FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
25of25items
Across 7 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Australia Cyber Security Act recordkeeping

What records should teams keep under the Australia Cyber Security Act 2024?

For smart devices, manufacturers and suppliers must keep the statement of compliance for the five-year period set by the Rules. The statement must identify the product type and batch, the manufacturer, an authorised representative, and any other authorised representatives in Australia, as well as compliance declarations, the defined support period, signatory details, and the place and date of issue. Keeping the product evidence behind the statement is a practical way to support those declarations, but the cited Rules prescribe the five-year period for the statement rather than every supporting record.

For ransomware payment reporting, keep a report file that can show whether the entity was a reporting business entity, when the payment was made or discovered, what information was known or findable by reasonable search or enquiry within the 72-hour reporting period, and what was submitted to the designated Commonwealth body. The Act and ransomware reporting rules do not prescribe a retention period for that report file. Retaining it with the source evidence is an operational recommendation, subject to other applicable legal, security, privacy, and records-management requirements.

  • Smart-device evidence: product and batch identifier, manufacturer details, an authorised representative, any other authorised representatives in Australia, compliance declaration, defined support period, signatory, place and date of issue, and the retained statement.
  • Ransomware report evidence: reporting-entity analysis, incident timing and awareness timing, infrastructure and customer impact, ransomware or malware variant, exploited vulnerabilities, demand amount or benefit, payment amount or benefit, method of provision, and communications with the extorting entity.
  • Overlap evidence: record SOCI status only where the entity is a responsible entity for a Part 2B critical infrastructure asset, and record APRA status only where the organisation is APRA-regulated under CPS 234.
Citations
Australia Cyber Security Act recordkeeping

What ransomware payment evidence should the record contain?

Build the ransomware record around the required report fields. The Act requires contact and business details for the reporting entity or another payer, the cyber security incident and its impact, the extortion demand, the ransomware payment, and communications with the extorting entity.

The 2025 ransomware reporting rules make those categories more concrete. They add an Australian Business Number (ABN), if any, and address details, incident occurrence and awareness timing, impact on infrastructure and customers, ransomware or malware variant, exploited vulnerabilities, information useful to government response, payment quantum and method, and the nature, timing, and description of communications or negotiations.

Keep the filed report and independently obtained incident evidence distinguishable. The Act's use, disclosure, and admissibility protections apply to information obtained through the statutory reporting path and contain exceptions; they do not prevent a body from using the same information to the extent it was obtained through another route.

  • Keep a dated trigger note showing when the payment was made or when the organisation became aware another entity paid on its behalf.
  • Preserve the facts that were known or reasonably searchable inside the 72-hour window, plus a later correction trail if more facts were found after submission.
  • Record the source of each material fact, access controls, disclosure decisions, and any legal professional privilege claim without assuming that filing creates privilege or a general immunity.
  • Keep evidence of any SOCI reporting-business-entity limb separately from ordinary turnover analysis, because section 26 of the Act identifies responsible entities for assets to which Part 2B applies as a distinct path into the ransomware duty.
Citations
Cyber Security Act 2024

Supports the ransomware payment trigger, 72-hour timing, statutory report categories, and the qualified use, disclosure, privilege, and admissibility protections in sections 29 to 32.

Australia Cyber Security Act recordkeeping

How should teams handle SOCI and APRA overlap in recordkeeping?

Do not merge every Australian cyber record into the Cyber Security Act file. SOCI overlap arises where section 26 of the Cyber Security Act covers a responsible entity for a critical infrastructure asset to which Part 2B of the SOCI Act applies. APRA overlap applies only to an APRA-regulated entity subject to CPS 234. CPS 234 is a separate prudential standard, so its incident and material-control-weakness notification records do not become Cyber Security Act records merely because the same event is involved.

Keep the Cyber Security Act submission evidence separate from adjacent SOCI or APRA evidence. Record which entity was in scope, which asset or prudential entity was affected, which regulator or body was notified, and which facts satisfied each regime's required fields. Do not omit a required fact merely because the same incident was reported through another route.

  • Mark SOCI overlap only when the affected entity or asset analysis shows a responsible entity for a Part 2B critical infrastructure asset.
  • Mark APRA overlap only when the incident involves an APRA-regulated entity subject to CPS 234; keep APRA notification evidence separate from the Cyber Security Act ransomware payment report.
  • Do not use a smart-device statement file as evidence for ransomware reporting unless it actually proves a required ransomware report fact.
Citations
Australia Ransomware Payment Reporting: Threshold and Report Content

When does Australia's Cyber Security Act require a ransomware payment report?

