Cyber Security Act 2024 (Australia)
Australia's first standalone cyber security legislation introducing mandatory security standards for smart devices, ransomware payment reporting, limited use obligations for ASD-shared information, and a Cyber Incident Review Board.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (16)
Compliance and Enforcement
| Code | Title |
|---|---|
| AUCSA-INF-01 | Information Gathering Powers of the Department |
| AUCSA-INF-02 | Civil Penalties and Infringement Notices |
Cyber Incident Review Board
| Code | Title |
|---|---|
| AUCSA-CIRB-01 | Cyber Incident Review Board Establishment |
| AUCSA-CIRB-02 | Compulsory Information Production to the Board |
| AUCSA-CIRB-03 | Protection of Identified Persons in Board Reports |
Governance
| Code | Title |
|---|---|
| AUCSA-GOV-01 | Board and Executive Oversight of Cyber Obligations |
Incident Response
| Code | Title |
|---|---|
| AUCSA-RES-01 | Incident Response Plan Aligned to Reporting Triggers |
Interactions with Other Laws
| Code | Title |
|---|---|
| AUCSA-INT-01 | Interaction with SOCI Act Obligations |
| AUCSA-INT-02 | Interaction with Privacy Act Notifiable Data Breaches |
IoT Security Standards
| Code | Title |
|---|---|
| AUCSA-IOT-01 | Mandatory Security Standards for Smart Devices |
| AUCSA-IOT-02 | Statement of Compliance for Relevant Products |
| AUCSA-IOT-03 | Response to Compliance Notice from Secretary |
Limited Use Obligation
| Code | Title |
|---|---|
| AUCSA-LU-01 | Limited Use Obligation on Government Bodies |
| AUCSA-LU-02 | Permitted Uses and Disclosures of Limited Use Information |
Part 1 - Preliminary
Definitions, objects and application of the Act
| Code | Title |
|---|---|
| CSA24-OBJ | Objects of the Act |
| SCA-S2 | Interpretation and Definitions |
| SCA-S3 | Appointment of Commissioner |
Part 2 - Security Standards for Smart Devices
Mandatory security standards for internet-connected devices
| Code | Title |
|---|---|
| CSA24-SMART-COMPLY | Compliance statements for connectable products |
| CSA24-SMART-ENFORCE | Enforcement for non-compliant devices |
| CSA24-SMART-STD | Security standards for relevant connectable products |
Part 3 - Ransomware Payment Reporting
Mandatory reporting of ransomware payments within 72 hours
| Code | Title |
|---|---|
| CSA24-RANSOM-CONTENT | Content of ransomware payment report |
| CSA24-RANSOM-PENALTY | Penalties for failure to report ransomware payments |
| CSA24-RANSOM-RPT | Obligation to report ransomware payments |
Part 4 - Limited Use Obligation
Protections for information shared with ASD during cyber incidents
| Code | Title |
|---|---|
| CSA24-LIMITED-USE | Limited use obligation for cyber security information |
| CSA24-SAFE-HARBOUR | Safe harbour for voluntary information sharing |
Part 5 - Cyber Incident Review Board
Establishment and powers of the Cyber Incident Review Board
| Code | Title |
|---|---|
| CSA24-CIRB-EST | Establishment of Cyber Incident Review Board |
| CSA24-CIRB-REVIEW | Conduct of incident reviews |
| CSA24-CIRB-RPT | Reporting by the Cyber Incident Review Board |
Ransomware Payment Reporting
| Code | Title |
|---|---|
| AUCSA-RAN-01 | Ransomware Payment Reporting Obligation |
| AUCSA-RAN-02 | Content of Ransomware Payment Report |
| AUCSA-RAN-03 | Internal Decision Process for Ransomware Payments |
Record Keeping
| Code | Title |
|---|---|
| AUCSA-REC-01 | Record Keeping and Evidence Retention |
Supply Chain
| Code | Title |
|---|---|
| AUCSA-SUP-01 | Supply Chain Assurance for Connectable Products |
Training and Awareness
| Code | Title |
|---|---|
| AUCSA-TRA-01 | Training on Cyber Security Act Obligations |
Your Compliance Coverage
If you comply with Cyber Security Act 2024 (Australia), you already cover:
AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
18%
6 controls mapped
Compare →NIST SP 800-124 Rev 2 - Mobile Device Security
18%
6 controls mapped
Compare →NIS2 Directive
18%
6 controls mapped
Compare →+ 548 more: TISAX - Trusted Information Security Assessment Exchange (18%), NIST SP 800-82 Rev 3 - Guide to OT Security (18%)
See all 551 mapped frameworks ↓Maps to 551 other frameworks
Frequently Asked Questions
What is Cyber Security Act 2024 (Australia)?
Cyber Security Act 2024 (Australia) is a compliance framework from Australia with 16 domains and 34 controls. Australia's first standalone cyber security legislation introducing mandatory security standards for smart devices, ransomware payment reporting, limited use obligations for ASD-shared information, and a Cyber Incident Review Board. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Cyber Security Act 2024 (Australia) have?
Cyber Security Act 2024 (Australia) has 34 controls organised across 16 domains. The largest domains are Cyber Incident Review Board (3 controls), IoT Security Standards (3 controls), Part 1 - Preliminary (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Cyber Security Act 2024 (Australia) map to?
Cyber Security Act 2024 (Australia) maps to 551 other compliance frameworks. The top mapping partners are AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) (18% coverage), NIST SP 800-124 Rev 2 - Mobile Device Security (18% coverage), NIS2 Directive (18% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Cyber Security Act 2024 (Australia) compliance?
Start your Cyber Security Act 2024 (Australia) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Cyber Security Act 2024 (Australia) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required