
On 10 June 2026, the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (Enhanced CIRMP Rules 2026) commenced, introducing a significant uplift in the way affected responsible entities must understand and manage supply chain risk.
The Enhanced CIRMP Rules 2026 amend the Security of Critical Infrastructure (Critical Infrastructure Risk Management Program) Rules 2023 (CIRMP Rules 2023) made under the Security of Critical Infrastructure Act 2018.
The Enhanced Rules supply chain requirements in section 10A must be implemented by 10 June 2028, providing affected responsible entities with a transitional period to build on their existing Critical Infrastructure Risk Management Program (CIRMP) arrangements and establish the additional systems, processes and capabilities required by the Enhanced Rules.
Section 10 of the CIRMP Rules 2023 already requires responsible entities to address material risks arising from supply chain hazards. This includes risks associated with major suppliers, supply disruption, overreliance on particular suppliers, privileged access by providers, and failures or reduced capacity elsewhere in the supply chain. Section 10A builds on that baseline foundation.
For responsible entities whose critical infrastructure (CI) assets are subject to the Enhanced Rules, the question is no longer simply whether supply chain risks have been identified and managed. Section 10A asks more.
Section 10A introduces an explicit requirement to map supply chains for major suppliers and critical components, requires greater visibility of the risks associated with those dependencies, introduces maximum acceptable outage (MAO) as an explicit consideration, and establishes a more structured vendor assessment process for existing and proposed major suppliers.
In simple terms:
Section 10 asks: What is our supply chain? What supply chain risks could affect our CI asset, and how are we managing them?
Section 10A asks: What are we actually dependent on, where do those dependencies sit across the supply chain, how long can we sustain their loss before disruption to the CI asset becomes unreasonable, and what assurance do we have over the major suppliers behind them?
The Enhanced Rules build upon the existing Baseline CIRMP framework. CI entities, therefore, have an existing foundation to work from. The challenge is determining what can be retained, what needs to be validated or strengthened, and what additional capability section 10A requires.
While the Enhanced Rules are considerably more prescriptive than the original CIRMP Rules, they still leave responsible entities to determine how these requirements should be implemented and integrated within their particular operational environment.
This reflects the broader direction of the Enhanced CIRMP framework: greater prescription around capabilities and processes that should exist, while responsibility for their implementation, integration and governance remains with the responsible entity.
That is where some of the most important implementation questions emerge.
Start with the dependency, not simply the supplier
Traditional supplier risk management often begins with the vendor: Who are our critical suppliers? What contracts do we have? Which vendors present the greatest supply risk?
Section 10A requires a broader perspective. A responsible entity needs to understand the critical dependency chain supporting its CI asset:
CI asset → critical component → product or service → supplier → upstream dependency → people and access → jurisdiction and control → outage and resilience
The question to consider: “What does the CI asset critically depend upon, where do those dependencies sit across the supply chain, who has access, influence or control over them, and what happens if they are disrupted?”
Mapping the supply chain: who actually needs to be captured?
One of the first challenges under section 10A is determining what actually needs to be mapped.
The Rules require affected responsible entities to establish and maintain a system or process in their CIRMP to map their supply chain for major suppliers and critical components across their supply chains.
These are overlapping, but not identical, populations.
Understanding the distinction starts with the definition of a major supplier. Section 3 of the CIRMP Rules defines a major supplier as:
“any vendor that by nature of the product or service they offer, has a significant influence over the security of a responsible entity’s CI asset.”
The critical concept here is “significant influence over the security” of the CI asset.
This is not necessarily determined by procurement spend, contract value, supplier size or commercial importance. Nor does supplying or supporting a critical component, by itself, necessarily determine whether a vendor is a major supplier. The statutory test focuses on the nature of the product or service and the influence that this gives the vendor over the security of the CI asset.
