CIRMP Physical Security Plan: What Critical Infrastructure Operators in Australia Need to Know

Australia’s critical infrastructure regulatory landscape changed significantly in late 2025. The Department of Home Affairs proposed targeted enhancements to the Critical Infrastructure Risk Management Program (CIRMP) Rules — and one of the most significant additions is a requirement that responsible entities develop and maintain a formal physical security plan.

For organisations that have focused their CIRMP compliance efforts on cyber and personnel security, this is a new and distinct obligation. Physical security — the protection of assets, sites, and people from physical threats including theft, vandalism, sabotage, and unauthorised access — now has an explicit, structured compliance requirement under the enhanced CIRMP framework, with a compliance deadline of 30 June 2028.

This article explains what the enhanced CIRMP physical security plan requires, which operators are affected, and what an independent physical security assessment contributes to developing a plan that is genuinely compliant rather than just documented.

 

Background: The Enhanced CIRMP Rules and Why Physical Security Is Now Mandatory

The Critical Infrastructure Risk Management Program came into effect on 17 February 2023, requiring responsible entities across 11 critical infrastructure sectors to establish, maintain, and comply with a risk management program addressing hazards across all domains — including physical, cyber, personnel, and supply chain.

The original CIRMP Rules did not specify a dedicated physical security measure. In response to industry feedback during consultation, the Department of Home Affairs introduced a proposed requirement to develop and maintain a physical security plan as a distinct element of the enhanced CIRMP.

The rationale is straightforward. Physical threats to critical infrastructure — which could materialise as physical theft of components or operational information, vandalism, or sabotage — can have significant consequences, including major disruption to essential services, increased operational costs, and serious safety risks for employees and the general public. Without a specific physical security uplift requirement, resourcing for physical security may not be sufficient, resulting in increased physical security risk.

The proposed enhanced requirements apply to the following critical infrastructure asset classes:

  • Critical energy market operator assets
  • Critical electricity assets
  • Critical gas assets
  • Critical liquid fuel assets
  • Critical water assets
  • Critical broadcasting assets
  • Critical domain name systems
  • Critical freight service assets
  • Critical freight infrastructure assets

The compliance deadline for the physical security plan is 30 June 2028, with responsible entities required to attest to compliance in the July to September 2028 reporting period. Critically, given the extended period for compliance, there will be a requirement to have a documented plan within the CIRMP detailing how compliance will be accomplished in attestation periods leading up to the 2028 attestation period. This means the work needs to start now — not in 2027.

 

What the CIRMP Physical Security Plan Must Contain

The proposed physical security plan is informed by the Protective Security Policy Framework (PSPF) Facility Security Plan principles — the established benchmark for Commonwealth Government entities and a framework many critical infrastructure operators are already familiar with. The Department has adopted the PSPF principles as a less prescriptive and cost-effective basis for the CIRMP physical security plan requirement.

The physical security plan will require the responsible entity, as far as it is reasonably practicable, to develop and maintain a process or system to address the following elements.

 

Site nature and location assessment

Identify the nature of the site the critical asset is located on, including ownership and tenancy, and how such arrangements could impair the availability of the asset. This could also include potential collateral exposure posed by nearby attractive targets and other critical infrastructure assets.

In practice this means documenting whether the site is sole-occupied or shared, understanding how co-location with other tenants or nearby infrastructure creates risk, and identifying whether the site’s physical characteristics — its location, boundary, and surroundings — create vulnerabilities that need to be managed.

 

Physical access controls

Implement physical access controls, which involves managing privileged access, implementing appropriate perimeter access controls such as fences and security barriers, and implementing and maintaining appropriate surveillance and security alarm systems, such that critical components and critical systems are subject to continuous monitoring.

This element specifically requires identification of:

  • Physical access controls to the critical infrastructure asset
  • Sensitive areas within the asset that hold business-critical data or contain critical systems and components
  • Business hours and out-of-hours access controls — including CCTV, alarms, secure doors, and sensors

Out-of-hours controls are explicitly called out because this is where critical infrastructure is most vulnerable. A site that has adequate access management during business hours but inadequate monitoring, alarm response, and physical controls after hours has a genuine gap that the physical security plan must address.

 

Protective security measures — whole of asset

Implement protective security measures that apply to the whole asset or organisation, and incident response plans to address breaches in such security arrangements.

This goes beyond individual controls to the overall security posture of the asset. It requires the responsible entity to consider how security measures work together across the site — not as isolated controls, but as an integrated system that addresses the threat environment the asset operates in.

The incident response plan component is significant. It’s not enough to have physical controls in place — the plan must also address what happens when those controls are breached. Who is notified, what response is initiated, how the breach is contained and investigated, and how normal operations are restored are all elements of a compliant incident response arrangement.

