A responsible entity must report a critical cyber security incident (with significant impact on availability) to the ACSC within 12 hours of becoming aware of the incident.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.