
Many responsible entities have now completed their initial review of the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (Enhanced CIRMP Rules 2026) and are beginning to consider what the additional legislative obligations mean for their organisations.
Understanding the new requirements is an important first step.
For Boards and senior executives, however, the more important question is now becoming: How do we implement the Enhanced CIRMP Rules in a structured, evidence-based and defensible way?
Over the past three years, responsible entities have invested considerable effort in implementing and progressively maturing their Critical Infrastructure Risk Management Programs (CIRMPs). Governance arrangements have been established, material risks assessed, policies and procedures developed, security controls implemented and assurance processes progressively strengthened.
The Enhanced CIRMP Rules introduce a different implementation challenge.
For many responsible entities, the challenge is no longer implementing a single set of CIRMP requirements, but understanding how the 78 additional Enhanced CIRMP obligations build upon the 59 existing Baseline obligations to create a single, integrated Critical Infrastructure Risk Management Program. For responsible entities subject to the Enhanced Rules, this means progressively implementing and maintaining a CIRMP capable of addressing up to 137 legislative obligations.
The Enhanced CIRMP Rules do not require organisations to start again. Rather, they require responsible entities to understand how their existing CIRMP supports and connects with the additional Enhanced obligations to determine what can be retained, what should be validated, what needs to be strengthened or expanded, and what must be newly implemented within the required legislative timeframes.
For many organisations, implementing the Enhanced CIRMP Rules will therefore require more than updating an existing CIRMP. It will require a systematic implementation program that enables responsible entities to review their existing CIRMP, assess readiness, validate and strengthen existing controls, identify new implementation requirements, prioritise implementation activities based on security risks and monitor progress towards the 10 June 2027 and 10 June 2028legislative implementation milestones.
This is where the distinction between maturity and readiness becomes important.
Maturity assesses how effectively today’s CIRMP is operating.
Readiness assesses how prepared the organisation is to build on that foundation and implement the additional Enhanced CIRMP obligations.
Unlike maturity, which measures today’s capability, readiness reflects the staged implementation approach adopted by the Enhanced CIRMP Rules and focuses on preparedness for future legislative obligations.
The Enhanced Rules build on what already exists
The Enhanced Rules do not create a separate risk management program or replace the existing CIRMP framework.
They build upon it.
The Enhanced Rules should therefore be viewed as an evolution of an existing CIRMP, rather than the creation of a new one.
Responsible entities must continue to comply with the Baseline CIRMP obligations while progressively implementing the additional Enhanced obligations. The implementation challenge is therefore cumulative: organisations must connect the new requirements to the governance arrangements, risk assessments, controls and assurance processes they have already established.
This changes the implementation conversation.
The question is no longer simply: What new obligations have been introduced?
Boards and senior executives should instead be asking:
- Which existing CIRMP arrangements already support the Enhanced obligations?
- Which controls remain appropriate but require further evidence or validation?
- Which capabilities need to be strengthened or expanded?
- Which new capabilities, processes or controls must be implemented?
- How will the organisation prioritise and monitor this work across the 2027 and 2028 implementation horizons?
Answering these questions requires more than reading the legislation or adding new requirements to an existing CIRMP document. It requires a structured assessment of how the Enhanced obligations build upon the organisation’s current security capability.
Sections 9 and 9A illustrate the implementation challenge
The relationship between section 9 (Personnel Hazards) and the new section 9A (Personnel Hazards – Enhanced Requirements), provides a practical example of how the Enhanced CIRMP Rules should be implemented.
Section 9 established a risk-based and outcome-focused obligation to identify personnel hazards, assess the associated risks and implement appropriate controls. It gave responsible entities flexibility to determine how personnel security risks should be managed within their own operational environment.
Section 9A builds on that foundation by introducing more defined expectations around critical workers, access to critical infrastructure assets and critical components, suitability assessment, ongoing suitability and the evidence required to support personnel security decisions.
The difference can be illustrated through two simple questions.
Section 9 asks: Have you identified and managed personnel security risks?
Section 9A asks: Can you demonstrate that only suitable critical workers are permitted access to critical components, and that their ongoing suitability is monitored, assessed and managed over time?
This is more than a change in wording. It reflects a shift from broad, risk-based, point-in-time personnel security towards a more structured, prescriptive, process-, evidence- and assurance-based trusted workforce capability that is managed (monitored) over time.
Organisations should therefore not approach section 9A as an isolated access-control exercise or as an entirely new personnel security program.
Instead, they should begin by reviewing the personnel security arrangements already established under section 9 and determining:
- what can be retained
- what should be validated and evidenced
- what requires strengthening
- what needs to be expanded
- what must be newly implemented.
For example, existing processes for identifying critical workers, assessing suitability, managing access to critical components and offboarding workers provide an important foundation.
Those arrangements may now need to be validated, strengthened and extended into a more comprehensive, risk-based access governance framework that:
- confirms the critical components relevant to personnel security
- identifies the workers who require authorised, privileged, supervised or visitor access at a point-in-time and into the future
- assigns responsibility for access authorisation and periodic review
- integrates personnel security across onboarding, contractor management, role changes and offboarding
- prevents, detects and manages unauthorised or unsupervised access
- enables the capability to assess people over time.
