Australia’s first standalone cyber security Act received Royal Assent on 29 November 2024, and its measures have commenced in stages since. As of mid-2026, the major pieces are all live. Here’s what each one actually asks of a business.
Ransomware payment reporting — active since 30 May 2025
If your business turns over more than A$3 million (or is a responsible entity under the SOCI Act) and makes — or becomes aware that someone made on its behalf — a ransomware or cyber-extortion payment, you must report it within 72 hours.
Two things people miss: the clock is 72 hours from making the payment or becoming aware of it, and “payment” isn’t only money — benefits count. The reporting Rules were made on 27 February 2025; the obligation itself has been active since 30 May 2025. This 72-hour clock is separate from any privacy-breach notification you may also owe under the NDB scheme.
Smart-device security standards — from 4 March 2026
Internet-connectable consumer devices manufactured on or after 4 March 2026 must meet mandatory security standards. If you sell or supply smart devices, this is your obligation; if you buy them, it’s a floor you can start expecting from suppliers.
The Cyber Incident Review Board — stood up 1 May 2026
The CIRB is a no-fault review body: after significant incidents it examines what happened and publishes lessons without attributing blame. Paired with the Act’s limited-use protections — which restrict how information you voluntarily share with government about an incident can be used against you — the design intent is to make early engagement with government less risky than silence.
What to do
- Put the 72-hour clock in your incident response plan — alongside, not instead of, the NDB scheme’s assessment and notification steps. Our data breach response guide covers how the clocks interact.
- If you supply smart devices, confirm post-March-2026 stock meets the standards.
- Know the limited-use position before an incident, so the decision to engage government early is made calmly, not at 2am.
Nothing further is currently scheduled under the Act — the change timeline on our Cyber Security Act guide will show it if that changes.
Sources
- Cyber Security Act 2024 (legislation.gov.au)
- Home Affairs — ransomware payment reporting factsheet
- Home Affairs — security standards for smart devices
- Home Affairs — Cyber Incident Review Board
This article is education, not legal advice. Dates and obligations are cited to the official sources above — the linked source is the authoritative wording. See how we verify.