CIRMP physical security is the part of a critical infrastructure risk management program that deals with physical security hazards and natural hazards. Under the SOCI Act rules, every responsible entity that must hold a CIRMP needs processes to identify its physical critical components, control and monitor access to them, respond to unauthorised access and test that its security arrangements work. Since 10/06/2026, nine asset classes also face enhanced physical security requirements, which existing assets must meet by 10/06/2028.
This playbook sets out, step by step, how an operator can implement those requirements in a way that will stand up to its board and to the regulator. It is written for security managers, asset owners and the executives who approve the annual CIRMP report. It sits alongside the SOCI Act and CIRMP explainer, which covers the wider regime.
- The baseline CIRMP physical security rules have applied since 2023 to all 13 asset classes that must hold a CIRMP.
- The enhanced rules add central management of physical security, continuous monitoring of critical components, and separate business hours and out-of-hours measures for nine asset classes.
- Physical security must now account for the physical consequences of cyber, credential, personnel and supply chain hazards, not only intruders and natural events.
- The regulator has signalled a move from education towards penalty-based enforcement, so evidence of implementation matters as much as the written program.
What does the CIRMP require for physical security?
The Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) commenced on 17/02/2023. They require a CIRMP for 13 classes of critical infrastructure asset, including electricity, gas, water, liquid fuel, freight, data storage or processing, designated hospitals, food and grocery, and financial market infrastructure.1
For physical security hazards and natural hazards, section 11 of the rules requires the responsible entity to establish and maintain a process or system in its CIRMP to:
- identify the physical critical components of the asset;
- as far as reasonably practicable, minimise or eliminate the material risk of a physical security hazard to those components, and of a natural hazard to the asset;
- respond to incidents where unauthorised access to a physical critical component occurs;
- control access to physical critical components, restricting it to critical workers or accompanied visitors; and
- test that the security arrangements are effective and appropriate to detect, delay, deter, respond to and recover from a breach.
The CIRMP guidance published by the Cyber and Infrastructure Security Centre (CISC) gives practical examples such as perimeter fencing, time-locked and biometric access, CCTV and motion detection, and bushfire planning, and notes that physical security and natural hazards were the most common cause of incidents with significant impact reported in 2023 to 2024.2
What do the enhanced CIRMP Rules add for physical security?

The Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (LIN 26/075) commenced on 10/06/2026.3 They apply enhanced requirements, on top of the baseline, to critical broadcasting, domain name system, electricity, energy market operator, freight infrastructure, freight services, gas, liquid fuel and water assets. Where the two conflict, the enhanced requirement prevails.
The new section 11A requires those entities to centrally manage physical security and natural hazards, and to consider the physical security consequences of all hazards, including cyber and information security, credential compromise, lateral movement, personnel and supply chain hazards. The rules give examples such as a cyber incident that opens gates, or a supply chain delay that weakens the ability to deter, detect, delay, respond and recover.
The CIRMP must outline the location, ownership and nature of each site, its critical components, and the areas that hold business critical data or critical systems. It must also consider and outline, as far as reasonably practicable:
- access controls that restrict critical components and critical systems to critical workers or accompanied visitors;
- surveillance and security alarm systems that keep critical components and critical systems under continuous monitoring;
- specific protective security measures for business hours and for out-of-hours;
- other measures to deter, detect, delay, respond to and recover from a breach; and
- mitigation and response measures once a physical security incident or consequence is detected.
For assets that were already critical infrastructure assets when the rules commenced, the physical security requirements in section 11A apply after a 24 month grace period, ending on 10/06/2028. Some related measures, including the additional material risks in section 6A and the personnel access management requirements in section 9A(2), have a 12 month grace period ending on 10/06/2027.4 The enhanced CIRMP Rules operator guide covers the full set of changes across all four hazards.
How do you implement CIRMP physical security? An eight step playbook
The steps below follow the order in which the work is usually done. Each produces evidence that belongs in the CIRMP and supports the board’s annual approval.
1. Confirm the obligations and scope
Confirm which assets are critical infrastructure assets, who the responsible entity is, whether each asset falls under the baseline rules only or the enhanced rules as well, and which sites and facilities make up each asset. Record any asset declared under section 51 of the Act, because the enhanced rules do not apply to those declarations made before 10/06/2026.
2. Identify critical components and critical systems
Build a register of the physical critical components at each site, and of the areas holding business critical data or critical systems such as control rooms, communications rooms and server rooms. For enhanced assets, record the location, ownership and nature of each site. This register becomes the spine of the physical security plan.
3. Assess physical security and natural hazards
Assess the threats and vulnerabilities for each critical component and the natural hazards for each site, such as bushfire, flood, storm and heat. A structured security risk assessment aligned with AS ISO 31000:2018 gives the consistent, defensible basis that auditors and boards look for.