Part 3 applies only where an incident has occurred, is occurring, or is imminent; it is a cyber security incident that has had, is having, or could reasonably be expected to have a direct or indirect impact on a reporting business entity; an extorting entity makes a demand to benefit from the incident or its impact; and the reporting business entity provides, or knows another entity has provided on its behalf, a payment or benefit directly related to that demand.

The cyber security incident test is narrower than a general label for any digital disruption. Section 9 requires an event covered by the SOCI Act meaning or an unauthorised impairment of electronic communications to or from a computer, plus a listed constitutional connection. For incidents outside the critical-infrastructure-asset and constitutional-corporation limbs, section 26 presumes the event is a cyber security incident if it was probably internet-enabled, probably impaired a computer's connection, or probably seriously prejudiced specified Australian interests. That presumption does not create civil-penalty liability if the relevant condition did not exist in fact.

A reporting business entity is either a responsible entity for a critical infrastructure asset to which Part 2B of the Security of Critical Infrastructure Act 2018 applies, or an entity carrying on business in Australia whose annual turnover for the previous financial year exceeds the turnover threshold and that is not a Commonwealth body, State body, or responsible entity for a critical infrastructure asset under the other limb.

The 2025 Rules prescribe a $3 million threshold for the previous financial year. Section 26 of the Act says annual turnover must exceed that threshold, so turnover of exactly $3 million does not satisfy the ordinary-business limb. If the business operated for only part of the previous financial year, the Rules prorate the threshold: $3 million multiplied by the number of days the business operated in that year, divided by the number of days in the year. The Act still requires turnover to exceed the resulting amount.

Part 3 and the Ransomware Payment Reporting Rules commenced on 29 May 2025. Commonwealth bodies and State bodies are excluded from the ordinary-business limb. A responsible entity for a critical infrastructure asset must use the separate limb, which applies only where SOCI Act Part 2B applies to the asset.

The current cyber.gov.au form describes its ordinary-business option as turnover that is equal to or exceeds $3 million. That wording conflicts with section 26 of the Act, which says turnover must exceed the prescribed threshold. For turnover of exactly $3 million, preserve the calculation and seek confirmation from Home Affairs rather than treating the form label as an amendment to the Act.

  • Scope evidence: entity status at the time of payment, whether it carries on business in Australia, prior-financial-year turnover, any partial-year calculation, and whether it is the responsible entity for a critical infrastructure asset to which Part 2B applies.
  • Incident evidence: why the event is treated as a cyber security incident and how it directly or indirectly impacted the reporting business entity.
  • Payment evidence: the extortion demand, who paid or provided the benefit, whether the payment was made on behalf of the reporting business entity, and when the entity made the payment or became aware it had been made.
Citations
Cyber Security Act 2024

Sections 9, 26, and 27 support the cyber-security-incident test and limited presumption, the complete payment-report trigger, the requirement for ordinary-business turnover to exceed the prescribed threshold, the separate SOCI responsible-entity limb, 72-hour timing, and report-content categories.

Australia Ransomware Payment Reporting: Threshold and Report Content

What must an Australian ransomware payment report contain within 72 hours?

The reporting business entity must give the designated Commonwealth body a ransomware payment report within 72 hours of making the ransomware payment or becoming aware that another entity made it on its behalf, whichever applies. The Australian Government provides the current reporting form through cyber.gov.au.

The Act requires the report to include information the reporting business entity knows or can find out by reasonable search or enquiry at the time of reporting. The report must cover contact and business details for the reporting business entity if it made the payment, or the other entity if another entity paid; the cyber security incident and its impact; the extortion demand; the ransomware payment; and communications with the extorting entity about the incident, demand, and payment.

The Rules add detail: ABN if any and address for the reporting entity or other payer; when the incident occurred or is estimated to have occurred; when the reporting business entity became aware of it; impacts on infrastructure and customers; ransomware or malware variants; exploited vulnerabilities; response-useful information; the amount or quantum and method demanded; the amount or quantum and method provided, including non-monetary benefits; and the nature, timing, description, and any pre-payment negotiations in communications with the extorting entity.

