---
title: "Australia Cyber Security Act penalties and fines"
canonical_url: "https://www.sorena.io/artifacts/apac/australia-cyber-security-act/penalties-and-fines"
source_url: "https://www.sorena.io/artifacts/apac/australia-cyber-security-act/penalties-and-fines"
author: "Sorena AI"
description: "Official source guide to Australia Cyber Security Act civil penalties, smart-device enforcement notices, ransomware reporting exposure, Board notice failures, and evidence records."
published_at: "2026-05-09"
updated_at: "2026-05-09"
keywords:
  - "Australia Cyber Security Act penalties"
  - "Cyber Security Act civil penalty"
  - "ransomware payment reporting penalty"
  - "smart device recall notice"
  - "Cyber Incident Review Board notice"
  - "Australia Cyber Security Act"
  - "civil penalties"
  - "ransomware reporting"
  - "smart device enforcement"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# Australia Cyber Security Act penalties and fines

Official source guide to Australia Cyber Security Act civil penalties, smart-device enforcement notices, ransomware reporting exposure, Board notice failures, and evidence records.

*Penalty guide* *Australia* *Cyber Security Act*

## Australia Cyber Security Act penalties and fines

Australia's Cyber Security Act 2024 uses 60-penalty-unit civil penalties for specific reporting, information-use, Board notice, and draft-review-report failures.

Smart-device non-compliance is handled differently: the Act sets a compliance notice, stop notice, recall notice, and public-notification pathway rather than listing a general smart-device fine in Part 2.

This page helps separate the Australia Cyber Security Act penalty triggers from adjacent enforcement tools. It covers the cited civil penalty provisions in the Act, the smart-device notice pathway, the ransomware reporting threshold and 72-hour report trigger, Cyber Incident Review Board notice exposure, and the evidence records teams should keep before approving a product, payment, disclosure, or regulator response.

## What are the main Australia Cyber Security Act civil penalty triggers?

The Act does not create one broad cyber-security fine for every control failure. The official source penalty pattern is narrower: an entity is liable to a 60-penalty-unit civil penalty when it misses a required ransomware payment report, improperly records, uses, or discloses protected information in specified circumstances, fails to comply with a Cyber Incident Review Board document-production notice, or improperly records, discloses, or uses a draft review report.

For ransomware payment reporting, the penalty attaches to contravening the section 27 obligation to give a ransomware payment report within 72 hours of making the payment or becoming aware that the payment was made. For protected information and Board material, the exposure depends on the specific information-use restrictions and exceptions in the relevant Part of the Act.

- Ransomware reporting: a reporting business entity that contravenes the 72-hour report obligation is liable to a civil penalty of 60 penalty units.
- Ransomware report information: restricted secondary use or disclosure can carry a 60-penalty-unit civil penalty when the statutory conditions are met.
- Significant cyber incident information: restricted use or disclosure of information shared with the National Cyber Security Coordinator can carry a 60-penalty-unit civil penalty.
- Cyber Incident Review Board: failure to comply with a section 49 document notice, misuse of protected review information, or prohibited disclosure of a draft review report can each carry a 60-penalty-unit civil penalty.

Sources for this answer:

- [Cyber Security Act 2024](https://www.legislation.gov.au/C2024A00098/asmade/2024-11-29/text?ref=sorena.io) - Supports the 60-penalty-unit civil penalty for failing to give a required ransomware payment report within the section 27 timeframe.
- [Cyber Security Act 2024](https://www.legislation.gov.au/C2024A00098/asmade/2024-11-29/text?ref=sorena.io) - Supports the 60-penalty-unit civil penalties for restricted recording, use, or disclosure of protected ransomware, incident-coordination, and review information.
- [Cyber Security Act 2024](https://www.legislation.gov.au/C2024A00098/asmade/2024-11-29/text?ref=sorena.io) - Supports civil penalty exposure for Cyber Incident Review Board document notices and prohibited draft-review-report use.

