Cyber Security Act 2024 (Cth)
Cyber Security Act 2024 — ransomware payment reporting, limited use protections, and Cyber Incident Review Board
- Requirements
- 5
- Last reviewed
- 16/04/2026
- Next review
- 16/04/2027
- Source
- Royal Assent 29 November 2024
Reconciliation notes
Curated build covering Cyber Security Act 2024 obligations for a DISP-member freight forwarder (~15 staff). Part 2 (smart device security standards) Not Applicable — targets manufacturers/importers/distributors, not end-users. Part 3 (ransomware payment reporting) Applicable if annual turnover exceeds $3M (s.26 threshold mirrors Privacy Act NDB). Part 4 (limited use protections) Reference-only — statutory shield, not an obligation. Part 5 (CIRB) Reference-only — not yet operational as of April 2026. Key interaction: E8 ML2 covers technical controls to prevent ransomware; this Act covers the reporting obligation IF a payment is made despite those controls. DSPF P16 requires DSC/ASD cyber incident notification — separate and parallel to Part 3 reporting. Total requirements: 5. Applicable: 3. Reference-only: 2. Sources: Gadens June 2025 (ransomware reporting in force), Cliffside Cybersecurity March 2026 (full Act guide), Home Affairs FAQ (smart device standards).
Requirements
Showing 5 of 5 requirements
| ID | Clause | Requirement | Applicability | Coverage | Evidence | Gap |
|---|---|---|---|---|---|---|
| CSA-SD-NA-01 | Cyber Security Act 2024 Part 2 (ss.12-24) | Part 2 imposes security standards on manufacturers, importers, and distributors of 'relevant connectable products' — no universal default passwords, published vulnerability reporting mechanism, minimum security update transparency. In force 4 March 2026. Obligations attach to the supply chain (manufacture/import/distribute), not to end-users or purchasers of connected devices. | Not Applicable | Referenced-only | — | Not Applicable — Westlink is an end-user of IoT/connected devices (GPS trackers, warehouse sensors), not a manufacturer, importer, or distributor of connectable products. Re-assess if Westlink begins importing and re-supplying connected hardware to customers. |
| CSA-RR-01 | Cyber Security Act 2024 s.26 (reporting business entity definition) | A 'reporting business entity' is a commercial entity carrying on business in Australia with annual turnover exceeding $3 million in the previous financial year, OR an entity responsible for a critical infrastructure asset under SOCI Act Part 2B regardless of turnover. Reporting obligations under Part 3 apply only to reporting business entities. | Applicable | Partial |
| Low Confirmed: annual turnover ~$45M (2026) — well above $3M threshold. Part 3 obligations are active. Monitor threshold annually as a formality. NDB scheme under Privacy Act Part IIIC also applies at this revenue level. |
| CSA-RR-02 | Cyber Security Act 2024 s.27 (mandatory ransomware payment report) | A reporting business entity must report any ransomware or cyber extortion payment to the Australian Signals Directorate (ASD) within 72 hours of making the payment or becoming aware that a payment was made on the entity's behalf. Report via ReportCyber portal. Required content includes: ABN, contact details, incident details, nature of demand, payment details (amount, method, recipient), extorter information, and communications. No minimum payment threshold — any benefit (monetary or non-monetary) triggers reporting. In force 30 May 2025 (full enforcement from 1 January 2026). | Applicable | Full |
| |
| CSA-RR-03 | Cyber Security Act 2024 s.27 — interaction with NDB and DSPF P16 | Part 3 ransomware payment reporting runs concurrently with and does not displace other notification obligations. A ransomware incident may simultaneously trigger: (a) Part 3 reporting to ASD (72 hours from payment), (b) Notifiable Data Breaches scheme reporting to OAIC and affected individuals (Privacy Act Part IIIC, 30-day assessment window — applies if entity exceeds $3M turnover or is covered by DISP contract terms), (c) DSPF P16 cyber incident reporting to DSC/ASD. Each regime has different triggers, timeframes, recipients, and forms. | Applicable | Gap |
| High No integrated incident response procedure maps the three parallel notification streams (Part 3 / NDB / DSPF P16). Remediation: build a single incident response decision tree that activates the correct notifications based on incident characteristics. High priority — a ransomware event affecting defence-classified data could trigger all three simultaneously with different deadlines. |
| CSA-LU-01 | Cyber Security Act 2024 Part 4 (ss.33-44) | Information voluntarily shared with the National Cyber Security Coordinator (NCSC) during a significant cyber incident receives limited use protections — it cannot be used for civil enforcement or regulatory action against the sharing entity, cannot be disclosed beyond incident response purposes, and does not waive legal professional privilege. Also applies to information in Part 3 ransomware reports — ASD cannot use Part 3 reports for regulatory enforcement against the reporting entity (s.30(6)). In force 30 November 2024. | Reference only | Referenced-only |
| Reference-only — this is a statutory protection, not an obligation. Practical implication: voluntary engagement with ASD/NCSC for incident assistance does not create regulatory exposure. Strengthens the case for early ASD engagement under existing DSPF P16 guidance. Note in incident response procedure. |
Source document
Cyber Security Act 2024 — ransomware payment reporting, limited use protections, and Cyber Incident Review Board
5 normative shall-statements extracted from Cyber Security Act 2024 (Cth) (source: Cyber Security Act 2024 (Cth) — No. 98, 2024). The frontmatter requirements array is the source of truth — this body is rendered by scripts/render_compliance.py.
Coverage summary
| Coverage | Count |
|---|---|
| ✅ Full | 1 |
| 🟡 Partial | 1 |
| 🟠 Ref-only | 2 |
| 🔴 Gap | 1 |
| — N/A | 0 |
Gap severity distribution
| Severity | Count |
|---|---|
| 🔴 Critical | 0 |
| 🟠 High | 1 |
| 🟡 Medium | 0 |
| 🟢 Low | 1 |
Requirements
Clause Cyber Security Act 2024 Part 2 (ss
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| CSA-SD-NA-01 | 🟠 Ref-only | — | N/A — |
Clause Cyber Security Act 2024 Part 4 (ss
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| CSA-LU-01 | 🟠 Ref-only | [TEC-PRO-001 §‘Limited Use Protections’](/wms/TEC-PRO-001#s’Limited Use Protections’) | Reference-only — this is a statutory protection, not an obligation. Practical implication: voluntary engagement with ASD/NCSC for incident assistance does not create regulatory exposure. Strengthens the case for early ASD engagement under existing DSPF P16 guidance. Note in incident response procedure. |
Clause Cyber Security Act 2024 s
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| CSA-RR-01 | 🟡 Partial | QHSE-MAN-001 §‘2.1’ [TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’) | 🟢 Low | Confirmed: annual turnover ~$45M (2026) — well above $3M threshold. Part 3 obligations are active. Monitor threshold annually as a formality. NDB scheme under Privacy Act Part IIIC also applies at this revenue level. |
| CSA-RR-02 | ✅ Full | [TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments) [TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’) | ||
| CSA-RR-03 | 🔴 Gap | [TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’) | 🟠 High | No integrated incident response procedure maps the three parallel notification streams (Part 3 / NDB / DSPF P16). Remediation: build a single incident response decision tree that activates the correct notifications based on incident characteristics. High priority — a ransomware event affecting defence-classified data could trigger all three simultaneously with different deadlines. |
Rendered from frontmatter by scripts/render_compliance.py. Source extraction: scripts/extract_iso9001_requirements.py. Evidence population: scripts/populate_iso9001_evidence.py. Validate: scripts/compliance_validate.py.