Penalty guideAustraliaCyber Security Act

Australia Cyber Security Act penalties and fines

The Cyber Security Act 2024 sets 60-penalty-unit civil penalties for specific ransomware reporting, protected-information, CIRB notice, and draft-review-report contraventions.

Part 2 uses compliance, stop, and recall notices for smart-device breaches; it does not state a general 60-unit smart-device penalty.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 23, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
10

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 23, 2026
Overview

The Cyber Security Act's express provisions differ from the smart-device notice pathway. Legal, incident-response, product, and compliance teams can use these triggers to check a ransomware report, protected-information use, response, or product enforcement issue. From 1 July 2026, one Commonwealth is $364, so 60 units equal $21,840. That figure is an arithmetic conversion, not an automatic penalty; confirm the applicable unit value, contravention date, entity type, and enforcement route before using it for a case.

Section 1

What are the main Australia Cyber Security Act civil penalty triggers?

Only specified contraventions carry the Act's 60-penalty-unit : the section 27 ransomware reporting duty, the secondary-use restrictions in sections 30, 40, and 56 when their additional conditions are met, a compulsory document notice under section 49, and the draft-report restriction in section 59.

The trigger and exceptions differ by section. Missing a covered ransomware report engages section 27(5). The protected-information provisions require more than any unauthorised handling: the information must fall within the relevant Part, the permitted-use rule must be contravened, the entity must not be a Commonwealth officer, and one of the listed sensitivity, confidentiality, or national-security conditions must apply. Sections 50 and 59 have their own exceptions.

The 60-unit amount is the stated maximum for a person other than a . Under section 82(5) of the Regulatory Powers Act, the court-ordered maximum for a body corporate is generally five times the amount specified for the provision, or 300 penalty units here. At the current $364 penalty-unit value, those figures convert to $21,840 and $109,200. Confirm which unit value applies to the alleged civil contravention before relying on a dollar figure. The court determines the appropriate penalty up to the applicable maximum.

  • Ransomware reporting: a that contravenes the 72-hour report obligation is liable to a of 60 penalty units.
  • Ransomware report information: section 30(6) can impose 60 penalty units for recording, using, or disclosing covered report information outside section 30(2), but only when the further conditions in section 30(6) apply.
  • Significant-incident information: section 40(6) applies the same 60-unit structure to covered information shared for National Cyber Security Coordinator work, subject to its scope, exceptions, and additional conditions.
  • document notices: section 50 imposes 60 penalty units for failure to comply with a . The penalty exception covers production that could reasonably be expected to prejudice specified security, intelligence, investigation, proceeding, or administration-of-justice interests.
  • information and drafts: section 56(6) governs secondary use of protected review information; section 59 separately restricts a recipient's use of a draft report, with exceptions for preparing a section 51 submission, the entity's own information, Chair consent, information already lawfully public, and State constitutional functions.
Section 2

How do smart-device penalties differ from ransomware and Board civil penalties?

Smart-device enforcement under Part 2 is built around notices. For a product within the prescribed class and circumstances, sections 15 and 16 impose manufacturer and supplier duties for the security standard and statement of compliance. The Secretary may issue a compliance notice when reasonably satisfied that an entity is not complying or when information suggests possible non-compliance.

If the compliance notice is not met or remediation is inadequate, the Secretary can escalate to a stop notice. If a stop notice is not met or remediation remains inadequate, the Secretary can escalate to a recall notice. If the recall notice is not complied with, the Minister may publish information including the entity identity, product details, non-compliance details, and product risks; the Smart Devices Rules add recall-notice details and recommended consumer actions.

  • Do not describe every smart-device breach as an immediate fine. First identify whether section 15 or 16 applies and whether a notice has been issued.
  • A compliance, stop, or recall notice must identify the entity, describe the non-compliance or possible non-compliance, specify action and a reasonable period, explain possible consequences, and explain the review route.
  • Before issuing any of these notices, the Secretary must notify the entity and allow at least 10 days for representations.
  • Sections 15 and 16 are also subject to monitoring under section 80, and an authorised person may accept an under section 79. These provisions do not turn every breach into the express 60-unit penalties listed elsewhere in the Act.
  • If an entity fails to comply with a recall notice, the Minister may publish the entity's identity, product details, non-compliance, product risks, recall details, and recommended consumer actions.
Section 3

Which scope facts decide whether a ransomware reporting penalty can arise?

The Part 3 scope test determines whether the ransomware reporting penalty can arise. A report duty can arise when a cyber security incident impacts a , an extorting entity makes a demand to benefit from the incident or its impact, and the reporting business entity provides, or becomes aware that another entity provided on its behalf, a payment or benefit directly related to that demand.