## How do smart-device penalties differ from ransomware and Board civil penalties?

Smart-device enforcement under Part 2 is built around notices. If a relevant connectable product is subject to a prescribed security standard, sections 15 and 16 create manufacturer and supplier obligations for compliance with that standard and statements of compliance. The Secretary can then issue a compliance notice where an entity is not complying, or where information suggests possible non-compliance.

If the compliance notice is not met or remediation is inadequate, the Secretary can escalate to a stop notice. If a stop notice is not met or remediation remains inadequate, the Secretary can escalate to a recall notice. If the recall notice is not complied with, the Minister may publish information including the entity identity, product details, non-compliance details, and product risks; the Smart Devices Rules add recall-notice details and recommended consumer actions.

- Do not describe every smart-device non-compliance as an immediate fine; first identify whether the issue is a section 15 or section 16 obligation and whether a notice has been issued.
- A compliance, stop, or recall notice must identify the entity, the non-compliance or possible non-compliance, required action, a reasonable action period, consequences, and the review route.
- Before issuing a compliance, stop, or recall notice, the Secretary must give the entity a representation period that is not shorter than 10 days.
- Public notification after recall-notice non-compliance can become a reputational and customer-risk consequence even where the smart-device Part is operating through notices.

Sources for this answer:

- [Cyber Security Act 2024](https://www.legislation.gov.au/C2024A00098/asmade/2024-11-29/text?ref=sorena.io) - Supports the Part 2 enforcement pathway of compliance notices, stop notices, recall notices, representation periods, and public notification.
- [Cyber Security (Security Standards for Smart Devices) Rules 2025](https://www.legislation.gov.au/F2025L00276/asmade/text?ref=sorena.io) - Supports the consumer-grade relevant connectable product security standard, statement-of-compliance context, and additional public-notification matters for recall-notice failures.

## Which scope facts decide whether a ransomware reporting penalty can arise?

The ransomware payment penalty cannot be assessed without the Part 3 scope test. A report obligation can arise when a cyber security incident impacts a reporting business entity, an extorting entity makes a demand to benefit from the incident or its impact, and the reporting business entity provides, or becomes aware that another entity provided on its behalf, a payment or benefit directly related to that demand.

The 2025 Ransomware Payment Reporting Rules prescribe the ordinary turnover threshold as $3 million for the previous financial year, with a pro-rated formula where the business operated for only part of that previous financial year. A responsible entity for a critical infrastructure asset to which Part 2B of the Security of Critical Infrastructure Act 2018 applies can also fall within the reporting-business-entity test.

- Threshold record: previous-financial-year turnover, any partial-year calculation, and whether the entity is excluded because it is a Commonwealth body, State body, or falls under the critical-infrastructure limb.
- Payment record: when the ransomware payment was made, who made it, whether it was made on behalf of the reporting business entity, and when awareness occurred.
- Clock record: the 72-hour reporting period should be tied to the earlier applicable fact pattern in section 27, not to a generic incident-response clock.
- Report-content record: ABN and address where required, incident timing and impact, demand details, payment amount or non-monetary benefit, payment method, malware or vulnerability information, and extortion communications.

Sources for this answer:

- [Cyber Security Act 2024](https://www.legislation.gov.au/C2024A00098/asmade/2024-11-29/text?ref=sorena.io) - Supports the Part 3 application test, reporting-business-entity definition, and 72-hour report obligation that can trigger civil penalty exposure.
- [Cyber Security (Ransomware Payment Reporting) Rules 2025](https://www.legislation.gov.au/F2025L00278/asmade/versions?ref=sorena.io) - Supports the $3 million turnover threshold, partial-year formula, and detailed ransomware payment report information requirements.
- [Security of Critical Infrastructure Act 2018](https://www.legislation.gov.au/Details/C2018A00029?ref=sorena.io) - Supports the critical-infrastructure responsible-entity limb referenced by the Cyber Security Act ransomware reporting test.

## What evidence should teams keep for Australia Cyber Security Act penalty exposure?

Penalty exposure records should be built around statutory triggers, not around a generic cyber incident ticket. Keep a separate record for each possible exposure: ransomware report failure, protected-information misuse, significant-incident information misuse, Board document notice failure, draft-review-report disclosure, or smart-device notice escalation.

