
← In Australia’s National Interest - Security of Critical Infrastructure28 Aug · 23 min
The Enhanced CIRMP Rules 2026: Section 10A – From Supply Chain Risk Management to Critical Dependency Assurance
<p>The Enhanced CIRMP Rules 2026 introduce a significant uplift in supply chain security requirements for affected critical infrastructure entities.</p><p>In this episode, Tim Slattery and Marina Shteinberg from Pentagram Advisory unpack <strong>section 10A</strong> and explore the shift from traditional supply chain risk management towards <strong>critical dependency assurance</strong>. We examine what organisations may need to map, the distinction between major suppliers and dependencies supporting critical components, how deeply supply chains should be mapped, and the challenges involved in determining <strong>Maximum Acceptable Outage (MAO)</strong>.</p><p>We also explore major-supplier assessment and <strong>Foreign Ownership, Control or Influence (FOCI)</strong>, the intersection between supply chain dependencies and <strong>critical worker obligations</strong>, and the practical implementation questions responsible entities should be considering as they prepare for the <strong>10 June 2028</strong> implementation deadline.</p><p>The central question is no longer simply: <em>Who are our suppliers?</em></p><p>It is: <strong>What does our critical infrastructure asset depend upon, where do those dependencies sit, and do we have sufficient assurance and resilience to manage the resulting risk?</strong></p>