Why there is no one-line answer
Ask what cyber security compliance requires of an Australian business and you will get a different answer from everyone you ask, because the honest answer starts with questions. Obligations here do not attach to businesses as a category. They attach to activities: how much revenue you earn, what kind of data you hold, which sector you operate in, whether you take card payments, who licenses you, and what your contracts promise. Two companies of identical size can carry completely different obligations.
The regimes also stack. A private health insurer sits under the Privacy Act because health information is involved, under the Notifiable Data Breaches scheme because the Privacy Act covers it, under APRA's CPS 234 because it holds an APRA licence, under PCI DSS because it takes card payments, and potentially under the SOCI Act because health care and medical is a critical infrastructure sector. None of those regimes replaces another. Each adds obligations, a regulator or counterparty to answer to, and its own consequences for failure.
This guide maps the regimes most Australian businesses will meet into one table, then explains how to work out which rows are yours and what a sensible order of work looks like. The table is a starting point. Definitions and thresholds in the underlying legislation decide the hard cases, and several of these regimes are under active reform, so verify anything that will drive a real decision.
The map
Read the table by scanning the second column and marking every row that describes you. Most businesses find they sit under two or three rows. Regulated entities and critical infrastructure operators find more, and the rows they add are the ones with statutory clocks attached.
| Framework | Who it applies to | Mandatory or voluntary | Core obligation | Consequence of failure |
|---|---|---|---|---|
| Privacy Act 1988 (APPs) | Organisations with turnover over $3m, plus carved-out small businesses | Mandatory (law) | Handle personal information under the 13 APPs | OAIC enforcement; civil penalties reaching $50m or more |
| Notifiable Data Breaches scheme | Every entity the Privacy Act covers, plus TFN recipients | Mandatory (law) | Assess suspected breaches in 30 days; notify OAIC and individuals | OAIC enforcement; penalties; public determinations |
| SOCI Act | Responsible entities for assets in 11 critical infrastructure sectors | Mandatory (law) | Register assets, report incidents, run a risk management program | Civil penalties; government intervention powers |
| APRA CPS 234 | Banks, insurers and superannuation trustees regulated by APRA | Mandatory (prudential standard) | Security capability, control testing, notify APRA within 72 hours | Supervisory action; licence conditions; enforced remediation |
| PCI DSS | Any business storing, processing or transmitting cardholder data | Contractual (merchant agreements) | Meet the standard; validate annually by SAQ or assessment | Scheme fines; losing the ability to take cards |
| ISO 27001 | Any organisation seeking certifiable security management | Voluntary; often required by contract | Run and certify an ISMS; maintain surveillance audits | Certification lost or suspended; failed tenders |
| SOC 2 | Service organisations, typically SaaS selling to enterprise buyers | Voluntary; buyer-driven | Independent attestation against the Trust Services Criteria | Stalled enterprise sales; failed vendor reviews |
| SMB1001 | Australian small and medium businesses | Voluntary tiered certification | Meet a tier's requirements; renew annually | No legal penalty; weaker standing in supply chains |
| Essential Eight | Mandated for Commonwealth entities; a benchmark for everyone else | Voluntary outside government | Implement eight mitigation strategies to a maturity level | Procurement and contract consequences only |
Australian cyber security laws and frameworks: who they bind and what failure costs
How to work out which rows are yours
Six questions sort most businesses. Work through them with your actual numbers and contracts in front of you, because the edge cases turn on details.
- Is annual turnover above $3 million? If yes, the Privacy Act and the APPs apply, and the NDB scheme with them.
- If turnover is $3 million or under, do the exemption carve-outs catch you? Health service providers, businesses trading in personal information, and Commonwealth contracted service providers are covered regardless of size.
- Do you operate in, or supply data storage or processing to, one of the SOCI Act's critical infrastructure sectors? The 2021 and 2022 amendments widened these sectors considerably.
- Do you hold an APRA licence as a bank, insurer or superannuation trustee? CPS 234 applies, including to information assets your service providers manage for you.
- Do you store, process or transmit cardholder data in any channel, including over the phone? PCI DSS applies through your merchant agreement, scaled to your transaction volume.
- Do any current or target contracts name ISO 27001, SOC 2, an SMB1001 tier, or an Essential Eight maturity level? A contractual requirement binds as firmly as you signed it.
The small business exemption is narrower than it looks
The Privacy Act's small business exemption is the most misunderstood line in the table. The Act generally does not apply to a small business operator, meaning a business with annual turnover of $3 million or less. Plenty of businesses read that, note their revenue, and file privacy under not applicable. That conclusion is often wrong, for two reasons.
The first is the carve-outs. A business loses the exemption regardless of turnover if it provides a health service and holds health information, a bracket that reaches well past hospitals into physiotherapy practices, psychology clinics, gyms running health assessments and childcare centres. It also loses the exemption if it trades in personal information, that is, collects or discloses it for a benefit (buying or selling a marketing list is the classic case), if it is a contracted service provider under a Commonwealth contract, or if it is a credit reporting body. Broadly, a small business related to a larger corporate group is assessed against the group. And separately, any business that holds tax file numbers carries obligations for that information, including data breach notification duties for it, whatever its turnover.