  • Keep a 72-hour clock record showing whether time started from making the payment or from becoming aware that another entity made it on the reporting business entity's behalf.
  • Keep a reasonable-search log for report fields that were known, found, estimated, or unavailable within the 72-hour period.
  • Keep the filed report, submission confirmation, incident notes, payment authorization trail, extortion communications, and any later correction or supplemental information together.
Citations
Australia Ransomware Payment Reporting: Threshold and Report Content

Which evidence gaps can undermine a ransomware payment assessment?

An incident-response policy or payment approval note does not establish whether section 27 applies. The record needs the reporting-business-entity analysis, threshold calculation, 72-hour clock, and report-content inventory tied to the Act and Rules.

Do not rely on a generic ransomware playbook to decide whether the Part 3 report is triggered. Preserve the facts that distinguish a non-reportable incident from a reportable ransomware payment: entity status, Australian business activity, turnover, critical-infrastructure responsibility, the demand, the payment or benefit, and awareness that another entity paid on the reporting entity's behalf.

  • Missing threshold proof: no previous-financial-year turnover record, no partial-year formula record, treating turnover equal to $3 million as exceeding the threshold, or no evidence for the critical-infrastructure responsible-entity limb.
  • Missing clock proof: no timestamp for payment, no timestamp for awareness of a payment made by another entity, or no record explaining why the 72-hour period started when it did.
  • Missing report-content proof: no ABN/address details, incident timing and awareness record, customer and infrastructure impact notes, malware and vulnerability findings, demand and payment method details, or extortion-communications log.
Citations
Cyber Security Act 2024

Supports the scope test for a reportable ransomware payment and the report obligation imposed on a reporting business entity.

Australia Ransomware Payment Reporting: Threshold and Report Content

How does the Act protect information in a ransomware payment report?

The Act limits how a designated Commonwealth body and later recipients may use or disclose information obtained through a ransomware payment report. Permitted purposes include helping respond to the incident, administering the reporting regime, government cyber-response functions, National Cyber Security Coordinator functions, ministerial advice, intelligence functions, and specified proceedings about false or misleading information or obstruction.

The protections are qualified. They do not stop use for enforcing Part 3 or laws that impose a penalty or sanction for a criminal offence, and they do not cover information to the extent a body obtained it through another route. Providing information in the report does not otherwise affect a legal professional privilege claim, subject to the statutory exceptions for coronial inquiries, Royal Commissions, and specified federal-court proceedings.

Section 32 also restricts admissibility of report information held by a Commonwealth or State body against the reporting business entity in listed proceedings, with exceptions. Treat these provisions as limits on specified use and admissibility, not as secrecy, immunity from the reporting duty, or a guarantee that the underlying facts cannot be obtained elsewhere.

  • Separate the filed report from evidence collected independently so the source of each item remains clear.
  • Mark privileged material by reference to the applicable privilege analysis; filing does not create privilege for material that was not privileged.
  • Do not omit or delay required information on the assumption that the report creates a general immunity. Failure to give the section 27 report is a civil-penalty contravention, while sections 29 and 32 preserve specified exceptions for false or misleading information and obstruction proceedings.
Citations
Cyber Security Act 2024

Sections 29 to 32 set the permitted-use, secondary-use, privilege, and admissibility rules and their exceptions.

Cyber Security Act 2024 Statements of Compliance

What should teams do about statements of compliance under the Cyber Security Act 2024?

For covered smart devices, the manufacturer must provide a statement of compliance for supply in Australia, and the supplier must supply the product in Australia with that statement. Both manufacturer and supplier must retain a copy for the period set by the rules.

Start by confirming scope. The current Smart Devices Rules prescribe a security standard for consumer-grade relevant connectable products intended or likely to be used for personal, domestic, or household use or consumption, where the products will be acquired in Australia by a consumer. The rules exclude desktop and laptop computers, tablet computers, smartphones, therapeutic goods, road vehicles, and road vehicle components.

The statement must be prepared by, or on behalf of, the manufacturer. The Act requires the supplier to supply the covered product in Australia with a compliant statement when the statutory conditions are met. The official Explanatory Statement says the statement is not required to be provided with the product at the point of sale. Neither the Act nor the Rules prescribes a regulator-issued certificate, third-party approval, or mandatory statement template. The required contents still need to appear in the statement.

