Skip to content

Australia Cyber Security Act (ransomware reporting)

In force Australia · In force Nov 30, 2024 · no upcoming deadlines

Deadlines

DateWhat happens
May 30, 2025Ransomware payment reporting starts16 months ago
Jan 1, 2026Ransomware reporting moves to compliance phase9 months ago

Summaries for reference, not legal advice. Check the official text.

What it does

Australia's first standalone cyber law: mandatory reporting of ransomware or cyber-extortion payments within 72 hours, security standards for consumer smart devices, 'limited use' protections for information shared with ASD and the National Cyber Security Coordinator, and a Cyber Incident Review Board. Ransomware payment reporting has applied since 30 May 2025.

Who it applies to
Ransomware reporting: entities carrying on business in Australia with annual turnover above AUD 3 million in the previous financial year (pro-rated for part years), plus responsible entities for critical infrastructure assets regardless of turnover, that make or have a ransomware payment made on their behalf.
Penalties
Failure to report a ransomware payment: civil penalty of 60 penalty units (AUD 19,800 at the rate cited by commentators).
Enforced by
Department of Home Affairs; reports go to the Australian Signals Directorate (ASD)
Official name
Cyber Security Act 2024 (Cth) and Cyber Security (Ransomware Payment Reporting) Rules 2025
Citation
Act No. 98, 2024
Topics
cybersecurity, breach-notification
Verified 2026-09-22 homeaffairs.gov.au
Research notes

Royal Assent was 29 Nov 2024 (from secondary sources); Part 1 commenced the next day. Commencement dates for the smart-device security standards were not verified here. Penalty unit values are indexed, and the AUD 19,800 figure uses the rate at commencement.

Related

Questions about Australia Cyber Security Act (ransomware reporting)
What are the Australia Cyber Security Act (ransomware reporting) compliance deadlines?
May 30, 2025: Ransomware payment reporting starts. Jan 1, 2026: Ransomware reporting moves to compliance phase.
When does Australia Cyber Security Act (ransomware reporting) take effect?
Australia Cyber Security Act (ransomware reporting) took effect on Nov 30, 2024.
Who does Australia Cyber Security Act (ransomware reporting) apply to?
Ransomware reporting: entities carrying on business in Australia with annual turnover above AUD 3 million in the previous financial year (pro-rated for part years), plus responsible entities for critical infrastructure assets regardless of turnover, that make or have a ransomware payment made on their behalf.
What are the penalties under Australia Cyber Security Act (ransomware reporting)?
Failure to report a ransomware payment: civil penalty of 60 penalty units (AUD 19,800 at the rate cited by commentators).

When the rules change: new data, privacy and AI laws and deadlines, the next morning.