- Supports APRA-regulated entity checklist items for Board responsibility, asset classification, controls, incident response, testing, audit, and APRA notifications.
"The Board of an APRA-regulated entity is ultimately responsible"
Verify Australian cyber-security obligations for smart-device security standards and statements, ransomware payment reporting, SOCI critical-infrastructure risk management, and APRA CPS 234 controls.
Each item names the condition to check, the evidence to keep, and the official Act or Rules provision that supports the obligation.
Structured answer sets in this page tree.
Cited legal and guidance references.
Use this checklist for an initial evidence review before supplying a smart device with a , responding to a , operating a critical-infrastructure asset, or maintaining APRA information-security assurance. These are separate regimes with different scope tests and records.
Use these checks when the product is a -grade relevant connectable product that will be acquired in Australia by a consumer. Part 2 applies to products manufactured on or after 29 November 2025 or supplied in Australia, other than as second-hand goods, on or after that date. The operative Smart Devices Rules requirements commenced on 4 March 2026 and exclude desktop or laptop computers, tablet computers, smartphones, therapeutic goods, road vehicles, and road vehicle components.
Use these checks when an entity is impacted by a cyber security incident and has made, or becomes aware that another entity made on its behalf, a to an entity seeking to benefit from the incident.
Use these checks only when the organisation is a for a critical-infrastructure asset to which Part 2A applies and no exemption removes the program duty. Keep this stream separate from Cyber Security Act ransomware reporting: SOCI risk-program obligations attach to the covered asset regardless of whether a payment event occurs.
Use the 10 June 2026 compilation of the risk-management-program rules. It adds for specified broadcasting, domain-name-system, electricity, energy-market-operator, freight, gas, liquid-fuel, and water assets. Existing covered assets generally receive 12 months from the amending instrument's commencement for section 6A and specified parts of sections 8A and 9A, and 24 months for the other enhanced provisions; later-added assets receive the same periods from the date they become critical infrastructure assets.
Use these checks for and groups applying Prudential Standard . The checklist should produce evidence that Board oversight, controls, incident response, testing, and assurance match the criticality and sensitivity of information assets.
Create scoped smart-device, ransomware-reporting, SOCI, and APRA CPS 234 evidence tasks in Sorena.
Turn the checklist into scoped questions for smart devices, ransomware reports, SOCI assets, and CPS 234 controls.
Use Research Copilot to inspect the official sources behind each checklist item.
Review scope, evidence gaps, owners, and next implementation actions with Sorena.
"The Board of an APRA-regulated entity is ultimately responsible"
"within the 72 hour time period for giving the report"
"The statement must include the following information"
"critical infrastructure risk management program"