SecurityPolicy.com.au
Home/ Articles/ The Cyber Security Act 2024 is now fully in force — what applies to you
Australia 16 July 2026

The Cyber Security Act 2024 is now fully in force — what applies to you

Ransomware payment reporting, smart-device security standards and the Cyber Incident Review Board have all commenced. A plain-English rundown of which obligations touch an ordinary Australian business.

Australia’s first standalone cyber security Act received Royal Assent on 29 November 2024, and its measures have commenced in stages since. As of mid-2026, the major pieces are all live. Here’s what each one actually asks of a business.

Ransomware payment reporting — active since 30 May 2025

If your business turns over more than A$3 million (or is a responsible entity under the SOCI Act) and makes — or becomes aware that someone made on its behalf — a ransomware or cyber-extortion payment, you must report it within 72 hours.

Two things people miss: the clock is 72 hours from making the payment or becoming aware of it, and “payment” isn’t only money — benefits count. The reporting Rules were made on 27 February 2025; the obligation itself has been active since 30 May 2025. This 72-hour clock is separate from any privacy-breach notification you may also owe under the NDB scheme.

Smart-device security standards — from 4 March 2026

Internet-connectable consumer devices manufactured on or after 4 March 2026 must meet mandatory security standards. If you sell or supply smart devices, this is your obligation; if you buy them, it’s a floor you can start expecting from suppliers.

The Cyber Incident Review Board — stood up 1 May 2026

The CIRB is a no-fault review body: after significant incidents it examines what happened and publishes lessons without attributing blame. Paired with the Act’s limited-use protections — which restrict how information you voluntarily share with government about an incident can be used against you — the design intent is to make early engagement with government less risky than silence.

What to do

  1. Put the 72-hour clock in your incident response plan — alongside, not instead of, the NDB scheme’s assessment and notification steps. Our data breach response guide covers how the clocks interact.
  2. If you supply smart devices, confirm post-March-2026 stock meets the standards.
  3. Know the limited-use position before an incident, so the decision to engage government early is made calmly, not at 2am.

Nothing further is currently scheduled under the Act — the change timeline on our Cyber Security Act guide will show it if that changes.

Sources

  1. Cyber Security Act 2024 (legislation.gov.au)
  2. Home Affairs — ransomware payment reporting factsheet
  3. Home Affairs — security standards for smart devices
  4. Home Affairs — Cyber Incident Review Board
Not legal advice

This article is education, not legal advice. Dates and obligations are cited to the official sources above — the linked source is the authoritative wording. See how we verify.