Cyber Security Act 2024 (Australia)
Australia's first standalone cyber security legislation introducing mandatory security standards for smart devices, ransomware payment reporting, limited use obligations for ASD-shared information, and a Cyber Incident Review Board.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Part 1 - Preliminary
Definitions, objects and application of the Act
| Code | Title |
|---|---|
| CSA24-OBJ | Objects of the Act |
| SCA-S2 | Interpretation and Definitions |
| SCA-S3 | Appointment of Commissioner |
Part 2 - Security Standards for Smart Devices
Mandatory security standards for internet-connected devices
| Code | Title |
|---|---|
| CSA24-SMART-COMPLY | Compliance statements for connectable products |
| CSA24-SMART-ENFORCE | Enforcement for non-compliant devices |
| CSA24-SMART-STD | Security standards for relevant connectable products |
Part 3 - Ransomware Payment Reporting
Mandatory reporting of ransomware payments within 72 hours
| Code | Title |
|---|---|
| CSA24-RANSOM-CONTENT | Content of ransomware payment report |
| CSA24-RANSOM-PENALTY | Penalties for failure to report ransomware payments |
| CSA24-RANSOM-RPT | Obligation to report ransomware payments |
Part 4 - Limited Use Obligation
Protections for information shared with ASD during cyber incidents
| Code | Title |
|---|---|
| CSA24-LIMITED-USE | Limited use obligation for cyber security information |
| CSA24-SAFE-HARBOUR | Safe harbour for voluntary information sharing |
Part 5 - Cyber Incident Review Board
Establishment and powers of the Cyber Incident Review Board
| Code | Title |
|---|---|
| CSA24-CIRB-EST | Establishment of Cyber Incident Review Board |
| CSA24-CIRB-REVIEW | Conduct of incident reviews |
| CSA24-CIRB-RPT | Reporting by the Cyber Incident Review Board |
Maps to 527 other frameworks
Frequently Asked Questions
What is Cyber Security Act 2024 (Australia)?
Cyber Security Act 2024 (Australia) is a compliance framework from Australia with 5 domains and 14 controls. Australia's first standalone cyber security legislation introducing mandatory security standards for smart devices, ransomware payment reporting, limited use obligations for ASD-shared information, and a Cyber Incident Review Board. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Cyber Security Act 2024 (Australia) have?
Cyber Security Act 2024 (Australia) has 14 controls organised across 5 domains. The largest domains are Part 1 - Preliminary (3 controls), Part 2 - Security Standards for Smart Devices (3 controls), Part 3 - Ransomware Payment Reporting (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Cyber Security Act 2024 (Australia) map to?
Cyber Security Act 2024 (Australia) maps to 527 other compliance frameworks. The top mapping partners are AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) (43% coverage), NIST SP 800-124 Rev 2 — Mobile Device Security (43% coverage), TISAX — Trusted Information Security Assessment Exchange (43% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Cyber Security Act 2024 (Australia) compliance?
Start your Cyber Security Act 2024 (Australia) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Cyber Security Act 2024 (Australia) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 14 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required