  • Classify the product against the consumer-grade relevant connectable product scope and listed exclusions before drafting the statement.
  • Map the actor role: manufacturer prepares or authorises the statement; supplier supplies the product with the statement and retains its copy.
  • Tie the statement to the security-standard evidence for passwords, vulnerability-reporting information, and published defined support periods where those Schedule 1 duties apply.
  • Keep the statement available for regulator review because the Secretary may request the product, the statement of compliance, or both for an independent examination.
Citations
Cyber Security Act 2024

Section 16 establishes manufacturer and supplier statement-of-compliance duties for relevant connectable products supplied in Australia.

Cyber Security Act 2024 Statements of Compliance

What must an Australian smart-device statement of compliance contain?

For statements of compliance with the security standard in Part 1 of Schedule 1 to the Smart Devices Rules, the statement must be prepared by, or on behalf of, the product manufacturer. It must identify the product and responsible parties, record manufacturer declarations, name the defined support period, and include execution details.

Use the required legal contents in the issued statement rather than a generic security attestation. The declaration records the manufacturer's opinion; it does not replace the product and publication evidence supporting that opinion.

  • Product type and batch identifier.
  • Name and address of the manufacturer, an authorised representative of the manufacturer, and each other authorised representative, if any, that is in Australia. The Rules do not define a special statement-only meaning for authorised representative.
  • Declaration that the statement was prepared by, or on behalf of, the manufacturer.
  • Manufacturer opinion that the product was manufactured in compliance with the security-standard requirements and that the manufacturer complied with other security-standard obligations for the product.
  • Defined support period for the product at the date the statement is issued.
  • Signature, name, and function of the manufacturer signatory, plus place and date of issue.
Citations
Cyber Security Act 2024 Statements of Compliance

What evidence and retention should teams keep for statements of compliance?

Manufacturers and suppliers must each retain a copy of the statement for the five-year period prescribed for the consumer-grade relevant connectable product security standard. The Act and Rules state the period but do not state in these provisions that every supporting engineering or supply record has the same prescribed retention period. The retention file should connect the signed statement to the product batch, the manufacturer role, the supplier handoff, and the underlying security-standard controls.

Evidence should be practical and product-specific: retain the issued statement, the product classification decision, supporting test or engineering records, the published vulnerability-reporting and support-period materials, supplier distribution proof, and any notices or regulator correspondence about examination requests.

  • Retain the issued statement version, date and place of issue, signatory details, product type, and batch identifier for five years.
  • Keep scope evidence showing why the product is covered or excluded, including consumer-grade use analysis and any exclusion relied on.
  • Keep control evidence for passwords, security-issue reporting, and defined support periods where those Schedule 1 requirements apply.
  • Keep supplier evidence showing the method used to meet the Act's statement supply duty in Australia, plus records of any corrections or replacement statements.
  • Keep examination-readiness records so the product, statement, or both can be produced if requested in writing by the Secretary.
Citations
Cyber Security Act 2024

Section 23 supports keeping examination-ready product and statement records because the Secretary may request them for an independent examination.

Cyber Security Act 2024 Statements of Compliance

Which mistakes create risk for statements of compliance?

A broad cyber compliance memo cannot replace the product-specific statutory statement tied to the smart-device security standard. Suppliers also need their own retained copy and evidence of the method used to meet the Act's statement supply duty for products supplied in Australia.

  • Using the statement for products outside the current covered class without recording the scope analysis.
  • Omitting the defined support period, signatory function, batch identifier, or authorised-representative details required by the rules.
  • Keeping only engineering test evidence and not the actual issued statement.
  • Treating the five-year retention period as a manufacturer-only obligation when section 16 also gives suppliers a copy-retention duty.
  • Publishing or supplying product information that conflicts with the support period recorded in the statement.
Citations
How do notices and recalls work under the Australia Cyber Security Act?

What triggers Australia Cyber Security Act compliance, stop, and recall notices?

A compliance notice can be issued by the Secretary when an entity that must comply with section 15 or 16 is not complying, or when information suggests possible non-compliance. A response record should start with the product, the relevant connectable product class, the security-standard requirement, the manufacturer or supplier role, and the specific section 15 or 16 obligation at issue.

