CIRMP (Critical Infrastructure Risk Management Program)
Part 2A of the SOCI Act. If you are a responsible entity for a covered critical infrastructure asset, you must have a written risk management program, keep it current, and report on it each year.
Part 2A of the Security of Critical Infrastructure Act 2018 requires specified responsible entities to adopt and maintain a Critical Infrastructure Risk Management Program (CIRMP). In the Act the duty sits next to the cyber incident notification clocks in Part 2B: one is how you manage material risk day to day; the other is how fast you tell government when a cyber incident hits.
The Act's outline for Part 2A is blunt. Section 30AC: the responsible entity must have a CIRMP. Section 30AD: comply with it. Section 30AE: review it. Section 30AF: keep a process to update it. Section 30AG: submit an annual report. Section 30AH sets out what a CIRMP is. Directions to vary and revocation powers sit beside those duties. This page is the program, not the 12-hour / 72-hour cyber notification clocks — those live under soci-clock.
A CIRMP is a written program. It has to identify hazards that could have a relevant impact on the critical infrastructure asset and set out how you minimise or eliminate the material risks of those hazards. The detail of which hazards and which asset classes are pulled in is in the CIRMP Rules made under the Act, not in a blog post. Read the Rules that apply to your asset class before you invent a template.
Annual reporting is part of the duty, not optional stationery. The responsible entity's board, council or other governing body has to approve the annual report and lodge it with the relevant regulator after the Australian financial year. Keep the approved form and the evidence pack with the CIRMP itself so the board is not signing a story it cannot evidence.
Practical desk: name the responsible entity and the asset class in writing. Map which hazards the Rules force you to treat. Tie personnel, cyber, supply chain and physical controls to named owners. Put the CIRMP review cadence next to your Essential Eight evidence and your SOCI cyber incident playbook. A CIRMP that only exists as a PDF in SharePoint is not a program.
Pair this page with soci-act and soci-clock. The program is how you reduce material risk before the incident. The clocks are what you do when the incident is already live.
Fact source: Security of Critical Infrastructure Act 2018 (Part 2A).
