A CIRMP Is Not a Document. It Is a Program.
The Security of Critical Infrastructure Act 2018 places its central requirement on the Critical Infrastructure Risk Management Program. A responsible entity must identify and manage material risks across four hazard vectors, have the program approved by its board or governing body, and report on it to the relevant regulator within 90 days of the end of the Australian financial year.
The four vectors:
Cyber and information security
The vector most operators assess, and the one where the evidence is thinnest. Identifying material risks to availability, integrity, reliability and confidentiality requires knowing what is reachable — which is an external question.
Supply chain
Your suppliers, their access, and the systems they hold on your behalf. From 4 April 2025 business critical data and the secondary systems holding it came into scope, which pulled a large number of providers into other organisations’ programs.
Personnel
Insider risk, vetting and access management. Not assessable from outside, and we say so rather than implying coverage we do not have.
Physical and natural hazards
Site security, environmental and natural hazard risk. Also outside the scope of a passive external assessment.
Programs Are Written From the Inside
A CIRMP is assembled from what the organisation believes it operates. Asset registers, architecture diagrams, system owner interviews, supplier contracts. Every one of those records intent. None records what actually answers on the public internet.
That gap is not theoretical. Across 2026, ASD issued advisory after advisory in which the operative instruction was the same: establish what is reachable from the internet, and reduce it. Internet-facing networking devices targeted by state actors since at least 2015. Management interfaces at service providers leading to customer compromise. Content management systems on forgotten domains. Almost none of it turned on a zero-day.
In July 2026 the point was made bluntly elsewhere: an attacker used valid credentials to enter Romania’s national land registry, mapped the network, attempted extortion, and when refused, deleted the database and its backups. Property transactions stopped nationwide. The agency had spent roughly 0.2 per cent of two decades of digitalisation investment on cyber security.
What a BlackFlag Advisory SOCI Assessment Covers
- External asset discovery — every hostname, subdomain and internet-facing service attributable to your entities, drawn from certificate transparency, passive DNS and public source aggregation, including assets that appear on no register
- Internet-facing management and administrative interfaces — the specific asset class named repeatedly in ASD’s 2026 advisories
- Network edge exposure — routers, firewalls, VPN gateways and SD-WAN controllers, the equipment targeted by the state actors named in the July 2026 joint advisory
- Technology and version fingerprinting, triaged with the CISA Known Exploited Vulnerabilities catalogue, EPSS and SSVC decision points so findings arrive as decisions rather than a severity count
- Credential exposure where your identities, or your suppliers’, appear in published breach and infostealer corpora
- Supply chain surface — the providers holding your business critical data, assessed from outside and without their cooperation
- Hazard vector mapping to the two vectors an external assessment can honestly evidence, with an explicit statement of the two it cannot
Who This Is For
Energy, water and sewerage operators
Among the first asset classes brought into the CIRMP obligation, and the sectors where an outage is measured in public consequence rather than revenue.
Transport, ports and freight
Captured by asset definition rather than by size. Several operators carry obligations without having registered the fact.
Food and grocery
A SOCI sector since the 2021 reforms. Two Mackay sugar mills halted operations after a cyber incident in June 2026 — production stopping, not data leaving, was the damage.
Health care and medical
Carrying SOCI obligations alongside Privacy Act and My Health Record obligations, with three regulators interested in the same estate.
Data storage or processing providers
Business critical data and the secondary systems holding it came into CIRMP scope from 4 April 2025. If you hold data for a responsible entity, their obligation reaches you.
Systems of National Significance
Where enhanced cyber security obligations apply on top of the CIRMP, including vulnerability assessment requirements.
How the Engagement Runs
Five steps. The only ones that require your time are the first and the last.
1. Confirm what is in scope
We agree the entities, domains and internet-facing estate to be assessed, and which of your asset classes the findings should be mapped against.
2. Passive collection
We observe what your organisation exposes using publicly available sources only. No systems, networks or accounts are accessed. Nothing touches operational technology, so no change window is required.
3. Hazard vector mapping
Findings are mapped to the two CIRMP hazard vectors an external assessment can honestly evidence — cyber and information security, and supply chain. We state plainly what we did not assess.
4. Board-ready output
Your CIRMP report must be approved by the board or governing body. The report is written so the evidence behind that approval is legible to the people signing it.
5. Delivery and walkthrough
A dual-audience report and a walkthrough. We remain available for the questions that follow, including from your regulator.
Frequently Asked Questions
The questions we are asked most often by responsible entities, their risk leads and their boards.
Which assets are captured by the SOCI Act?
The Security of Critical Infrastructure Act 2018 covers eleven sectors including energy, water and sewerage, transport, food and grocery, health care and medical, communications, financial services and markets, data storage or processing, defence industry, higher education and research, and space technology. Capture depends on the specific asset definition rather than the sector alone, and many operators are captured without having registered the fact.
What does a CIRMP have to cover?
A Critical Infrastructure Risk Management Program must identify and manage material risks across four hazard vectors: cyber and information security, personnel, supply chain, and physical and natural hazards. It must be written, operational rather than templated, approved by the board or governing body, and reported to the relevant regulator within 90 days of the end of the Australian financial year.
What are the incident reporting timeframes?
Critical cyber security incidents having a significant impact on the availability of the asset must be reported to the Australian Signals Directorate within 12 hours of becoming aware. Other reportable cyber security incidents must be reported within 72 hours. The clock starts when you become aware, not when the investigation concludes.
Does this replace a CIRMP or an AESCSF assessment?
No. A passive external assessment produces evidence for two of the four hazard vectors — cyber and information security, and supply chain — from outside your organisation. It does not assess personnel or physical and natural hazards, and it does not write your CIRMP. It is designed to sit underneath the program as independent evidence.
Do you need access to our OT or control systems?
No, and that is the point. BlackFlag Advisory assessments are passive only. No systems, networks or accounts are accessed, probed or tested at any point. Nothing we do can touch operational technology, so no change window, no authorisation to test, and no operational risk.
Packages and pricing are set out on the assessment packages page. To scope an engagement against your asset classes, book a short call.