Cybersecurity 2026

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

4. Cyber-Resilience 4.1 Cyber-Resilience Legislation

ing controls over information assets and oversight of third-party service providers. Other cyber-resilience obligations for critical infra - structure, the broader financial sector and others, as well as relevant enforcement mechanisms, are dis - cussed elsewhere in this chapter. 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation There is no single legislation in Australia addressing broad-sweeping information technology and cyberse - curity (ITC) certification procedures. However, ITC-relevant certification provisions are rele - vant to the SOCI Act. Specifically, where a responsible entity holds a certain “certificate of hosting certifica - tion (strategic level)” that relates to its critical infra - structure asset, that entity is exempt from needing a critical infrastructure risk management programme. This certificate must be issued under a scheme that is administered by the Commonwealth and is known as the “Hosting Certification Framework” (HCF). This HCF is only available to data centre providers and cloud service providers; and approximately 11 data centre facilities and 14 cloud services were certified. However, the DoHA has paused the HCF registration process until reforms have been completed in line with the DoHA’s Protective Security Policy Frame - work released on 24 July 2025 and tranche 2 of the Commonwealth Cyber Security Uplift reforms. These reforms are still ongoing. For additional context, since 30 June 2022, all govern - ment contracts for hosting services must be with cer - tified service providers. However, this policy require - ment is not restricted to “strategic level” certification per the SOCI Act. Under this framework, there are three certification levels: “strategic”, “assured”, and “uncertified”. Depending on a government depart - ment’s risk profile and data set, they may contract with a “Certified Assured Service Provider”.

There is no specific legislation for cyber-resilience in Australia. However, cyber-resilience requirements have legislative status across various contexts, including: • the risk management programmes required by the legislation already discussed under the SOCI Act for responsible entities of critical infrastructure assets ( 2.2 Critical Infrastructure Cybersecu- rity Requirements ) and the Corporations Act for financial licensees ( 3.3 Key Operational Resilience Obligations ); • other obligations on certain responsible entities concerning TLPT-like requirements ( 3.6 Threat-Led Penetration Testing ); and • the data protection standards for various types of information such as “personal information” ( 6.1 Cybersecurity and Data Protection ) and the healthcare sector ( 6.3 Cybersecurity in the Health- care Sector ). Under the Cyber Security Act, the government is mov - ing towards mandatory security standards for smart devices, with the Cyber Security (Security Standards for Smart Device) Rules 2025 (Cth) set to take effect from 4 March 2026. This framework will be primarily targeted towards the manufacturers and suppliers of these devices. 4.2 Key Obligations Under Legislation Cyber-resilience obligations are imposed on certain responsible entities of critical infrastructure asset by way of the Critical Infrastructure Risk Management Program, which must be adopted, reviewed, and updated. The purpose of these programmes is to identify each hazard with a material risk and minimise, eliminate, or mitigate that hazard (or its material risk). The relevant responsible entities and specific require - ments for these programs are set out in the Security of Critical Infrastructure (Critical infrastructure risk man - agement program) Rules (LIN 23/006) 2023. Additionally for APRA-regulated entities, Prudential Standard CPS 234 imposes obligations relating to information security capability, including maintain -

22 CHAMBERS.COM

Powered by