Part 6 matters because the Act applies the Regulatory Powers Act framework. Civil penalty orders may be sought from a relevant court, infringement notices may be given for alleged contraventions, undertakings can be accepted for civil penalty provisions and sections 15 and 16, and injunctions can restrain or compel compliance. The Secretary is an authorised applicant for civil penalty and injunction purposes and is the relevant chief executive for infringement notices.

- Owner record: accountable business owner, legal reviewer, security reviewer, product or incident owner, and Board or regulator response owner where relevant.
- Source record: exact Act or Rules provision, trigger facts, applicable exceptions, and why the team treated the issue as a civil penalty exposure, notice escalation, or no-trigger case.
- Evidence record: report submission proof, reasonable-search notes, notice copies, representation submissions, remediation evidence, recall or consumer-action records, disclosure approvals, and draft-report handling logs.
- Escalation record: whether civil penalty order, infringement notice, enforceable undertaking, injunction, public notification, or independent review risk is in play.

Sources for this answer:

- [Cyber Security Act 2024](https://www.legislation.gov.au/C2024A00098/asmade/2024-11-29/text?ref=sorena.io) - Supports the Regulatory Powers Act enforcement context for civil penalties, infringement notices, enforceable undertakings, and injunctions.
- [Cyber Security Act 2024](https://www.legislation.gov.au/C2024A00098/asmade/2024-11-29/text?ref=sorena.io) - Supports the Secretary's role as authorised applicant and relevant chief executive for enforcement powers described on this page.

*Recommended next step*

*Placement: after the penalty guidance*

## Turn Australia Cyber Security Act penalty exposure into assigned work

This guide helps assign ransomware reporting clocks, smart-device notice responses, Board notice handling, protected-information controls, and evidence records in Sorena.

- [Open Assessment Autopilot for Australia Cyber Security Act](/solutions/assessment.md): Turn penalty triggers into scoped questions, evidence fields, owners, and review tasks.
- [Review Australia Cyber Security Act source evidence](/solutions/research-copilot.md): Use Research Copilot to check the Act, ransomware rules, smart-device rules, and cited enforcement provisions.
- [Talk through implementation](/contact.md): Review civil penalty exposure, notice response records, source support, and next compliance actions with Sorena.

## Primary sources

- [Cyber Security Act 2024](https://www.legislation.gov.au/C2024A00098/asmade/2024-11-29/text?ref=sorena.io) - Primary source for Cyber Security Act civil penalty triggers, 60-penalty-unit amounts, smart-device enforcement notices, Board notice failures, and Part 6 regulatory powers.
  - Quote: "Contravening a civil penalty provision"
- [Cyber Security (Ransomware Payment Reporting) Rules 2025](https://www.legislation.gov.au/F2025L00278/asmade/versions?ref=sorena.io) - Supports the $3 million ransomware reporting turnover threshold, partial-year threshold formula, and detailed report-content evidence fields.
  - Quote: "the amount of turnover threshold"
- [Cyber Security (Security Standards for Smart Devices) Rules 2025](https://www.legislation.gov.au/F2025L00276/asmade/text?ref=sorena.io) - Supports the smart-device security-standard scope, statement-of-compliance context, and extra matters that may be published after recall-notice non-compliance.
  - Quote: "Matters to be published with notification"
- [Security of Critical Infrastructure Act 2018](https://www.legislation.gov.au/Details/C2018A00029?ref=sorena.io) - Supports the critical-infrastructure responsible-entity reference used in the Cyber Security Act ransomware reporting scope test.
  - Quote: "Security of Critical Infrastructure Act 2018"

