Skip to main
Help and resources
Register
for My Account
Sign in
to My Account
Search
Australian Government
Federal Register of Legislation
Site navigation
Constitution
Acts
Legislative instruments
Notifiable instruments
Gazettes
Administrative Arrangements
Prerogative instruments
Norfolk Island
Annual survey
We would appreciate it if you could complete our website
survey
, open until 28 November 2025.
1 Announcement
Home
Acts
In force
Text
Details
Authorises
Downloads
All versions
Interactions
Security of Critical Infrastructure Act 2018
In force
Administered by
Department of Home Affairs
Superseded version
View latest version
View as made version
Order print copy
Save this title to My Account
Set up an alert
C2021C00570 C03
03 December 2021
-
01 April 2022
Legislation text
View document
Select value
Act
Filter active
Table of contents
Enter text to search the table of contents
Collapse
Part 1—Preliminary
Collapse
Division 1—Preliminary
1 Short title
2 Commencement
3 Object
4 Simplified outline of this Act
Collapse
Division 2—Definitions
5 Definitions
6 Meaning of interest and control information
7 Meaning of operational information
8 Meaning of direct interest holder
8A Meaning of influence or control
8B Meaning of associate
8C Meanings of subsidiary and holding entity
8D Meaning of critical infrastructure sector
8E Meaning of critical infrastructure sector asset
8F Critical infrastructure sector for a critical infrastructure asset
8G Meaning of relevant impact
9 Meaning of critical infrastructure asset
10 Meaning of critical electricity asset
11 Meaning of critical port
12 Meaning of critical gas asset
12A Meaning of critical liquid fuel asset
12B Meaning of critical freight infrastructure asset
12C Meaning of critical freight services asset
12D Meaning of critical financial market infrastructure asset
12E Meaning of critical broadcasting asset
12F Meaning of critical data storage or processing asset
12G Meaning of critical banking asset
12H Meaning of critical insurance asset
12J Meaning of critical superannuation asset
12K Meaning of critical food and grocery asset
12KA Meaning of critical domain name system
12L Meaning of responsible entity
12M Meaning of cyber security incident
12N Meaning of unauthorised access, modification or impairment
12P Examples of responding to a cyber security incident
Collapse
Division 3—Constitutional provisions and application of this Act
13 Application of this Act
14 Extraterritoriality
15 This Act binds the Crown
16 Concurrent operation of State and Territory laws
17 State constitutional powers
Collapse
Part 2—Register of Critical Infrastructure Assets
Collapse
Division 1—Introduction
18 Simplified outline of this Part
18A Application of this Part
18AA Consultation—rules
Collapse
Division 2—Register of Critical Infrastructure Assets
19 Secretary must keep Register
20 Secretary may add information to Register
21 Secretary may correct or update information in the Register
22 Register not to be made public
Collapse
Division 3—Obligation to give information and notify of events
23 Initial obligation to give information
24 Ongoing obligation to give information and notify of events
25 Information that is not able to be obtained
26 Meaning of notifiable event
27 Rules may exempt from requirement to give notice or information
Collapse
Division 4—Giving of notice or information by agents etc.
28 Requirement for executors and administrators to give notice or information for individuals who die
29 Requirement for corporate liquidators etc. to give notice or information
30 Agents may give notice or information
Collapse
Part 2B—Notification of cyber security incidents
30BA Simplified outline of this Part
30BB Application of this Part
30BBA Consultation—rules
30BC Notification of critical cyber security incidents
30BD Notification of other cyber security incidents
30BE Liability
30BEA Significant impact
30BEB Consultation—rules
30BF Relevant Commonwealth body
Collapse
Part 3—Directions by the Minister
Collapse
Division 1—Simplified outline of this Part
31 Simplified outline of this Part
Collapse
Division 2—Directions by the Minister
32 Direction if risk of act or omission that would be prejudicial to security
33 Consultation before giving direction
34 Requirement to comply with direction
35 Exception—acquisition of property
35AAB Liability
Collapse
Part 3A—Responding to serious cyber security incidents
Collapse
Division 1—Simplified outline of this Part
35AA Simplified outline of this Part
Collapse
Division 2—Ministerial authorisation relating to cyber security incident
35AB Ministerial authorisation
35AC Kinds of acts or things that may be specified in an intervention request
35AD Consultation
35AE Form and notification of Ministerial authorisation
35AF Form of application for Ministerial authorisation
35AG Duration of Ministerial authorisation
35AH Revocation of Ministerial authorisation
35AJ Minister to exercise powers personally
Collapse
Division 3—Information gathering directions
35AK Information gathering direction
35AL Form of direction
35AM Compliance with an information gathering direction
35AN Self-incrimination etc.