A stop notice is the next escalation. It depends on a prior compliance notice and the Secretary being reasonably satisfied that the compliance notice was not met or that attempted remediation was inadequate.

A recall notice is a further escalation after a stop notice. It can be issued where the stop notice was not met or remediation remains inadequate for the same section 15 or 16 non-compliance.

  • Responsible actor: the entity that must comply with the section 15 or 16 obligation, usually the manufacturer or supplier for the affected smart device.
  • Trigger evidence: the non-compliance or possible non-compliance, the applicable security-standard requirement, and any compliance-notice or stop-notice history.
  • Pre-notice timing: before giving a compliance, stop, or recall notice, the Secretary must notify the entity of the intention to issue it and allow at least 10 days for representations. The final notice must specify a separate reasonable period for compliance.
Citations
Cyber Security Act 2024

Sections 17, 18, and 19 establish the compliance-notice, stop-notice, and recall-notice escalation path for section 15 or 16 smart-device obligations.

How do notices and recalls work under the Australia Cyber Security Act?

Can an entity seek review or variation of a notice?

Yes. An entity may apply in writing to the Secretary for internal review of a decision to give or vary a compliance, stop, or recall notice. The application must be made within 30 days after the notice is given. Within 30 days after receiving the application, the decision-maker must review the decision and affirm, vary, or revoke it, then provide written reasons as soon as practicable.

The Secretary may also vary a notice to correct an error, defect, or ambiguity, or to address the non-compliance adequately. Before a variation, the entity must receive at least 10 days to make representations. The Secretary may revoke a notice if no longer satisfied that the grounds for issuing it were met. Once a notice for a particular non-compliance or possible non-compliance is revoked under section 21, no further Part 2 notices may be issued for that same non-compliance.

  • Record the date the notice was given and calculate the 30-day internal-review application deadline from that date.
  • Keep the review application, supporting product and remediation evidence, review decision, and written reasons with the notice file.
  • Do not assume an internal-review application pauses the notice. The cited provisions create the review route but do not state that applying automatically stays the notice.
Citations
Cyber Security Act 2024

Sections 21 and 22 set the variation, revocation, representation, internal-review application, decision, and written-reasons rules.

How do notices and recalls work under the Australia Cyber Security Act?

What can an Australia Cyber Security Act recall notice require?

A recall notice must identify the entity, give brief details of the non-compliance, and specify the action the entity must take. The action can require the entity to stop the product being acquired in Australia, stop the product being supplied to suppliers for supply in Australia, or arrange return of the product to the entity or to the manufacturer.

The notice must also specify a reasonable period for the action. If the Secretary considers it appropriate, the notice can also specify a reasonable period for the entity to provide evidence that the action was taken. The notice must explain what may happen if the entity does not comply and how the entity may seek review.

  • Assign the recall response to a product owner who can stop Australian acquisition or supply, plus a manufacturer or supplier contact who can arrange product return.
  • Track the notice fields exactly: entity name, product details, non-compliance, required action, action period, evidence period if included, consequences, and review route.
  • Keep the recall scope tied to the particular instance of non-compliance because the Act allows only one recall notice to be given to an entity for that instance. Sections 17 and 18 contain corresponding one-notice limits for compliance and stop notices.
Citations
Cyber Security Act 2024

Section 19 lists the mandatory recall-notice contents, the available recall actions, evidence period language, review explanation, and one-notice-per-instance limit.

How do notices and recalls work under the Australia Cyber Security Act?

What becomes public if an entity fails to comply with a recall notice?

If an entity fails to comply with a recall notice, the Minister may publish information on the Department's website or another way the Minister considers appropriate. The Act lists the identity of the entity, product details, non-compliance details, and risks posed by the product relating to the non-compliance.

The 2025 Smart Devices Rules add that the public notification may include details of the recall notice and actions consumers are recommended to consider, such as destroying the product or taking extra precautions when using it.

  • Publication-risk evidence: entity identity, affected product identifiers, non-compliance description, product risk explanation, recall-notice details, and recommended consumer actions.
  • Consumer messaging owner: product, legal, and security teams should reconcile recall wording against the Secretary's notice and the Minister's possible public-notification fields.
  • Do not replace the notice's deadlines with the separate 10-day pre-notice representation period. The final notice specifies the reasonable action period and any evidence period.
Citations
Page 1 of 2
Previous12Next