When does Australia's Cyber Security Act require a ransomware payment report?
Part 3 applies only where an incident has occurred, is occurring, or is imminent; it is a that has had, is having, or could reasonably be expected to have a direct or indirect impact on a ; an extorting entity makes a demand to benefit from the incident or its impact; and the reporting business entity provides, or knows another entity has provided on its behalf, a payment or benefit directly related to that demand.
The test is narrower than a general label for any digital disruption. Section 9 requires an event covered by the SOCI Act meaning or an unauthorised impairment of electronic communications to or from a computer, plus a listed constitutional connection. For incidents outside the critical-infrastructure-asset and constitutional-corporation limbs, section 26 presumes the event is a cyber security incident if it was probably internet-enabled, probably impaired a computer's connection, or probably seriously prejudiced specified Australian interests. That presumption does not create civil-penalty liability if the relevant condition did not exist in fact.
A is either a responsible entity for a critical infrastructure asset to which of the Security of Critical Infrastructure Act 2018 applies, or an entity carrying on business in Australia whose annual turnover for the previous financial year exceeds the and that is not a Commonwealth body, State body, or responsible entity for a critical infrastructure asset under the other limb.
The 2025 Rules prescribe a $3 million threshold for the previous financial year. Section 26 of the Act says annual turnover must exceed that threshold, so turnover of exactly $3 million does not satisfy the ordinary-business limb. If the business operated for only part of the previous financial year, the Rules prorate the threshold: $3 million multiplied by the number of days the business operated in that year, divided by the number of days in the year. The Act still requires turnover to exceed the resulting amount.
Part 3 and the Reporting Rules commenced on 29 May 2025. Commonwealth bodies and State bodies are excluded from the ordinary-business limb. A responsible entity for a critical infrastructure asset must use the separate limb, which applies only where SOCI Act applies to the asset.
The current cyber.gov.au form describes its ordinary-business option as turnover that is equal to or exceeds $3 million. That wording conflicts with section 26 of the Act, which says turnover must exceed the prescribed threshold. For turnover of exactly $3 million, preserve the calculation and seek confirmation from Home Affairs rather than treating the form label as an amendment to the Act.
- Scope evidence: entity status at the time of payment, whether it carries on business in Australia, prior-financial-year turnover, any partial-year calculation, and whether it is the responsible entity for a critical infrastructure asset to which applies.
- Incident evidence: why the event is treated as a and how it directly or indirectly impacted the .
- Payment evidence: the extortion demand, who paid or provided the benefit, whether the payment was made on behalf of the , and when the entity made the payment or became aware it had been made.
Sections 9, 26, and 27 support the cyber-security-incident test and limited presumption, the complete payment-report trigger, the requirement for ordinary-business turnover to exceed the prescribed threshold, the separate SOCI responsible-entity limb, 72-hour timing, and report-content categories.
Section 6 prescribes the $3 million amount and the partial-year threshold formula; section 26 of the Act supplies the requirement that turnover exceed that amount.
Supports the responsible-entity limb for critical infrastructure assets that are brought into the ransomware reporting test.
Current submission form. Its option saying turnover equal to or exceeding $3 million conflicts with section 26 of the Act, which uses exceeds; the Act and Rules remain the controlling sources for the threshold.