The 2025 Ransomware Payment Reporting Rules prescribe the ordinary turnover threshold as $3 million for the previous financial year, with a pro-rated formula where the business operated for only part of that previous financial year. A responsible entity for a critical infrastructure asset to which Part 2B of the Security of Critical Infrastructure Act 2018 applies can also fall within the reporting-business-entity test.

  • Threshold record: previous-financial-year turnover, any partial-year calculation, whether the entity is a Commonwealth or State body, and whether it falls within the critical-infrastructure limb instead.
  • Payment record: when the ransomware payment was made, who made it, whether it was made on behalf of the , and when awareness occurred.
  • Clock record: tie the 72-hour period to the applicable section 27 event - making the payment or becoming aware that the payment was made - rather than initial incident detection.
  • Report-content record: Australian Business Number (ABN) and address where required, incident timing and impact, demand details, payment amount or non-monetary benefit, payment method, malware or vulnerability information, and extortion communications.
Section 4

What evidence should teams keep for Australia Cyber Security Act penalty exposure?

Build records around the statutory trigger, not a generic cyber incident ticket. Keep a separate record for each possible exposure: ransomware report failure, protected-information misuse, significant-incident information misuse, Board document notice failure, draft-report use, or smart-device notice escalation.

Part 6 applies the Regulatory Powers Act framework. A relevant court may make orders for the Act's civil penalty provisions. Enforceable undertakings may cover those provisions and sections 15 and 16. Injunctions apply to civil penalty provisions. Section 82 permits infringement notices for alleged civil penalty contraventions; an is an alternative process and is not a court finding that the provision was contravened. The Act identifies authorised applicants, authorised persons, and the relevant chief executive for those functions.

  • Owner record: accountable business owner, legal reviewer, security reviewer, product or incident owner, and Board or regulator response owner where relevant.
  • Source record: exact Act or Rules provision, trigger facts, applicable exceptions, and why the team treated the issue as a exposure, notice escalation, or no-trigger case.
  • Evidence record: report submission proof, reasonable-search notes, notice copies, representation submissions, remediation evidence, recall or consumer-action records, disclosure approvals, and draft-report handling logs.
  • Escalation record: whether a order, , , , smart-device notice, public notification, or internal review is in play.
Primary sources

References and citations

legislation.gov.au
Referenced sections
  • Sets one penalty unit at $364 from 1 July 2026. Its timing note expressly addresses offences committed on or after that date, so this page does not infer a civil-contravention timing rule from the instrument.
"the amount of a penalty unit is $364"
legislation.gov.au
Referenced sections
  • Supports the consumer-grade relevant connectable product security standard, statement-of-compliance context, and additional public-notification matters for recall-notice failures.
"actions consumers are recommended to consider"
legislation.gov.au
Referenced sections
  • Supports the Part 3 application test, reporting-business-entity definition, and 72-hour report obligation that can trigger civil penalty exposure.
"within 72 hours"
legislation.gov.au
Referenced sections
  • Supports the court-order framework, body-corporate maximum, and infringement notice process applied by Part 6 of the Cyber Security Act.
"5 times the pecuniary penalty specified"
legislation.gov.au
Referenced sections
  • Supports the critical-infrastructure responsible-entity limb referenced by the Cyber Security Act ransomware reporting test.
"responsible entity"
Related guides