4. Map the physical consequences of other hazards
Run a joint session with cyber, operational technology, personnel and procurement staff to trace how their hazards could play out physically: a compromised credential that opens a door, a remote access path to a gate controller, a contractor with unsupervised access, or a supplier delay that leaves a site short of guards. For enhanced assets this is now an explicit requirement.
5. Define and implement the controls
Set out the layered controls that deter, detect, delay, respond and recover, with particular attention to:
- access control that limits critical components to critical workers or accompanied visitors, with visitor escort and key management rules;
- surveillance and alarm systems that give continuous monitoring of critical components, with a defined response to each alarm;
- separate measures for business hours and out-of-hours, including unattended sites; and
- perimeter, building and room hardening proportionate to the risk.
Where electronic security needs to be specified, upgraded or brought under continuous monitoring, the specification should be written against these requirements, not against a product list.
6. Connect physical security to personnel security
Physical access control only works if the list of critical workers is right. Align the physical controls with the personnel requirements: for enhanced assets, section 9A allows a critical worker to be assessed as suitable only after an AusCheck background check and the entity’s own assessment, or where the worker holds a relevant security clearance, and requires the entity to monitor ongoing suitability.
7. Test, exercise and respond
Test that the arrangements work, not only that they exist: alarm response times, access control audits, out-of-hours patrol records and scenario exercises for unauthorised access and natural hazard events. Record the results and the fixes, because testing is a stated requirement of the baseline rules.
8. Document, govern and report
Bring the work together in a centrally managed physical security plan within the CIRMP, assign owners, and set a review cycle. The annual report must be given to the regulator within 90 days after the end of the Australian financial year and must be approved by the board, council or other governing body.
What evidence should a board expect before approving the annual report?
Directors are approving a statement about the program, so they should ask to see evidence that it operates, not only that it is written. A practical evidence pack for physical security includes:
- the critical component register and site outlines, reviewed within the year;
- the current physical and natural hazard risk assessment, with treatment status;
- access control reports showing that only critical workers and escorted visitors reached critical components;
- monitoring and alarm response records, including out-of-hours;
- test and exercise results with the actions taken; and
- incidents involving unauthorised access, with how each was handled.
What further SOCI changes are expected?
An independent review of the SOCI Act was delivered to government on 31/01/2026, and the Government accepted its recommendations in principle.5 The CISC has said it is moving from a light touch compliance approach towards a penalty-based risk management approach, encouraging voluntary compliance first and escalating where necessary.6 Consultation on proposals to streamline and modernise the Act, including its assurance and governance arrangements, has also closed. Until any amendments are made, operators should plan against the current rules and expect closer scrutiny of how well their CIRMP is implemented.
How Agilient supports CIRMP physical security
Agilient provides independent critical infrastructure risk management advice, covering the physical, natural, personnel and supply chain hazard vectors that cyber-led providers often leave to one side. Agilient does not sell or install security equipment, and it works alongside in-house security and risk teams so that they can run the program themselves. Its work includes a SOCI-aligned protective security assessment for a bulk liquid fuel terminal.
CIRMP gap analysis
A review of the current program against the baseline and enhanced physical security rules.
Physical security plan
A centrally managed plan built on the critical component register and site outlines.
Site risk assessments
Physical and natural hazard assessments for critical sites, aligned with AS ISO 31000:2018.
Monitoring and access control
Independent requirements and specifications for continuous monitoring and access control.
Testing and exercises
Control validation and scenario exercises for unauthorised access and natural hazards.
Board assurance
Evidence review and briefing to support the annual report approval.
Agilient works with critical infrastructure operators across Sydney, Melbourne, Brisbane, Adelaide and Canberra.
To see where your program stands now, try the free CIRMP readiness check.
Get your CIRMP physical security ready for 2028
A gap analysis against the enhanced rules shows what needs to change, what it will cost and what can be done now.
Frequently asked questions about CIRMP physical security
What is CIRMP physical security?
Which assets must meet the enhanced CIRMP physical security requirements?
When must existing assets comply with the enhanced physical security rules?
Does the CIRMP require continuous CCTV monitoring?
Who can access critical components under the CIRMP Rules?
Who approves the CIRMP annual report?

- Federal Register of Legislation, Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006), legislation.gov.au
- Cyber and Infrastructure Security Centre, Guidance for the Critical Infrastructure Risk Management Program, cisc.gov.au
- Federal Register of Legislation, Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (LIN 26/075), legislation.gov.au
- Cyber and Infrastructure Security Centre, Enhanced CIRMP implementation factsheet, cisc.gov.au
- Department of Home Affairs, Independent Review of the Security of Critical Infrastructure Act 2018, final report, homeaffairs.gov.au
- Cyber and Infrastructure Security Centre, Our regulatory principles and approach, cisc.gov.au
