EXPLORE KNOWLEDGE BASE
-
CERI Knowledge Base
-
About the CERI knowledge base
-
Introduction to Australia’s electricity markets
-
Australian consumer insights
-
CER technical and interoperability standards
-
Connecting a customer to an electricity network
-
Connecting a generator to a distribution network
-
Utility interconnection (CSIP-AUS)
-
Dynamic network export and generation control schemes
-
Network load control schemes
-
Network tariffs and network support services
-
Participating in the National Electricity Market
-
Participating in a frequency control market
-
Participating in the RERT
-
Participating in the Wholesale Electricity Market (Western Australia)
-
Participating in the I-NTEM (NT)
-
Cyber security and data privacy arrangements
-
Consumer protection frameworks
-
The Cyber Security Act
Last Updated on 4 August 2026
SUGGEST AN EDIT
LIKE THIS PAGE?
The Cyber Security Act 2024 introduces a national framework to strengthen cyber resilience across Australia, with direct implications for CER solutions. The Act mandates minimum secure-by-design principles for connected technologies, requiring OEMs and service providers to embed cybersecurity into product architecture from inception.
While the Cyber Security Act is technology-neutral, it captures CER by imposing cybersecurity obligations on all network-connected technologies that interact with critical infrastructure. CER devices are included because they can influence power system security when aggregated.
Key points
- Connected CER products should incorporate cybersecurity from the design stage.
- Security must be maintained throughout the product’s operational life.
- Developers should manage vulnerabilities, third-party components and supplier risks.
- Consumers should receive clear information about security features, updates and data handling.
- Relevant international standards can help developers structure their security controls.
How does the Act affect CER product developers?
To meet requirements of the Cyber Security Act, where applicable, CER developers should implement strong authentication mechanisms, such as multi-factor authentication and secure credential storage, to prevent unauthorised access. They are required to ensure end-to-end encryption for all data in transit and at rest, including communications between devices, applications, and cloud platforms.
Products must support secure firmware update processes, incorporating cryptographic signing and validation to maintain integrity during updates. Developers should establish robust vulnerability management protocols, including regular security testing, timely patching, and transparent disclosure processes.
All security measures must also align with recognised international standards, notably IEC 62443 for industrial control systems and ETSI EN 303 645 for IoT baseline security, adapted to meet Australian regulatory requirements under the Cyber Security Act 2024.
Lifecycle Security
Products must support timely patching and remote update capabilities throughout their operational life. Developers are required to maintain long-term security update commitments beyond warranty periods. Secure decommissioning processes must be implemented to prevent data leakage or unauthorised reuse. Continuous monitoring for emerging threats and updating security controls accordingly is mandatory.
Compliance Enforcement
Failure to maintain security after deployment can lead to civil penalties, product bans, or exclusion from the Australian market. The Cyber Security Act requires that operators of CER fleets or platforms must also comply with mandatory incident reporting requirements to the ACSC, including ransomware and cyber extortion.
Supply Chain Assurance
CER developers must assess and mitigate cybersecurity risks associated with third-party components and offshore manufacturing. They are required to ensure all suppliers comply with Australian cybersecurity standards and include contractual obligations for security compliance.
Consumer transparency requirements
Consumer transparency requirements under the Cyber Security Act include disclosure of implemented security features, and commitments for ongoing updates. Manufacturers must inform consumers about vulnerabilities and breaches promptly and provide transparent data handling practices. These measures aim to build trust and enable informed purchasing decisions.
International Alignment
The Cyber Security Act 2024 is broadly aligned with international frameworks such as the EU Cybersecurity Act, ETSI EN 303 645, and IEC 62443, but it introduces several distinctive Australian features:
International alignment:
- Requires secure-by-design principles, including authentication, encryption, and secure firmware updates aligned with ETSI EN 303 645 and IEC 62443.
- Mandates lifecycle security, covering patching, vulnerability management, and secure decommissioning, consistent with global best practice.
- Emphasises supply chain risk management, reflecting international norms for third-party assurance.
Unique Australian features:
- Mandatory incident reporting to the ACSC within strict timeframes, unlike voluntary schemes in other jurisdictions.
- Integration with local energy market and critical infrastructure arrangements such as the SOCI Act and AESCSF.
- Specific enforcement mechanisms include civil penalties, product bans, and market exclusion for non-compliance
- Consumer transparency through proposed security labelling for IoT and CER devices, a feature not widely adopted internationally