Staff member holding an identification badge, the kind of credential controlled under CIRMP personnel security requirements

SOCI playbook

CIRMP personnel security playbook

Critical workers, AusCheck background checks and the section 9A suitability rules, step by step.

CIRMP personnel security is the part of a critical infrastructure risk management program that deals with personnel hazards: the risk that a trusted insider, through malice or negligence, harms a critical infrastructure asset. Under the SOCI Act rules, every responsible entity that must hold a CIRMP needs a process to identify its critical workers, allow them access to critical components only once they are assessed as suitable, and manage the risks from malicious or negligent staff and from off-boarding. Since 10/06/2026, nine asset classes also face enhanced requirements, including mandatory background checking, which existing assets must meet by 10/06/2028.

This playbook is the second in Agilient’s SOCI series. It sets out, step by step, how an operator can build a critical worker program that will stand up to its board and to the regulator. It is written for security, human resources and risk managers, and for the executives who approve the annual CIRMP report. It sits alongside the CIRMP physical security playbook, because physical access control only works when the list of critical workers is right.

  • The baseline personnel rules in section 9 of the CIRMP Rules have applied since 2023 to every asset class that must hold a CIRMP. Using AusCheck is optional under the baseline.
  • For nine enhanced asset classes, section 9A allows a critical worker to be assessed as suitable only after an AusCheck background check and the entity’s own assessment, or where the worker holds an active Negative Vetting 1 or higher security clearance.
  • Enhanced assets must also monitor ongoing suitability, repeat background checks at least every five years, and manage access risks from credentials, non-critical workers and people joining or leaving.
  • AusCheck advises that on-boarding a responsible entity can take up to six months, so operators facing the 2027 and 2028 deadlines should start now.
The baseline

What does the CIRMP require for personnel security?

The Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) require a CIRMP for 13 classes of critical infrastructure asset. For personnel hazards, section 9 requires the responsible entity to establish and maintain a process or system in its CIRMP to:1

  • identify its critical workers;
  • permit a critical worker to access critical components of the asset only where the worker has been assessed as suitable; and
  • as far as reasonably practicable, minimise or eliminate the material risks arising from malicious or negligent employees or contractors, and from the off-boarding of outgoing employees and contractors.

The suitability process may be an AusCheck background check, but under the baseline rules it does not have to be. Where an entity does use AusCheck, the check must cover the matters set out in the rules, identity must be verified both electronically and in person, and the entity must tell the Secretary if a worker no longer needs a check. In assessing suitability, the entity must consider the advice AusCheck provides, whether giving the worker access would be prejudicial to security, and any other relevant information.

The SOCI Act defines a critical worker as an employee, intern, contractor or subcontractor of the responsible entity whose absence or compromise would prevent the proper function of the asset or could cause significant damage to it, as assessed by the entity, and who has access to, or control and management of, a critical component of the asset.2 The CIRMP guidance published by the Cyber and Infrastructure Security Centre (CISC) gives examples such as a chief information security officer, control room operators and IT administrators with unrestricted access rights.3

What changed

What do the enhanced CIRMP Rules add for personnel security?

Operators in an energy control room, a common location for critical workers under CIRMP personnel security rules

The Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (LIN 26/075) commenced on 10/06/2026.4 They add section 9A for critical broadcasting, domain name system, electricity, energy market operator, freight infrastructure, freight services, gas, liquid fuel and water assets.

Section 9A has three main parts. First, access management: the CIRMP must minimise or eliminate the material risk from unauthorised or unsupervised access to critical components, the compromise or misuse of credentials and privileged access, access by people who are not critical workers, and incoming and outgoing critical workers.

Second, a narrower test of suitability. A critical worker can be assessed as suitable only if:

  • the worker has had an AusCheck background check, and the entity has then assessed the worker as suitable, considering the same matters as the baseline rules; or
  • the worker held a relevant security clearance when identified as a critical worker, meaning an active clearance at Negative Vetting 1 or higher issued by an authorised Australian Government entity.

Where a worker cannot meet either pathway, the CIRMP must set out the risk of employing that worker and the actions taken, or to be taken as soon as reasonably practicable, to minimise or eliminate it.

Third, ongoing suitability. The entity must proactively monitor, identify and act on developments that may affect a critical worker’s suitability. AusCheck background checks for workers who need ongoing access must be repeated at least every five years, and a worker relying on a clearance must have it revalidated, or complete an AusCheck check and suitability assessment, before it lapses.