Explore more topics

Australia Compliance Statement Evidence Workflow
Evidence workflow for preparing, supplying, and retaining statements of compliance under Australia's Cyber Security Act 2024 and Smart Devices Rules.
Australia Cyber Security Act 2024 scope and definitions
Official source scope guide for Australia's Cyber Security Act 2024: relevant connectable products, consumer-grade smart devices, reporting business entities, ransomware payment reports, and SOCI overlap.
Australia Cyber Security Act and SOCI Act overlap
How the Australia Cyber Security Act overlaps with the Security of Critical Infrastructure Act for responsible entities, ransomware payment reporting, smart devices, and evidence records.
Australia Cyber Security Act Applicability Test
Decide whether the Australia Cyber Security Act 2024 applies to a smart-device product, supplier, manufacturer, or ransomware payment reporting scenario.
Australia Cyber Security Act Commencement Timeline
Cyber Security Act 2024 commencement timeline for ransomware reporting, CIRB reviews, smart-device duties, statement retention, and statutory review.
Australia Cyber Security Act Compliance Checklist
Concrete checklist items for Australian Cyber Security Act smart-device and ransomware duties, with SOCI and APRA CPS 234 evidence checks.
Australia Cyber Security Act Compliance Guide
A cited compliance guide for Australia Cyber Security Act smart-device statements, ransomware payment reporting, incident coordination, and review-board readiness.
Australia Cyber Security Act Deadlines and Calendar
Cyber Security Act 2024 dates and event-driven deadlines for ransomware payment reports, smart-device duties, records, notices, and statutory review.
Australia Cyber Security Act FAQ
Answers to Australia Cyber Security Act questions on smart device scope, statements of compliance, ransomware reports, enforcement notices, and incident review.
Australia Cyber Security Act recordkeeping FAQ
What records to keep for Cyber Security Act 2024 smart-device statements, ransomware payment reports, and supported SOCI or APRA overlap checks.
Australia Cyber Security Act Requirements
Australia Cyber Security Act requirements for smart-device security standards, statements of compliance, ransomware payment reports, notices, and evidence records.
Australia Cyber Security Act Statement of Compliance Evidence
Evidence guide for Australia Cyber Security Act smart-device statements of compliance: required fields, manufacturer and supplier records, five-year retention, and examination readiness.
Australia Cyber Security Act templates
Source-backed field lists for Australia Cyber Security Act smart-device scope, statements of compliance, ransomware reports, notices, SOCI overlap, and records.
Australia Cyber Security Act vs EU Cyber Resilience Act
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
Australia Cyber Security Act vs UK PSTI Act Guide
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
Australia ransomware payment reporting 72-hour duty
Explain when Australia's Cyber Security Act 2024 requires a ransomware payment report, when the 72-hour clock starts, and what information the report must contain.
Australia Ransomware Payment Reporting Workflow
Operational workflow for Australia Cyber Security Act 2024 ransomware payment reports: scope, 72-hour trigger, report fields, owners, evidence, and cited Act and Rules sources.
Australia Ransomware Payment Reporting: Threshold and Report Content
FAQ answer on Australia's Cyber Security Act ransomware payment reporting scope, $3 million turnover threshold, 72-hour trigger, report fields, and evidence.
Australia Smart Device Applicability Workflow
Decide whether Australia's mandatory smart-device security standard applies, including commencement, connectivity, consumer use, exclusions, roles, and evidence.
Australia Smart Device Compliance Statement
What a smart-device statement of compliance must contain under Australia's Cyber Security Act 2024 and Smart Devices Rules, who prepares and supplies it, how long to retain it, and how to prepare for examination.
Australia Smart Device Security Standards under the Cyber Security Act
Plain-English guide to Australia's Cyber Security (Security Standards for Smart Devices) Rules 2025: scope, passwords, vulnerability reporting, support periods, statements of compliance, and evidence records.
CSA 2024 Smart Device Applicability Test
Check whether a smart device is a consumer-grade relevant connectable product under Australia's Cyber Security Act and Smart Devices Rules.
Cyber Security Act 2024 Smart Device Compliance Checklist
Checklist for Australia Cyber Security Act 2024 smart-device scope, password controls, vulnerability reporting, security-update support periods, statements of compliance, retention, and evidence.
Cyber Security Act 2024 Statements of Compliance FAQ
Australian smart-device statements of compliance: covered products, responsible actors, required contents, supporting evidence, and five-year retention.
Cyber Security Act vs EU CRA: scope and obligations comparison
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
Cyber Security Act vs UK PSTI Act: device security obligations compared
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
How do notices and recalls work under the Australia Cyber Security Act?
FAQ on Australia Cyber Security Act compliance notices, stop notices, recall notices, public notifications, owners, evidence fields, and cited timing.
How does the Australia Cyber Security Act overlap with the SOCI Act?
FAQ on when Australia Cyber Security Act ransomware reporting overlaps with SOCI critical infrastructure assets, responsible entities, and smart-device duties.
Manufacturer, Importer, and Supplier Duties under Australia's Cyber Security Act 2024
Cyber Security Act 2024 smart-device duties for manufacturers, importers, and suppliers, including role tests, scope, statements, and records.
SOCI overlap triage workflow for Australia Cyber Security Act
Triage SOCI Act overlap with Australia Cyber Security Act ransomware reporting and smart-device standards using separate owners, evidence, and cited scope checks.
Which smart devices are in scope under Australia's Cyber Security Act 2024?
FAQ on Cyber Security Act 2024 smart-device scope: relevant connectable products, consumer-grade criteria, exclusions, Australian consumer acquisition, and records to keep.