In applying that test, responsible entities will need to consider the substance of the relationship. Relevant factors may include the supplier’s access to the asset, systems or critical components; privileged or remote access; operational or administrative control; ability to maintain, alter or disrupt critical functionality; access to business critical data; and the security consequences if the supplier, its service or its access were compromised.
This is particularly relevant to managed service providers, outsourced operators, technology providers and remote-support providers. A vendor does not need to manufacture or supply a physical critical component to potentially exercise significant influence over the security of the asset.
The distinction between a major supplier and a supplier or dependency supporting a critical component therefore matters. They may overlap, but they should not automatically be treated as the same population. A major supplier may or may not directly support a critical component, while the supply chain supporting a critical component may include suppliers or dependencies that do not themselves meet the definition of a major supplier.
This distinction is important because section 10A applies different requirements to different parts of the supply chain. The prescribed major supplier assessment process applies to existing and proposed major suppliers, while the mapping requirement is framed around major suppliers and critical components across their supply chains. Supply chain risks that could compromise business critical data are also relevant under section 10A, while the broader supply chain hazard requirements in section 10 continue to apply.
Organisations should therefore not start with their existing major supplier register and assume that it represents the complete population relevant to section 10A. A major supplier list is not necessarily a supply chain map.
Existing major supplier classifications should also be revalidated. Suppliers identified under section 10 should be reconsidered against the definition of a major supplier and the nature of the access, influence or control their products or services provide over the CI asset. This may identify suppliers that were previously overlooked, particularly MSPs, outsourced operators, technology providers and remote-support providers.
For some responsible entities, the major-supplier assessment will require capability beyond existing commercial, financial or modern-slavery due-diligence processes. Those systems may provide useful inputs, but section 10A requires additional security, jurisdictional, access, dependency and resilience information to be collected, maintained and analysed over time.
How deep should the map go?
The Rules do not prescribe how many tiers of the supply chain must be mapped. This creates an important implementation question: when has an organisation mapped far enough?
If critical technology is purchased through an Australian reseller, does the map stop there if the true dependency is a sole overseas OEM? Similarly, if an managed service provider (MSP) operates a critical component, is identifying the MSP sufficient where the responsible entity has limited visibility of its subcontractors, offshore support arrangements or technology dependencies?
A rigid approach such as “map to Tier 3” may, therefore, be misleading. A Tier 4 manufacturer could be the true single point of failure, while several Tier 2 suppliers may be operationally inconsequential.
A more useful implementation principle is: Map by dependency, not simply by tier.
The objective should be to understand the upstream dependencies that could materially affect the critical component and ultimately the CI asset. This can also expose hidden concentration risk: apparently diversified Tier 1 suppliers may rely on the same OEM, cloud platform, specialist provider or manufacturing capability.
The question to consider: Do we have supplier diversity or dependency diversity?
Maximum Acceptable Outage: deceptively simple
Section 10A introduces another important concept: Maximum Acceptable Outage (MAO) – the maximum period for which a critical component, service or other thing for the CI asset can be unavailable without unreasonably disrupting the ongoing availability, integrity, reliability or confidentiality of the asset.
The definition is fundamentally asset centric, but the Enhanced Rules do not prescribe a methodology for determining when disruption becomes “unreasonable”. That judgement, therefore, needs to be made and supported by the responsible entity. It should not be reduced simply to organisational risk appetite or commercial tolerance.
Determining MAO will require consideration of the consequences of disruption to the CI asset and the dependencies supporting it. For entities subject to the Enhanced Rules, this also sits within the broader context of section 6A, which introduces material risks associated with impairment of asset functions that could prejudice Australia’s social stability, economic stability, national security or defence.
Many organisations already maintain Recovery Time Objectives, Maximum Tolerable Periods of Disruption, service-level commitments and other business continuity measures. These may provide valuable inputs, but they should not simply be relabelled as MAO without testing whether they answer the statutory definition.
MAO also needs to connect to the supply chain dependency itself: supplier product/service → critical component → CI asset
This enables the organisation to understand how disruption of a supplier, product or service could affect a critical component and ultimately the CI asset, and whether existing recovery capability is sufficient.
