Australia Cyber Security Act (ransomware reporting)
In force Australia · In force Nov 30, 2024 · no upcoming deadlines
Deadlines
| Date | What happens | When |
|---|---|---|
| May 30, 2025 | Ransomware payment reporting starts16 months ago | 16 months ago |
| Jan 1, 2026 | Ransomware reporting moves to compliance phase9 months ago | 9 months ago |
Summaries for reference, not legal advice. Check the official text.
What it does
Australia's first standalone cyber law: mandatory reporting of ransomware or cyber-extortion payments within 72 hours, security standards for consumer smart devices, 'limited use' protections for information shared with ASD and the National Cyber Security Coordinator, and a Cyber Incident Review Board. Ransomware payment reporting has applied since 30 May 2025.
- Who it applies to
- Ransomware reporting: entities carrying on business in Australia with annual turnover above AUD 3 million in the previous financial year (pro-rated for part years), plus responsible entities for critical infrastructure assets regardless of turnover, that make or have a ransomware payment made on their behalf.
- Penalties
- Failure to report a ransomware payment: civil penalty of 60 penalty units (AUD 19,800 at the rate cited by commentators).
- Enforced by
- Department of Home Affairs; reports go to the Australian Signals Directorate (ASD)
- Official name
- Cyber Security Act 2024 (Cth) and Cyber Security (Ransomware Payment Reporting) Rules 2025
- Citation
- Act No. 98, 2024
- Topics
- cybersecurity, breach-notification
Research notes
Royal Assent was 29 Nov 2024 (from secondary sources); Part 1 commenced the next day. Commencement dates for the smart-device security standards were not verified here. Penalty unit values are indexed, and the AUD 19,800 figure uses the rate at commencement.
Related
Questions about Australia Cyber Security Act (ransomware reporting)
- What are the Australia Cyber Security Act (ransomware reporting) compliance deadlines?
- May 30, 2025: Ransomware payment reporting starts. Jan 1, 2026: Ransomware reporting moves to compliance phase.
- When does Australia Cyber Security Act (ransomware reporting) take effect?
- Australia Cyber Security Act (ransomware reporting) took effect on Nov 30, 2024.
- Who does Australia Cyber Security Act (ransomware reporting) apply to?
- Ransomware reporting: entities carrying on business in Australia with annual turnover above AUD 3 million in the previous financial year (pro-rated for part years), plus responsible entities for critical infrastructure assets regardless of turnover, that make or have a ransomware payment made on their behalf.
- What are the penalties under Australia Cyber Security Act (ransomware reporting)?
- Failure to report a ransomware payment: civil penalty of 60 penalty units (AUD 19,800 at the rate cited by commentators).