CIRMP annual report
The board-approved annual attestation for a Critical Infrastructure Risk Management Program. Due within 90 days after the Australian financial year ends.
Part 2A and Part 2AA of the Security of Critical Infrastructure Act 2018 require covered responsible entities to adopt, maintain and comply with a written Critical Infrastructure Risk Management Program (CIRMP). It is an all-hazards program: cyber and information security, personnel, physical security, supply chains, and natural hazards sit in the same risk register.
The governing body must approve an annual report and submit it to the relevant Commonwealth regulator within 90 days after the end of the Australian financial year. For most assets the CISC is the regulator; payment systems report to the Reserve Bank of Australia. Use the approved online form and keep a copy.
The report is an attestation, not a copy of the program. The approved form asks whether the CIRMP was up to date at year end, what significant or relevant-impact incidents occurred, what variations were made, and whether the program was effective in mitigating relevant hazard impacts. Board or governing-body approval must be recorded.
Evidence desk: keep the current program, hazard register, owner and review dates; minutes showing board approval; incident and exercise records; supplier and personnel-control evidence; changes made during the year; and the submitted form plus receipt. A report that says effective without those artefacts is an assertion, not assurance.
Do not confuse this annual report with Part 2B cyber incident reporting. A 12-hour or 72-hour cyber incident clock can run during the year; the annual CIRMP report follows later and does not replace that immediate notification.
See also:
Fact source: CISC, Responsible Entity CIRMP Annual Report.