Importantly, MAO is not recovery capability. If a critical component has an MAO of eight hours but restoration takes 48 hours, the MAO does not become 48 hours. The difference exposes a resilience gap that may require redundancy, strategic spares, alternative supply, manual operation, internal capability or other reasonably practicable treatment.
The implementation challenge is to establish a defensible asset-level tolerance and test whether the supply chain can actually support it.
FOCI: useful guidance, but not the whole answer
Section 10A also establishes a structured vendor assessment process for existing and proposed major suppliers, including consideration of foreign legal requirements, jurisdictional restrictions or impediments, sanctions, and the supplier’s access, influence and control over the CI asset.
The Department of Home Affairs’ publication Foreign Ownership, Control and Influence (FOCI) Risk Assessment Guidance provides a useful foundation. It assists organisations to examine ownership and control, foreign-state relationships, jurisdictional and legal exposure, access and control, subcontractors, sanctions, geopolitical developments, risk treatment and reassessment.
However, FOCI exposure is not static. Ownership and control can change, companies can be acquired, subcontractors and jurisdictions can change, data and support arrangements can move offshore, and geopolitical or sanctions environments can shift. Organisations need mechanisms to identify and respond to material changes throughout the ongoing supplier relationship, rather than relying on a point-in-time assessment.
Section 6A reinforces the need to consider material risks at the CI asset level rather than in isolation within individual hazard domains. A FOCI-related risk identified through another hazard domain may therefore have implications for supply chain risk and should be assessed accordingly.
This may include contractual notification requirements for material changes in ownership, control, parent entities, key subcontractors, jurisdictions, data locations or material upstream dependencies, together with appropriate review, additional control and exit rights where the supplier’s risk profile materially changes.
Responsible entities should also consider upstream concentration and common dependency risk, the supplier’s own capability to identify and manage its supply chain, and the level of evidence needed to verify supplier assertions proportionate to the risk.
A questionnaire completed at procurement is not, by itself, ongoing assurance.
Supply chain dependencies may also create critical worker obligations
Section 10A has an important intersection with the enhanced personnel security requirements in section 9A.
Personnel engaged through major suppliers, MSPs, technology providers, maintenance providers and other suppliers may fall within the definition of a critical worker where they are contractors or subcontractors of the responsible entity and the other statutory criteria are satisfied.
This is particularly relevant where those personnel have access to, or control and management of, critical components and their absence or compromise could prevent the proper functioning of, or cause significant damage to, the CI asset.
This means that supply chain mapping should not stop at identifying the organisation providing the product or service. It should also identify the people within the supply chain whose roles and access may bring them within the critical worker requirements.
For supplier personnel who meet the definition of a critical worker, section 9A brings them within the enhanced suitability and access-management framework. Depending on the applicable pathway, this includes an AusCheck background check followed by the responsible entity’s own suitability assessment, or an eligible Australian Government security clearance, together with ongoing monitoring of developments or changes that may affect suitability.
Importantly, an AusCheck background check is not itself a determination of suitability. Where that pathway is used, the responsible entity must subsequently make its own organisational assessment of the individual’s suitability.
The practical connection is therefore:
Critical component → supplier dependency → supplier personnel → critical worker determination → suitability and ongoing assurance
For organisations that rely heavily on outsourced operations, remote support, specialist maintenance or MSP arrangements, this could materially expand the population of workers that needs to be considered under the enhanced personnel security framework set in section 9A.
It also creates an important implementation question: how will the responsible entity meet its critical worker obligations where the relevant individuals are employed or engaged through its suppliers?
The responsible entity may not control those employment relationships directly, yet it will need arrangements that enable it to meet the applicable section 9A requirements.
