1 July 2026: The Data Arrived Before the Security Did
Tranche 2 obligations commenced on 1 July 2026. AUSTRAC enrolment opened 31 March and closed 29 July. Roughly 80,000 to 90,000 Australian businesses are now reporting entities.
The compliance conversation has been almost entirely about collection — what to verify, how to verify it, what to record. The security conversation has barely started, and it is the one that determines what happens next.
Because of Tranche 2, tens of thousands of small Australian professional services businesses are now legally required to collect and retain, for seven years:
- Verified identity documents — passports, driver licences, birth certificates
- Residential addresses and dates of birth
- Beneficial ownership information for corporate and trust clients
- Source of funds and source of wealth evidence — bank statements, tax returns, sale contracts, gift and loan documentation
- Politically exposed person determinations
- Records of suspicious matter assessments, which are themselves highly sensitive
Why This Becomes a Live Problem Quickly
Attackers follow data concentration. The target selection logic through 2026 has been consistent: where sensitive data pools, particularly where it pools in organisations with limited defensive capability. Tranche 2 created tens of thousands of new pools in a single day.
These firms are already being compromised. ASD’s 2026 advisories repeatedly named Australian small and medium businesses — through a large-scale content management system exploitation campaign, through credential harvesting distributed via compromised Australian business websites, and through managed service provider control panels leading to customer compromise. The professions now in Tranche 2 sit squarely in that population.
The retention period works against you. Seven years is a long time to hold a passport scan, and the law removes your option to minimise retention. That makes the security of the archive the only variable you actually control.
What a Tranche 2 Assessment Covers
- Your firm’s full external footprint — every domain, subdomain and internet-facing service attributable to the practice, including legacy and forgotten sites
- Exposed remote access — portals, VPN endpoints and practice management access reachable from the public internet
- Staff credential exposure in published breach and infostealer corpora. In our scan of twenty Australian law firms, this was the most consistently present finding
- Website and CMS exposure, matched against the vulnerability classes ASD named in its 2026 campaign advisories
- Email authentication posture — whether your firm’s domain can be spoofed in a trust-account or settlement fraud attempt
- Third-party surface — your practice management platform, document automation and outsourced IT provider, which hold or reach the same data
- APP 11 mapping with a documented, dated record of the reasonable steps considered
The report is written to be read in a partners’ meeting, not by a security team you do not have.
Who This Is For
Law firms
In scope by designated service rather than by profession. A practice assisting with property transactions or with equity or debt financing is captured.
Accounting practices
Now holding source-of-funds and source-of-wealth evidence — bank statements, tax returns, sale contracts — for seven years.
Conveyancers, real estate agencies and property developers
High transaction volume means the identity archive accumulates faster than in any other Tranche 2 profession.
Trust and company service providers, and precious metals dealers
Frequently the smallest businesses in scope, with the least compliance infrastructure and the most walk-in identification.
How the Engagement Runs
Five steps. The only one that requires your time is the first and the last.
1. Scope
We agree the domains, entities or suppliers in scope and the frameworks the findings should be mapped to. Nothing else is required from you — no access, no credentials, no questionnaire to complete.
2. Passive collection
We observe what your organisation exposes using publicly available sources: certificate transparency logs, passive DNS, published vulnerability data, and public breach and infostealer corpora. No systems, networks or accounts are accessed, probed or tested at any point.
3. Analysis and triage
Findings are validated, deduplicated and prioritised against confirmed exploitation status, exploitation probability and asset exposure — not by severity score alone. Every finding carries the evidence that produced it.
4. Regulatory mapping
Each finding is mapped to the obligation it engages, so the report speaks in the language your Board, auditor, insurer or regulator already uses.
5. Delivery and walkthrough
A dual-audience report: a Board section stating the position in plain terms, and a technical section carrying reproducible evidence. We walk you through it, and we are available for the remediation questions that follow.
Frequently Asked Questions
The questions we are asked most often by partners and practice managers in newly regulated firms.
Who is covered by Tranche 2?
Lawyers, accountants, conveyancers, real estate agents and property developers, trust and company service providers, and dealers in precious metals and stones. The obligation attaches when a business provides a designated service with a geographical link to Australia, so the activity rather than the profession determines scope.
Does Tranche 2 create a cyber security obligation?
Not directly, but the data it requires you to collect and retain does. Seven years of identity documents, source-of-funds evidence and transaction records is personal and in places sensitive information, engaging APP 11 reasonable steps obligations and the Notifiable Data Breaches scheme. The AML obligation creates the data concentration; the Privacy Act governs how you protect it.
We are a small practice. Is this relevant?
Particularly so. ASD named Australian small and medium businesses as impacted in multiple 2026 advisories, including a large-scale content management system exploitation campaign and a credential-harvesting campaign using compromised Australian business websites. Small professional services firms now hold a concentration of identity data with, in most cases, no security function.
Will our clients ask about this?
Corporate clients performing their own third-party risk assessments are increasingly asking their law firm, accountant and conveyancer how identity data is protected. Firms that can answer with independent evidence are better placed than firms relying on assurances.
Packages are set out on the assessment packages page. To discuss scope for your practice, book a short call.