Skip to navigation Skip to content

Submission to the consultation on proposed amendments to streamline and modernise the Security of Critical Infrastructure Act 2018


Submission to the consultation on proposed amendments to streamline and modernise the Security of Critical Infrastructure Act 2018

The Business Council of Australia (BCA) supports the intent behind the Tranche 2 amendments to the Security of Critical Infrastructure Act 2018. The key issue is not whether the framework should be modernised, but whether the reforms genuinely reduce duplication or simply shift it into Rules, forms and administrative processes.

The BCA’s key points are:

  • Recognise equivalent regimes: Remove duplicated obligations where another framework achieves the same outcome, and make exemptions available to newly captured entities at the point of capture.
  • Set proportionate coverage and responsibility: Use objective, self-assessable criteria, assess criticality by operational consequence rather than financial size, and assign duties according to what each entity actually controls.
  • Make assurance proportionate: Calibrate assurance to risk, recognise existing audits and certifications, and retain safeguards on the use of annual compliance reports so entities are not discouraged from candidly disclosing gaps.
  • Coordinate implementation: Publish a consolidated plan covering Tranche 1, Tranche 2 and the CIRMP Rules, with 12 to 24 months’ transition for newly captured entities.

Read our full submission here.