Loading...
EOFY Sale · Save up to $750 off your legals · Ends 30 June
Claim offerLoading...
Commonwealth Act
The Security of Critical Infrastructure Act regulates critical infrastructure risk, cyber incident reporting and government powers in Australia.
Plain-English explainers, not legal advice. Check the linked official source before you rely on a specific section, and get advice for your situation.
Get legal helpQuick read
Likely relevant if
Check first
Penalties & enforcement
Risks include government directions, reporting failures, regulatory action, contract breach, loss of enterprise customers and incident-response cost.
Enforced by Cyber and Infrastructure Security Centre and the Department of Home Affairs
Supplying software to a regulated customer
Expect security questionnaires, audit rights, incident notice clauses and data-access controls to become part of the contract negotiation.
A serious cyber incident occurs
Check whether the customer or asset is covered, who must report and what contractual notices must be sent.
No. It is sector-specific. It matters most if the business owns, operates or supplies regulated critical infrastructure or handles systems that support those assets.
Regulated customers often push security, access, incident and audit obligations down into supplier contracts.