These are not merely technical access-control decisions. They are governance decisions that determine how the organisation identifies, authorises, monitors and assures access to its critical infrastructure assets and critical components. Section 9A(2) establishes the governance, workforce lifecycle security and access management foundations for a broader personnel security capability.
The remaining section 9A obligations build on these foundations by introducing documented processes for assessing suitability before access is granted, monitoring changes that may affect a critical worker’s ongoing suitability, managing circumstances where the prescribed suitability pathway cannot immediately be met, and retaining evidence that personnel security decisions are documented, justified and regularly reviewed.
Importantly, an AusCheck background check does not, by itself, establish that an individual is suitable. The responsible entity must still undertake and document its own organisational suitability assessment, or rely on an appropriate Australian Government security clearance where permitted under the Rules.
This example also illustrates why implementation cannot be reduced to a checklist.
Access is an important indicator of personnel security risk, but it is not the only determinant of criticality. Some critical workers may be able to create, influence or amplify risk through decision-making authority, procurement responsibilities, administration of critical systems or indirect influence over critical components, even where they do not require direct physical or logical access. The objective should therefore be to manage risk exposure, not merely permissions.
The same implementation principle applies across the other Enhanced domains. Cyber security, supply chain security, physical security and governance requirements should likewise be implemented by building on existing organisational capability, rather than as separate compliance activities.
The task is not to discard what has already been built. It is to determine whether the existing CIRMP provides a sufficient foundation for the Enhanced Rules, identify where it must be validated, strengthened or extended, and establish a structured pathway from current maturity to future readiness.
The same implementation methodology can then be applied across every Enhanced obligation, providing a consistent and repeatable approach to implementing the Enhanced CIRMP Rules.
In practice, implementing the Enhanced CIRMP Rules follows three logical steps: first understand current CIRMP maturity, then assess readiness against the Enhanced obligations, and finally develop a systematic implementation roadmap to achieve compliance within the applicable legislative timeframes.
From Maturity to Readiness: A Practical Implementation Framework
The distinction between maturity and readiness provides a practical framework for implementing the Enhanced CIRMP Rules.
A maturity assessment establishes an organisation’s current baseline by evaluating how effectively its existing CIRMP is operating. It provides an evidence-based understanding of current governance arrangements, risk management processes and security controls.
A readiness assessment builds on that baseline by examining how well the existing CIRMP supports the additional Enhanced CIRMP obligations. Rather than treating the Enhanced Rules as a separate compliance exercise, it evaluates what can be retained, validated, strengthened, expanded or newly implemented to achieve compliance within the required legislative timeframes.
The staged implementation periods create an important opportunity for responsible entities. While the Enhanced CIRMP Rules have commenced, many of the additional obligations are not required to be fully implemented until 10 June 2027 or 10 June 2028. During this transition period, assessing organisational maturity against obligations that are not yet legally required provides only limited value. Organisations instead need a structured way to assess their preparedness, prioritise implementation activities and monitor progress towards the applicable legislative milestones.
A practical readiness assessment should therefore enable organisations to:
- understand how the additional Enhanced obligations build upon their existing CIRMP
- determine what can be retained, validated, strengthened, expanded or newly implemented
- identify implementation gaps and prioritise activities based on security risk and legislative implementation milestones
- assign responsibility and accountability for implementation activities
- monitor progress towards implementation milestones
- provide Boards and senior executives with ongoing visibility of implementation progress and organisational readiness
- develop a practical Enhanced CIRMP Implementation Roadmap aligned to the 2027 and 2028 legislative milestones.
Importantly, readiness is not a point-in-time assessment.
As implementation progresses, organisations should be able to reassess their readiness, demonstrate how existing capability has evolved, and provide evidence that the Enhanced CIRMP Rules are being systematically implemented rather than addressed through isolated compliance activities.
For Boards and senior executives, this creates a practical implementation pathway. Rather than asking whether the organisation is simply compliant today, they can ask a more meaningful question: Are we on track to implement the Enhanced CIRMP Rules, and can we demonstrate our progress towards readiness?
Answering that question requires more than a compliance checklist. It requires a structured methodology for assessing organisational readiness and planning implementation over time.
Recognising this implementation challenge, Pentagram Advisory developed the Enhanced CIRMP Readiness Assessment Module. Building on Pentagram’s CIRMP Security Maturity Assessment and Evaluation Model™, the Module provides a structured, evidence-based methodology for assessing readiness against the 78 additional Enhanced CIRMP obligations, identifying implementation priorities, and developing practical implementation roadmap aligned to the 10 June 2027 and 10 June 2028 legislative milestones.
Readiness is therefore not a substitute for maturity. It is the mechanism that enables organisations to transition from today’s CIRMP capability to tomorrow’s Enhanced CIRMP obligations.
Together, maturity and readiness provide organisations with a structured methodology for understanding where they are today, determining where they need to be tomorrow, and providing Boards and senior executives with the governance, visibility and assurance needed to oversee successful implementation of the Enhanced CIRMP Rules.
Learn more
Download Pentagram’s Enhanced CIRMP Readiness Assessment Module brochure to explore Pentagram’s approach to assessing organisational readiness, prioritising implementation activities and developing practical Enhanced CIRMP Implementation Roadmap.