## Related Topic Guides

- [Australia Cyber Security Act 2024 scope and definitions](/artifacts/apac/australia-cyber-security-act/scope-and-definitions.md): Official source scope guide for Australia's Cyber Security Act 2024: relevant connectable products, consumer-grade smart devices, reporting business entities, ransomware payment reports, and SOCI overlap.
- [Australia Cyber Security Act and SOCI Act overlap](/artifacts/apac/australia-cyber-security-act/security-of-critical-infrastructure-act-overlap.md): How the Australia Cyber Security Act overlaps with the Security of Critical Infrastructure Act for responsible entities, ransomware payment reporting, smart devices, and evidence records.
- [Australia Cyber Security Act Applicability Test](/artifacts/apac/australia-cyber-security-act/applicability-test.md): Decide whether the Australia Cyber Security Act 2024 applies to a smart-device product, supplier, manufacturer, or ransomware payment reporting scenario.
- [Australia Cyber Security Act Compliance Checklist](/artifacts/apac/australia-cyber-security-act/checklist.md): Concrete checklist items for Australian Cyber Security Act smart-device and ransomware duties, with SOCI and APRA CPS 234 evidence checks.
- [Australia Cyber Security Act Compliance Guide](/artifacts/apac/australia-cyber-security-act/compliance.md): A cited compliance guide for Australia Cyber Security Act smart-device statements, ransomware payment reporting, incident coordination, and review-board readiness.
- [Australia Cyber Security Act Deadlines and Compliance Calendar](/artifacts/apac/australia-cyber-security-act/deadlines-and-compliance-calendar.md): Calendar of official source Australia Cyber Security Act milestones for ransomware reporting, smart-device security standards, statements of compliance, and statutory review.
- [Australia Cyber Security Act FAQ](/artifacts/apac/australia-cyber-security-act/faq.md): Answers to Australia Cyber Security Act questions on smart device scope, statements of compliance, ransomware reports, enforcement notices, and incident review.
- [Australia Cyber Security Act recordkeeping FAQ](/artifacts/apac/australia-cyber-security-act/faq/recordkeeping.md): What records to keep for Cyber Security Act 2024 smart-device statements, ransomware payment reports, and supported SOCI or APRA overlap checks.
- [Australia Cyber Security Act Requirements](/artifacts/apac/australia-cyber-security-act/requirements.md): Australia Cyber Security Act requirements for smart-device security standards, statements of compliance, ransomware payment reports, notices, and evidence records.
- [Australia Cyber Security Act Statement of Compliance Evidence](/artifacts/apac/australia-cyber-security-act/statement-of-compliance-evidence.md): Evidence guide for Australia Cyber Security Act smart-device statements of compliance: required fields, manufacturer and supplier records, five-year retention, and examination readiness.
- [Australia Cyber Security Act templates](/artifacts/apac/australia-cyber-security-act/templates.md): Official source template fields for Australia Cyber Security Act smart-device scope, statements of compliance, ransomware reports, notices, SOCI overlap, and records.
- [Australia Cyber Security Act Timeline and Commencement Guide](/artifacts/apac/australia-cyber-security-act/timeline-and-commencement.md): Australia Cyber Security Act commencement dates for ransomware reporting, CIRB reviews, smart-device duties, statement retention, and statutory review.
- [Australia Cyber Security Act vs EU Cyber Resilience Act](/artifacts/apac/australia-cyber-security-act/australia-cyber-security-act-vs-eu-cyber-resilience-act.md): Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
- [Australia Cyber Security Act vs UK PSTI Act Guide](/artifacts/apac/australia-cyber-security-act/australia-cyber-security-act-vs-uk-psti-act.md): Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
- [Australia ransomware payment reporting 72-hour duty](/artifacts/apac/australia-cyber-security-act/ransomware-payment-reporting-72-hours.md): Explain when Australia's Cyber Security Act 2024 requires a ransomware payment report, when the 72-hour clock starts, and what information the report must contain.
- [Australia Smart Device Security Standards under the Cyber Security Act](/artifacts/apac/australia-cyber-security-act/smart-device-security-standards.md): Plain-English guide to Australia's Cyber Security (Security Standards for Smart Devices) Rules 2025: scope, passwords, vulnerability reporting, support periods, statements of compliance, and evidence records.