For assets that were already critical infrastructure assets when the rules commenced, the access management requirements in section 9A(2) apply from 10/06/2027. The remaining section 9A requirements, including mandatory background checking and ongoing monitoring, apply after a 24 month grace period ending on 10/06/2028.5 The enhanced CIRMP Rules operator guide covers the full set of changes across all four hazards.

Background checks

What does an AusCheck critical infrastructure background check cover?

AusCheck, within the Department of Home Affairs, conducts the critical infrastructure background check. The check covers identity verification, criminal history, a national security assessment by ASIO and the person’s entitlement to work in Australia.6

Criminal history is assessed against criteria set out in the AusCheck Regulations, which group relevant offences into two levels: serious offences such as terrorism, treason, murder and weapons offences, and a second level covering offences such as fraud, drug offences, money laundering and theft.7 AusCheck then advises the responsible entity whether the person has an unfavourable criminal history, whether the ASIO assessment is adverse or qualified, and whether the person has work entitlement. AusCheck can also advise the entity of a material change in the person’s criminal history after the check.

The decision on suitability remains with the responsible entity. AusCheck provides the advice; the entity must weigh it with the other relevant information and make a documented decision. Before any checks can start, the entity must complete AusCheck’s on-boarding requirements, which AusCheck advises can take up to six months.6

The playbook

How do you implement CIRMP personnel security? An eight step playbook

The steps below follow the order in which the work is usually done. Each produces evidence that belongs in the CIRMP and supports the board’s annual approval.

1. Confirm the obligations and scope

Confirm which assets are critical infrastructure assets, who the responsible entity is, and whether each asset falls under the baseline rules only or the enhanced rules as well. The answer decides whether AusCheck checking is a choice or, for enhanced assets, effectively the default pathway.

2. Identify the critical workers

Apply the statutory test role by role: would this person’s absence or compromise stop the asset working properly or cause significant damage, and do they have access to, or control of, a critical component? Include contractors and subcontractors, not only employees. Record the reasoning, because the CIRMP should list the critical workers and the personnel risks that could affect the asset.

3. Map access to critical components

Link each critical worker to the physical critical components and critical systems they can reach, including privileged system accounts and remote access. This map joins the personnel program to the critical component register used for CIRMP physical security, and it shows where people who are not critical workers still have access that needs to be removed or supervised.

4. Set the suitability process

Decide which pathway applies to each group of workers, write the suitability criteria, and name who makes the decision. For enhanced assets, identify the workers who already hold an active clearance at Negative Vetting 1 or higher and those who will need an AusCheck check. Start AusCheck on-boarding early, and involve human resources, privacy and industrial relations advisers, because checks affect recruitment, contracts and the handling of personal information.

5. Manage joiners, movers and leavers

Tie suitability and access to the employment lifecycle. A person should not reach a critical component before the suitability decision is made, access should change when a role changes, and off-boarding should remove physical access, credentials and privileged accounts on the day a person leaves. Off-boarding risk is a baseline requirement, and incoming and outgoing critical workers are named in the enhanced rules.

6. Monitor ongoing suitability

Suitability is not a one-off decision. Set out how the entity will learn of and act on relevant changes, such as AusCheck advice of a change in criminal history, self-reported matters and concerning behaviour. For enhanced assets, schedule background checks to repeat at least every five years and track clearance expiry dates so that revalidation happens before a clearance lapses.

7. Handle exceptions and address the insider risk

Where a critical worker cannot meet the suitability requirements, document the risk and the treatment, such as supervision, reduced access or a changed role. Address malicious and negligent insider risk more broadly through clear policies, reporting channels and security awareness training for critical workers and their managers.

8. Document, govern and report

Bring the work together in the CIRMP, assign owners, and set a review cycle. The annual report must be given to the regulator within 90 days after the end of the Australian financial year and must be approved by the board, council or other governing body. The CISC has advised that entities do not need to report on the enhanced measures in the 2025 to 2026 reporting period, so the 2026 to 2027 report is the first where boards should expect to see them.5

Board assurance

What evidence should a board expect before approving the annual report?

Directors are approving a statement about the program, so they should ask for evidence that the personnel controls operate. A practical evidence pack includes:

  • the current list of critical workers, with the basis for each identification;
  • the proportion of critical workers assessed as suitable, by pathway, and any exceptions with their treatment;
  • access reviews showing that only suitable critical workers, or supervised others, reached critical components;
  • off-boarding records showing access and credentials removed on time;
  • the schedule of background check renewals and clearance expiries; and
  • personnel security incidents and how each was handled.
What is next

Why act on critical worker requirements now?