 

Testing and effectiveness review

In line with existing requirements, test that security arrangements for the asset are effective and appropriate to detect, delay, deter, respond to, and recover from a breach in the arrangements.

This is an active, ongoing obligation — not a one-time exercise. Security arrangements must be tested, and the results of that testing must inform the ongoing maintenance of the physical security plan. Controls that were adequate at the time of initial assessment may become inadequate as the threat environment changes, as the site evolves, or as technology degrades.

 

Integration with other plans

The responsible entity will need to consider the interaction between their physical security plan and other organisational security plans, as well as organisational incident response plans, for all-hazards.

The physical security plan is not a standalone document — it must connect with the broader CIRMP, with cyber security arrangements, with personnel security programs, and with operational emergency and business continuity plans. This integration requirement is often where organisations underestimate the work involved.

 

Why an Independent Physical Security Assessment Is the Foundation

The CIRMP physical security plan is a governance and compliance document — but it must be grounded in evidence. A plan that documents controls without assessing whether those controls are adequate against the actual threat environment is not compliant in any meaningful sense. It is paperwork.

The foundation of a genuinely compliant physical security plan is an independent physical security assessment — a structured, evidence-based evaluation of the site, the threat environment, the current controls, and the gaps that exist between what is in place and what is required.

An independent assessment provides several things that internal reviews cannot.

Objectivity. An internal review of security controls is conducted by people who are embedded in the organisation — who may have designed or approved the existing controls, and who have a professional interest in the outcome. An independent consultant has no stake in the finding. The assessment reflects what is actually there and how it actually performs, not what was intended or what looks good on paper.

Methodology. A security risk assessment aligned with ISO 31000:2018 applies a structured, documented methodology to threat identification, vulnerability analysis, and risk rating. This methodology is recognisable and defensible to regulators, auditors, and boards. An assessment that applies a consistent, standards-aligned methodology produces findings that can be compared over time and across sites — which is particularly valuable for operators with multiple assets.

Specificity. The CIRMP physical security plan requires specific, site-level findings — not generic statements about security. The assessment identifies which access control arrangements are adequate, which are not, where perimeter controls have gaps, what the out-of-hours monitoring capability actually looks like, and how incident response arrangements perform against the scenarios most likely to occur at this specific site. This specificity is what makes the plan credible.

Independence for board and regulatory purposes. A physical security plan supported by an independent assessment carries more weight with boards, auditors, and regulators than one that is self-certified. For responsible entities whose CIRMP attestation is subject to oversight — and increasingly to audit — the provenance of the assessment matters.

 

What This Means for WA Critical Infrastructure Operators

Western Australia has a significant concentration of critical infrastructure assets across the energy, water, transport, and health sectors. Energy generators and distributors, water utilities, port operators, freight infrastructure, and health service providers across metropolitan and regional WA are among the responsible entities operating assets that fall within the CIRMP framework.

For these organisations, the enhanced CIRMP physical security plan requirement is not a distant compliance consideration — it is an active obligation with a documented pathway requirement that begins now. The June 2028 attestation deadline sounds distant, but the requirement to have a documented compliance plan in the intervening reporting periods means the assessment and plan development process needs to begin in 2026.

The physical security landscape in WA also has specific characteristics that a WA-based independent consultant understands in ways that a national firm may not. Remote and regional assets — common in WA’s energy, water, and resources sectors — have different threat profiles and different practical constraints than metropolitan facilities. After-hours vulnerability is greater when response times are longer. Perimeter security in remote locations faces environmental and maintenance challenges that urban assets don’t. These realities need to be reflected in a physical security plan that is genuinely fit for purpose, not adapted from a template designed for a Sydney office building.

 

How Smartsec Supports CIRMP Physical Security Plan Development

Smartsec Security Solutions is an independent physical security consultancy based in Perth, delivering security risk assessments and physical security plans for critical infrastructure operators, government agencies, and commercial organisations across Western Australia.

Our approach to CIRMP physical security plan support:

Independent physical security assessment. Aligned with ISO 31000:2018, covering site nature and access arrangements, perimeter and physical access controls, surveillance and alarm systems, out-of-hours arrangements, sensitive area identification, and incident response capability. The assessment is the evidentiary foundation of the physical security plan.

Physical security plan development. Translating the assessment findings into a structured plan that addresses each element of the proposed CIRMP requirement — site nature, access controls, protective security measures, testing arrangements, and integration with other organisational plans.

Vendor-neutral advice. Smartsec does not supply or install security systems. Every recommendation reflects what the asset actually needs to meet its physical security obligations — not what a product range offers.

WA-based and available. For WA critical infrastructure operators, engaging a Perth-based independent consultant means site visits are practical, turnaround times are realistic, and the assessment reflects genuine knowledge of the WA operating environment.

Contact Smartsec Security Solutions to discuss your CIRMP physical security plan requirements and arrange a scoping conversation.

more insights

Call for a scope chat