- Official Rules source tying commencement to Part 5 of the Act.
"at the same time as Part 5"
The Act and its three 2025 rule instruments started on different dates. Track framework commencement and the operative dates for ransomware, CIRB, and smart-device obligations separately.
Match each workflow to the relevant Part and instrument; consultation, registration, commencement, and event deadlines are different legal events.
Structured answer sets in this page tree.
Cited legal and guidance references.
The Cyber Security Act 2024 commenced in stages: Parts 1, 4, 6, and 7 on 30 November 2024; Parts 3 and 5 on 29 May 2025; and Part 2 on 29 November 2025. Home Affairs guidance incorrectly gives 30 May 2025 for the Part 3 and Part 5 regimes. The prescribed smart-device standard and statement duties became operative on 4 March 2026. Match each ransomware, smart-device, and Cyber Incident Review Board workflow to its governing Part and Rules.
Parts 1, 4, 6, and 7 commenced on 30 November 2024, and Part 2 commenced on 29 November 2025. Parts 3 and 5 commenced on 29 May 2025 under the binding column 2 mechanism in section 2: no earlier day was proclaimed, so they commenced on the day after the six-month fallback period ended. The Federal Register also displays 29 May 2025 in column 3. Home Affairs guidance incorrectly says the ransomware reporting regime and Rules started on 30 May 2025.
The subordinate instruments have separate tables. The ransomware and Rules commence with Parts 3 and 5. Part 1 of the Smart Devices Rules commenced on registration on 4 March 2025, but Part 2 and Schedule 1 - including the prescribed class, security standard, statement requirements, and five-year retention rule - commenced on 4 March 2026.
Ransomware teams should track the payment event or awareness event for each incident. A is either a qualifying non-government business carried on in Australia whose previous-financial-year turnover exceeds the prescribed $3 million threshold, or a responsible entity for a critical infrastructure asset to which SOCI Part 2B applies. The incident, demand, payment, and statutory exclusion conditions must also be met. If the reporting business entity made the payment, the report is due within 72 hours after payment. If another entity paid on its behalf, the report is due within 72 hours after the reporting business entity became aware of the payment.
Product teams need both 29 November 2025 and 4 March 2026. Section 13 brings a into Part 2 if it was manufactured on or after 29 November 2025 or supplied in Australia, other than as second-hand goods, on or after that date. The prescribed consumer-grade security standard and provisions became operative on 4 March 2026. The official explanatory statement gives smart TVs, smart watches, home assistants, baby monitors, and consumer energy resources as examples of the consumer-grade class, but product teams must still apply the binding connectivity, intended-use, acquisition, awareness, date, and exclusion tests to each product.
The date establishes the review framework; it does not create a periodic filing. A published review notification does not itself require an organisation to respond. A written request under section 48 is voluntary, but a later notice under section 49 may require an involved non-government entity to produce relevant documents, with at least 14 days allowed for production.
Royal Assent, registration, framework , operative rule commencement, and event-triggered deadlines describe different legal events. Registration of the Smart Devices Rules on 4 March 2025 did not activate Part 2 and Schedule 1; they commenced on 4 March 2026.
The five-year statement period is a retention duration, not a common destruction date. The Rules specify a five-year period but do not state its starting event, so the manufacturer and supplier should record the interpretation used and obtain case-specific advice before disposing of a statement.
The 72-hour reporting period starts from the payment or awareness trigger in section 27, not from initial detection of the cyber incident. If no payment or benefit directly related to the extorting demand was provided, Part 3 does not create a ransomware payment report deadline, although other incident-reporting duties may still apply.
Keep one dated legal-status register that links each Act Part and rule instrument to its provision, affected workflow, owner, and evidence location. Keep event-triggered deadlines in the operational system where the trigger occurs.
Recheck the latest authorised Act and rule versions after an amendment or new instrument. Preserve the version relied on for an earlier decision so the organisation can explain what was in force at that time.
Assign each commencement milestone and event-driven deadline to an owner, evidence record, and review point.
Turn commencement dates into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"at the same time as Part 5"
"The later of"
"The day after the end of the period of 12 months"
"2 Commencement"
"Commencement information"
"Chair may require certain entities to produce documents"
"30 May 2025"