The CISC has said it is moving from a light touch compliance approach towards a penalty-based risk management approach, encouraging voluntary compliance first and escalating where necessary.8 For enhanced assets, the lead times are real: AusCheck on-boarding can take months, and every critical worker without a qualifying clearance will need a check before the 10/06/2028 deadline. Identifying critical workers and mapping their access can be done now, and it improves security whether or not the enhanced rules apply.

How we help

How Agilient supports CIRMP personnel security

Agilient provides independent critical infrastructure risk management advice, covering the personnel, physical and supply chain hazard vectors that cyber-led providers often leave to one side. Agilient does not conduct background checks, which are carried out by AusCheck, and it works alongside in-house security, risk and human resources teams so that they can run the program themselves.

Critical worker identification

A role-by-role review against the statutory test, with the reasoning recorded for the CIRMP.

Suitability framework

Criteria, decision rules and records for AusCheck and clearance pathways, and for exceptions.

Access and lifecycle review

Mapping of critical workers to critical components, and joiner, mover and leaver controls.

Personnel risk assessment

Insider threat and personnel hazard assessment, aligned with AS ISO 31000:2018.

Awareness training

Security awareness for critical workers and their managers, including insider risk.

Board assurance

Evidence review and briefing to support the annual report approval.

Agilient works with critical infrastructure operators across Sydney, Melbourne, Brisbane, Adelaide and Canberra.

To see where your program stands now, try the free CIRMP readiness check.

Get your critical worker program ready for 2028

A short briefing will show which of your workers are critical workers, which pathway applies to each, and what needs to start now.

FAQs

Frequently asked questions about CIRMP personnel security

What is a critical worker under the SOCI Act?
A critical worker is an employee, intern, contractor or subcontractor of the responsible entity for a critical infrastructure asset whose absence or compromise would prevent the proper function of the asset or could cause significant damage to it, as assessed by the entity, and who has access to, or control and management of, a critical component of the asset.
Is an AusCheck background check mandatory for critical workers?
Under the baseline CIRMP Rules, an AusCheck background check is one way to assess suitability but is not required. For the nine asset classes covered by the enhanced rules, a critical worker can be assessed as suitable only after an AusCheck background check and the entity’s own assessment, or where the worker holds an active security clearance at Negative Vetting 1 or higher.
What does an AusCheck critical infrastructure background check cover?
The check covers identity verification, criminal history assessed against criteria in the AusCheck Regulations, a national security assessment by ASIO, and the person’s entitlement to work in Australia. AusCheck advises the responsible entity of the outcome, and the entity makes the suitability decision.
When must existing assets comply with the enhanced personnel security rules?
For assets that were critical infrastructure assets when the enhanced rules commenced on 10/06/2026, the access management requirements in section 9A(2) apply from 10/06/2027, and the remaining section 9A requirements, including mandatory background checking and ongoing monitoring, apply from 10/06/2028.
How often must critical worker background checks be repeated?
For assets covered by the enhanced rules, AusCheck background checks for critical workers who need ongoing access must be repeated at least every five years, and the entity must monitor and act on developments that may affect a worker’s suitability between checks.
What happens if a critical worker cannot meet the suitability requirements?
For enhanced assets, the CIRMP must set out the risk of employing a critical worker who cannot meet the suitability requirements, and the actions taken, or to be taken as soon as reasonably practicable, to minimise or eliminate that risk, such as supervision or reduced access.
Security gates controlling staff access in an office lobby
References

  1. Federal Register of Legislation, Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006), legislation.gov.au
  2. Federal Register of Legislation, Security of Critical Infrastructure Act 2018, legislation.gov.au
  3. Cyber and Infrastructure Security Centre, Guidance for the Critical Infrastructure Risk Management Program, cisc.gov.au
  4. Federal Register of Legislation, Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (LIN 26/075), legislation.gov.au
  5. Cyber and Infrastructure Security Centre, The enhanced critical infrastructure risk management program: a snapshot, cisc.gov.au
  6. AusCheck, Critical infrastructure: information for responsible entities, auscheck.gov.au
  7. Federal Register of Legislation, AusCheck Legislation Amendment (Critical Infrastructure Background Check) Regulations 2023, legislation.gov.au
  8. Cyber and Infrastructure Security Centre, Our regulatory principles and approach, cisc.gov.au