The second is that the exemption is under sustained reform pressure. The Australian Government has agreed in principle to remove it as part of the wider Privacy Act review, with transition arrangements still to be worked through. A first tranche of Privacy Act reform legislation has already passed; it did not remove the small business exemption, but it shows the reform process is moving rather than stalled. Whether and when removal lands depends on legislation that has not yet been introduced, but a business planning its data handling around permanent exemption is relying on something the government has already said it intends to change. The safer approach is to treat the APPs as the eventual baseline, and to use any time under the exemption to prepare for it.
Mandatory, contractual and voluntary are different kinds of force
The third column of the table carries more weight than it looks. The mandatory rows are law. The Privacy Act and the NDB scheme are enforced by the OAIC, which can investigate, make determinations, and seek civil penalties that for serious interferences with privacy run to the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover. The SOCI Act is administered through the Department of Home Affairs and carries civil penalties plus something no other row has: government powers to step into your systems during a serious incident. CPS 234 is a prudential standard, so failure lands as supervisory action from APRA, which for a regulated entity can mean licence conditions and enforced remediation programs.
The mandatory rows also carry clocks. Under the NDB scheme, a suspected eligible data breach must be assessed within 30 days, and a breach likely to result in serious harm must be notified to the OAIC and affected individuals as soon as practicable. Under the SOCI Act, responsible entities for many assets must report significant cyber incidents to the Australian Cyber Security Centre within hours of becoming aware of them, with a longer window for less severe incidents. CPS 234 requires material information security incidents to be notified to APRA within 72 hours and material control weaknesses within ten business days. None of these timeframes can be met by a business that starts thinking about them on the day of the breach.
PCI DSS works differently. It is a contractual scheme run by the card industry rather than a law: it binds through your merchant agreement with your acquiring bank, scales its validation requirements with transaction volume, and enforces through fines passed down by the card schemes, higher transaction costs, and ultimately the loss of the ability to accept cards. ISO 27001, SOC 2, SMB1001 and the Essential Eight sit in the voluntary band, though the label is misleading in practice. The moment a contract, a tender condition or an insurance proposal names one of them, it binds as a commercial obligation, and a growing share of Australian procurement does exactly that. The Essential Eight is also mandated for non-corporate Commonwealth entities, which is why its maturity levels flow down supply chains into private contracts.
A sensible sequence
If a mandatory row binds you, it comes first, and there is no sequencing decision to make. An APRA-regulated entity does CPS 234. A SOCI responsible entity registers its assets, stands up incident reporting and builds its risk management program. Those obligations are current, dated and enforced.
For everyone else, the practical order runs from the legal floor upward. Start with a data inventory: what personal information you hold, where it lives, and which systems touch it. Every regime in the table assumes you know this, the NDB assessment clock cannot be met without it, and it is usually smaller work than teams fear. Then settle your Privacy Act position honestly, carve-outs included, and write the data breach response plan the NDB scheme quietly requires you to be capable of executing.
Next, shrink your contractual exposure before you comply with it. The clearest example is PCI DSS. A business that never touches cardholder data, because payments run through a hosted payment page or a tokenising provider, inherits a far smaller validation burden than one that lets card numbers pass through its own systems. Reducing the systems in scope is almost always cheaper than hardening them to the standard.
Then harden against the technical baseline the frameworks share: multi-factor authentication on everything internet-facing, patching on a cadence you actually keep, backups you have restored at least once, and administrative privilege stripped back to need. These controls appear in the Essential Eight and in SMB1001's tiers, they cut real-world compromise likelihood immediately, and every hour spent on them counts toward whichever assurance framework you certify against later.
Buy assurance last, in the order your market asks for it. For most smaller businesses that means an SMB1001 tier first, because the scheme is scaled to the size of the business and produces a dated certificate a buyer can verify. ISO 27001 comes when enterprise or government contracts demand a certified management system and you can carry the audit cycle that maintains it. SOC 2 matters when you sell software or services into markets, often through the United States, that ask for an attestation report. Certifying before the controls exist wastes the money twice: you fail the audit, or worse, you pass one that was scoped around the gaps.
Keeping the map current
The output of this exercise is deliberately small: a one-page obligations register listing each row that applies, why it applies, who owns it, and what evidence exists that it is being met. Review it when turnover crosses a threshold, when a new contract lands, when you enter a new sector or start holding a new class of data, and when legislation moves, which in this area is now roughly yearly. Obligations shift with the business as much as with the law, and a register written three years ago describes a different company.
Mapping which regimes bind you is the part a careful reader can do from this guide. Measuring the distance between what a row requires and what your systems actually do takes an assessment. Closing that distance is engineering work most teams do not carry in-house. Both are engagements we run at Black Shard, from Essential Eight and SMB1001 uplift through ISO 27001 readiness to the incident response planning the mandatory rows assume you already have. The register is the starting point for that conversation: which rows apply, what evidence backs each one, and where the gaps sit.