35AP Admissibility of information etc.
Collapse
Division 4—Action directions
35AQ Action direction
35AR Form of direction
35AS Revocation of direction
35AT Compliance with direction
35AV Directions prevail over inconsistent obligations
35AW Liability
Collapse
Division 5—Intervention requests
35AX Intervention request
35AY Form and notification of request
35AZ Compliance with request
35BA Revocation of request
35BB Relevant entity to assist the authorised agency
35BC Constable may assist the authorised agency
35BD Removal and return of computers etc.
35BE Use of force against an individual not authorised
35BF Liability
35BG Evidentiary certificates
35BH Chief executive of the authorised agency to report to the Defence Minister and the Minister
35BJ Approved staff members of the authorised agency
Collapse
Division 6—Reports to the Parliamentary Joint Committee on Intelligence and Security
35BK Reports to the Parliamentary Joint Committee on Intelligence and Security
Collapse
Part 4—Gathering and using information
Collapse
Division 1—Simplified outline of this Part
36 Simplified outline of this Part
Collapse
Division 2—Secretary’s power to obtain information or documents
37 Secretary may obtain information or documents from entities
38 Copies of documents
39 Retention of documents
40 Self-incrimination
Collapse
Division 3—Use and disclosure of protected information
Collapse
Subdivision A—Authorised use and disclosure
41 Authorised use and disclosure—performing functions etc.
42 Authorised use and disclosure—other person’s functions etc.
43 Authorised disclosure relating to law enforcement
43A Authorised disclosure to IGIS official
43B Authorised use and disclosure—Ombudsman official
43C Authorised use and disclosure—IGIS official
43D Authorised use and disclosure—ASD
44 Secondary use and disclosure of protected information
Collapse
Subdivision B—Offence for unauthorised use or disclosure
45 Offence for unauthorised use or disclosure of protected information
46 Exceptions to offence for unauthorised use or disclosure
47 No requirement to provide information
Collapse
Part 5—Enforcement
Collapse
Division 1—Simplified outline of this Part
48 Simplified outline of this Part
Collapse
Division 2—Civil penalties, enforceable undertakings and injunctions
49 Civil penalties, enforceable undertakings and injunctions
Collapse
Division 3—Monitoring and investigation powers
49A Monitoring powers
49B Investigation powers
Collapse
Division 4—Infringement notices
49C Infringement notices
Collapse
Part 6—Declaration of assets by the Minister
Collapse
Division 1—Simplified outline of this Part
50 Simplified outline of this Part
Collapse
Division 2—Declaration of assets by the Minister
51 Declaration of assets by the Minister
51A Consultation—declaration
52 Notification of change to reporting entities for asset
Collapse
Part 7—Miscellaneous
Collapse
Division 1—Simplified outline of this Part
53 Simplified outline of this Part
Collapse
Division 2—Treatment of certain entities
53A How certain entities hold interests
54 Treatment of partnerships
55 Treatment of trusts and superannuation funds that are trusts
56 Treatment of unincorporated foreign companies
Collapse
Division 3—Matters relating to Secretary’s powers
57 Additional power of Secretary
58 Assets ceasing to be critical infrastructure assets
59 Delegation of Secretary’s powers
Collapse
Division 4—Periodic reports, reviews and rules etc.
60 Periodic report
60AA Compensation for acquisition of property
60AB Service of notices, directions and instruments by electronic means
60A Review of this Act
60B Review of this Act
61 Rules
Collapse
Endnotes
Endnote 1—About the endnotes
Endnote 2—Abbreviation key
Endnote 3—Legislation history
Endnote 4—Amendment history