Legal authority
Security of Critical Infrastructure Act (Australia, 2018)
The Security of Critical Infrastructure Act 2018 is Australia's federal framework for security obligations, risk management and government assistance concerning specified critical infrastructure. It is defensive infrastructure regulation, not a sanctions, export-control or foreign-investment statute.
Current framework
The official C09 compilation dated 4 June 2026 was current at the review lock. The Act defines covered asset classes and responsible entities, supports the Register of Critical Infrastructure Assets, imposes incident-reporting and risk-management duties, and provides enhanced obligations and government-assistance powers under stated conditions.
Coverage and duty vary by asset and declaration. Registration, cyber-incident reporting, a critical-infrastructure risk-management programme and a direction under government-assistance provisions are separate legal steps. Editors should identify the asset class, responsible entity, duty, commencement and regulator.
The Cyber and Infrastructure Security Centre provides regulatory information within the Department of Home Affairs. A government power in the statute is not evidence that a direction was issued or that an operator failed to comply.
2026 status
Enhanced critical-infrastructure risk-management-programme arrangements commenced on 10 June 2026. They should be distinguished from baseline obligations and from telecommunications-specific arrangements. The applicable rules and declarations determine which assets face the enhanced requirements.
A separate July 2026 consultation proposed further changes to streamline and modernise the Act. Consultation text is not enacted law. The 4 June compilation and commenced subordinate instruments govern until legislation or rules change.
Statecraft context
The Act supports Economic security as national security by reducing vulnerability in systems whose disruption could affect national security, economic stability or public services. Its focus is resilience and continuity, not punishment of a foreign state.
The Foreign Acquisitions and Takeovers Act (Australia, 1975) governs foreign-investment review, while the Defence Trade Controls Act (Australia, 2012, amended 2024) regulates specified defence trade. Within the Economic Kill Chain (EKC), these authorities occupy different stages.
Effectiveness requires evidence about risk reduction, incident response and continuity, not enactment alone. Publication-day review should confirm the latest compilation, rules, declarations and consultation status.
Obligations and escalation
The register obligation supplies ownership and operational information to government under statutory controls. Incident reporting provides time-sensitive notice of specified cyber events. A risk-management programme requires an entity to identify and manage prescribed hazards. These functions create different records and compliance tests.
Enhanced obligations can include information gathering, vulnerability assessment, a risk-management programme or incident-response planning for declared systems of national significance. Declaration and notice matter. The existence of a statutory category does not prove that every asset in the sector has received an enhanced obligation.
Government-assistance powers are escalation tools for serious incidents under stated conditions. A direction, intervention request and voluntary collaboration should not be described as the same act. Any use should be attributed to the responsible minister or agency and dated.
Editors should protect security-sensitive detail while preserving enough information to explain legal authority and outcome. Counts of registered assets, reports or directions need a defined period and denominator. More reports may reflect broader coverage or better reporting rather than a worsening threat environment.
Sources
- Australian legislation, Security of Critical Infrastructure Act series (accessed 30 July 2026).
- Australian legislation, latest Security of Critical Infrastructure Act text (accessed 30 July 2026).
- Cyber and Infrastructure Security Centre, regulatory obligations (accessed 30 July 2026).
- Cyber and Infrastructure Security Centre, July 2026 reform town hall (accessed 30 July 2026).
Recommended citation
Cite this entry
Tennant, James J., ed. 'Security of Critical Infrastructure Act (Australia, 2018).' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 30 July 2026. https://jamesjtennant.com/entries/security-of-critical-infrastructure-act-australia-2018/.
Suggest an edit