- [Australia Smart Device Statement of Compliance Evidence Workflow](/artifacts/apac/australia-cyber-security-act/statement-of-compliance-evidence-workflow.md): Evidence workflow for preparing, supplying, and retaining statements of compliance under Australia's Cyber Security Act 2024 and Smart Devices Rules.
- [CSA 2024 Ransomware Payment Reporting Workflow](/artifacts/apac/australia-cyber-security-act/ransomware-payment-reporting-workflow.md): Operational workflow for Australia Cyber Security Act 2024 ransomware payment reports: scope, 72-hour trigger, report fields, owners, evidence, and cited Act and Rules sources.
- [CSA 2024 Ransomware Threshold & Report FAQ](/artifacts/apac/australia-cyber-security-act/faq/ransomware-payment-threshold-and-report-content.md): FAQ answer on Australia's Cyber Security Act ransomware payment reporting scope, $3 million turnover threshold, 72-hour trigger, report fields, and evidence.
- [CSA 2024 Smart Device Applicability Test](/artifacts/apac/australia-cyber-security-act/smart-device-applicability-and-product-scope.md): Check whether a smart device is a consumer-grade relevant connectable product under Australia's Cyber Security Act and Smart Devices Rules.
- [CSA 2024 Smart Device Statement of Compliance](/artifacts/apac/australia-cyber-security-act/statement-of-compliance-and-recordkeeping.md): What a smart-device statement of compliance must contain under Australia's Cyber Security Act 2024 and Smart Device Rules, who prepares and supplies it, how long to retain it, and how to prepare for examination.
- [Cyber Security Act 2024 Smart Device Compliance Checklist](/artifacts/apac/australia-cyber-security-act/smart-device-compliance-checklist.md): Checklist for Australia Cyber Security Act 2024 smart-device scope, password controls, vulnerability reporting, security-update support periods, statements of compliance, retention, and evidence.
- [Cyber Security Act 2024 Statements of Compliance FAQ](/artifacts/apac/australia-cyber-security-act/faq/statements-of-compliance.md): FAQ answer on Australian Cyber Security Act 2024 statements of compliance for smart devices, including scope, actors, required contents, retention, evidence, and citations.
- [Cyber Security Act vs EU CRA: scope and obligations comparison](/artifacts/apac/australia-cyber-security-act/cyber-security-act-vs-eu-cyber-resilience-act.md): Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
- [Cyber Security Act vs UK PSTI Act: device security obligations compared](/artifacts/apac/australia-cyber-security-act/cyber-security-act-vs-uk-psti-act.md): Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
- [How do notices and recalls work under the Australia Cyber Security Act?](/artifacts/apac/australia-cyber-security-act/faq/notices-and-recalls.md): FAQ on Australia Cyber Security Act compliance notices, stop notices, recall notices, public notifications, owners, evidence fields, and cited timing.
- [How does the Australia Cyber Security Act overlap with the SOCI Act?](/artifacts/apac/australia-cyber-security-act/faq/security-of-critical-infrastructure-act-overlap.md): FAQ on when Australia Cyber Security Act ransomware reporting overlaps with SOCI critical infrastructure assets, responsible entities, and smart-device duties.
- [Manufacturer, Importer, and Supplier Duties under Australia's Cyber Security Act 2024](/artifacts/apac/australia-cyber-security-act/faq/manufacturer-and-importer-obligations.md): Direct FAQ answer on Cyber Security Act 2024 smart-device duties for manufacturers, importers, and suppliers, including scope, statement records, exceptions, and citations.
- [Smart Device Applicability: CSA 2024](/artifacts/apac/australia-cyber-security-act/smart-device-applicability-workflow.md): A cited workflow for deciding whether a connected product is covered by Australia's Cyber Security Act 2024 smart-device standard and what evidence to keep.
- [SOCI overlap triage workflow for Australia Cyber Security Act](/artifacts/apac/australia-cyber-security-act/soci-overlap-triage-workflow.md): Triage SOCI Act overlap with Australia Cyber Security Act ransomware reporting and smart-device standards using separate owners, evidence, and cited scope checks.
- [Which smart devices are in scope under Australia's Cyber Security Act 2024?](/artifacts/apac/australia-cyber-security-act/faq/smart-device-scope.md): FAQ on Cyber Security Act 2024 smart-device scope: relevant connectable products, consumer-grade criteria, exclusions, Australian consumer acquisition, and records to keep.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/australia-cyber-security-act/penalties-and-fines.md