In practice, this may require organisations to translate their section 9A requirements into supplier contracts, access conditions and operational processes, including requirements to identify relevant personnel, facilitate AusCheck background checks or verify eligible security clearances, support the responsible entity’s suitability assessment and ongoing monitoring, notify relevant changes, and remove or modify access where requirements are no longer satisfied.
The question to consider: Do our supplier contracts, access arrangements and operational processes give us the ability to meet our critical worker obligations for relevant supplier personnel?
Key implementation questions for industry
As responsible entities begin preparing for section 10A, some questions deserve particular attention:
- What actually constitutes our supply chain for the CI asset?
- How are we determining which suppliers have “significant influence over security” and, therefore, qualify as major suppliers? Who owns that determination?
- How are suppliers and dependencies classified: major supplier, critical component dependency, both, or neither?
- How deeply must we map the supply chain to understand the real dependency chain and identify hidden concentration or single points of failure?
- Can we see behind resellers, integrators and MSPs to the actual OEM, platform, manufacturer or upstream service dependency? If not, how might we?
- Who determines MAO, on what basis, and can we defend the number?
- What happens when supplier recovery capability exceeds the MAO of the critical component it supports?
- What do we do when a major supplier cannot or will not disclose its upstream dependencies?
- What evidence demonstrates that reasonably practicable alternatives have genuinely been considered where dependencies cannot readily be removed or diversified?
- What changes in ownership, control, jurisdictions, subcontractors, access or dependencies should trigger reassessment?
- Who owns the integrated asset-level picture? Procurement may understand the contract, Engineering the component, Cyber the access, Security the FOCI exposure and Resilience the outage tolerance—but who brings those perspectives together?
Where to start: practical implementation priorities
Section 10A builds on existing section 10 arrangements. For responsible entities preparing for implementation, the task is to determine what can be retained, what needs to be validated or strengthened, and what needs to be newly implemented.
Seven practical priorities provide a starting point:
- Confirm critical components: validate the existing inventory and establish a defensible common foundation for supply chain and personnel security.
- Validate supply chain risks and establish a common taxonomy: align how Procurement, Engineering, Risk, People and Culture, Cyber, Security and Resilience identify and classify supply chain risks and dependencies.
- Revalidate and classify suppliers and dependencies: reconsider the existing major supplier population and distinguish major suppliers, critical component dependencies, both, or neither.
- Map major suppliers and critical component supply chains: look beyond immediate contractual counterparties where relevant to identify upstream dependencies, concentration and single points of failure.
- Connect supplier personnel to critical worker requirements: identify supplier and MSP personnel who may meet the critical worker definition and establish the contractual, access and operational arrangements needed to meet the relevant section 9A requirements.
- Determine and evidence MAO: establish defensible asset and critical component outage tolerances and test whether supplier and service recovery capabilities can support them.
- Embed major supplier assessment into the procurement lifecycle: assess proposed major suppliers before new dependencies are created, reassess existing major suppliers, translate treatment into contractual arrangements, and establish triggers for ongoing review.
Conclusion
Section 10A requires responsible entities to develop a defensible understanding of the critical dependencies supporting their CI asset, where those dependencies sit, and how the resulting risks are managed. It builds materially on section 10 by requiring greater visibility, analysis and assurance over critical supply chain dependencies.
The question for Boards to consider is: Do we understand the dependencies that sustain our CI asset, how long their loss can be sustained before disruption becomes unreasonable, who has access, influence or control over them, and whether we have sufficient assurance and resilience?
That is the shift from mapping the supply chain for compliance to understanding it for risk management, assurance and security.
Learn more
Download Pentagram’s Enhanced CIRMP Readiness Assessment Module brochure to explore Pentagram’s approach to assessing organisational readiness, prioritising implementation activities and developing a practical Enhanced CIRMP Implementation Roadmap.
You can also explore Pentagram’s course, How to Establish a Supply Chain Risk Management Framework, which provides a practical approach to assessing, managing and mitigating risks associated with third-party suppliers, with a focus on security, compliance and resilience.
