multiple critical infrastructure assets, the CIRMP Rules allow for streamlined compliance with risk management program obligations to the extent spread across multiple SOCI rules.[4] For example:
Timeline: These amendments are in effect from 4 April 2025
APPLICATION RULES – CRITICAL TELECOMMUNICATIONS ASSETS
The amendments to the Application Rules bring telco carriers and certain other telco providers into alignment with a range of other critical infrastructure entities under the SOCI regime, reflective of the 2023-2030 Australian Cyber Security Strategy.[6]
The Application Rules now switch on, for a critical telecommunications asset that is either (a) owned or operated by a carrier or (b) a relevant carriage service provider asset:
A “critical telecommunications asset” is defined as:[7]
A “relevant carriage service provider asset” is defined as a critical infrastructure asset owned or operated by a carriage service provider, where:[8]
Timeline: These amendments are in effect from 4 April 2025. The relevant assets are already subject to equivalent cyber incident and register reporting obligations pursuant to instruments under the Telecommunications Act, which will remain in effect until 7 July 2025.[9] Grace periods apply to critical telecommunications assets caught by the Application Rules that come into existence after 4 April 2025 – six months from when the asset became a critical telecommunications asset caught by the Rules for Part 2 compliance and three months for Part 2B compliance.[10]
TSRMP RULES – HEIGHTENEND TELCO SECURITY & RISK MANAGEMENT
The TSRMP Rules switch on heightened security obligations, as contained in the new Part 2D of the SOCI Act, for a subset of critical telecommunications assets. These enhanced obligations are bespoke for the sector, intended to address telecommunications-specific risks.
In summary, the TSRMP Rules:
Telco protection / notification obligations
Under the newly introduced Part 2D of the SOCI Act, section 30EB obliges a responsible entity to protect a critical telecommunications asset so far as reasonably practicable to ensure the confidentiality of communications carried on and information contained on the asset, as well as the asset’s availability and integrity. Pursuant to the TSRMP Rules, this protection obligation applies only to a “relevant critical infrastructure asset”,[11] namely, a critical telecommunications asset that is:[12]
This definition is intended to reflect a proportionate, threshold-based approach as it subjects only a discrete class of critical telecommunications assets to security / protection obligations.[14] The SOCI Act’s government assistance, information gathering and direction powers remain applicable to all critical telecommunications assets.
Also under Part 2D, s 30EC obliges a responsible entity to provide the Secretary of the Department of Home Affairs with written notification of the implementation of a change, or proposed change, by the entity to a telecommunications service or telecommunications system that is likely to have a material adverse effect on the entity’s capacity to comply with its protection obligation. The TSRMP Rules apply this s 30EC notification obligation only to critical telecommunications assets owned or operated by a carrier.[15]
As part of the notification, s 17 of the TSRMP Rules requires the responsible entity to provide all information that is reasonably necessary to assess the change or proposed change. A non-exhaustive list of information that should be provided is also included (for example, a risk assessment or a timeline of the planning, development and implementation of the proposed changes).
Timeline: These obligations are in effect from 4 April 2025.
Uplifted risk management obligations
Finally, the TSRMP Rules apply the risk management program obligations contained in Part 2A of the SOCI Act to “relevant critical infrastructure assets” (see definition above).[16] This means that the responsible entity for a critical telecommunications asset that is:
must have, and comply with, a CIRMP.
The TSRMP Rules replicate and uplift the requirements set out in the CIRMP Rules. Under s 9 of the TSRMP Rules, a CIRMP must comply with the following requirements:
Further requirements are prescribed by the TSRMP Rules in respect of cyber and information security hazards (s 11), personnel hazards (s 12), supply chain hazards (s 14) and physical security hazards and natural hazards (s 15). Carriers in particular are required to comply with more stringent cybersecurity frameworks (s 11(4)).
Timeline: The TSRMP Rules have inbuilt grace periods for compliance with CIRMP obligations.[17] For any existing relevant critical infrastructure assets, the obligation does not take effect until 4 October 2025. For any assets that become a relevant infrastructure asset after 4 April 2025, the obligation does not take effect until six months after the asset became a relevant critical infrastructure asset.
NEXT STEPS
All organisations responsible for critical infrastructure assets should be implementing changes to risk and compliance frameworks, processes and documentation with respect to CIRMPs (alongside other SOCI obligations) to address any data storage systems that are now caught as ‘part of’ their primary critical infrastructure assets.
Telco sector entities will require careful risk management, compliance, reporting, incident management and security review, and uplift as required, to reflect the transfer of obligations from telecommunications legislation and instruments to the SOCI Act and its associated rules.
[1] Explanatory Memorandum ‘Security of Critical Infrastructure Amendment (2025 Measures No. 1) Rules 2025’ at 7, 9.
[2] CIRMP Rules s 4(1).
[3] CIRMP Rules s 6(f).
[4] CIRMP Rules s 4(4).
[5] Explanatory Memorandum ‘Security of Critical Infrastructure Amendment (2025 Measures No. 1) Rules 2025’ at 3.
[6] Explanatory Memorandum ‘Security of Critical Infrastructure Amendment (2025 Measures No. 1) Rules 2025’ at 2.
[7] SOCI Act s 5.
[8] Application Rules s 3.
[9] Explanatory Memorandum ‘Security of Critical Infrastructure Amendment (2025 Measures No. 1) Rules 2025’ at 11-12.
[10] Application Rules ss 4(3), 5(5).
[11] TSRMP Rules s 6.
[12] TSRMP Rules s 5.
[13] TSRMP Rules s 4 (defined the same as in the Application Rules).
[14] Explanatory Memorandum ‘Security of Critical Infrastructure (Telecommunications Security and Risk Management Program) Rules 2025’ at 1-2.
[15] TSRMP Rules s 16.
[16] TSRMP Rules s 7(1).
[17] TSRMP Rules s 7(2).