One page. Every date.Six chapters · sourced

The Australian cyber and privacy regulatory calendar on one page

Every Australian regulatory date Real Bytes is tracking for clients. Cyber Security Act 2024, statutory privacy tort, Privacy Act reforms, ASD's Essential Eight evolution, Voluntary AI Safety Standard, and the Notifiable Data Breaches scheme. One timeline. Each row has the obligation, who is affected, what to do, and links to the Real Bytes detailed look and the primary source.

Designed for boards, CFOs, and operational leaders who need to know what is live, what is pending, and what is still in consultation.

Live, pending and consultation

Each row carries a status badge

Real Bytes deep-dive on each row

Plus a link to the primary source

Reviewed at the end of each quarter

Refresh date noted at the top

Editorially reviewed
Last reviewed31 Aug 2026
Sources verified31 Aug 2026

The calendar

Chronological. Sourced. Operationally relevant.

The calendar below is ordered by commencement or close date. Each row is a single regulatory instrument we expect a board or executive team to be briefed on. Most rows link to a full Real Bytes deep-dive page with operational controls and FAQ. The status badge tells you whether the obligation is live today, pending commencement, or still in public consultation.

In force

30 May 2025

Cyber Security Act 2024 (Cth), Part 3

Mandatory ransomware payment reporting

In force

Department of Home Affairs / National Cyber Security Coordinator

Businesses with annual turnover over $3 million, and all critical infrastructure entities, must report any ransomware payment to the Australian Signals Directorate, via the ReportCyber portal, within 72 hours of making the payment or becoming aware one was made on their behalf. Reporting does not legalise the payment; it is a transparency obligation that sits alongside existing OAIC and AUSTRAC obligations.

Who is affected

Australian businesses over $3M turnover and all SOCI-regulated critical infrastructure entities.

What to do

Update incident response plan with the 72-hour reporting clock. Brief board on payment-decision authority.

In force

10 Jun 2025

Privacy and Other Legislation Amendment Act 2024 (Cth)

Statutory tort for serious invasions of privacy

In force

Privacy Act 1988 (Cth)

For the first time in Australian law, individuals have a direct cause of action against any person or organisation that seriously invades their privacy, intentionally or recklessly, whether through intrusion on seclusion or misuse of information. The cause of action is not limited to entities covered by the Australian Privacy Principles. Small businesses currently exempt from the APPs are still exposed to the tort.

Who is affected

Any Australian business handling personal information, including those still exempt from the APPs under the $3M turnover rule.

What to do

Review surveillance policies, vendor due diligence, employee record handling, and incident response with the tort in mind.

In force

1 Jul 2025

APRA Prudential Standard CPS 230

Operational risk management for financial services

In force

Australian Prudential Regulation Authority (APRA)

CPS 230 commenced on 1 July 2025 for most APRA-regulated entities, consolidating five previous standards covering operational risk, business continuity and outsourcing. Boards are now accountable for identifying critical operations, setting tolerance levels for disruption, testing business continuity annually, and maintaining a register of material service providers with substitution plans. APRA finalised targeted amendments on 30 April 2026.

Who is affected

All APRA-regulated entities: ADIs (banks, credit unions, mutuals), general, life and private health insurers, and superannuation trustees.

What to do

Identify critical operations, set board-approved tolerance levels, build the material service provider register with substitution plans, and lock annual continuity testing into the board calendar.

In force

Ongoing

September 2024 release

Voluntary AI Safety Standard

In force

Department of Industry, Science and Resources

Australia's voluntary AI governance framework. Ten guardrails covering accountability, risk management, data quality, testing, transparency, contestability, human oversight, supply chain, and stakeholder engagement. It remains the reference framework Australian regulators use when assessing AI deployment. On 15 July 2026 the Government announced mandatory Australian AI Standards and a new Office of AI, affirmed by National Cabinet on 26 August 2026, with legislation expected in early 2027.

Who is affected

Any Australian organisation deploying AI in a way that affects customers, employees or members of the public.

What to do

Map current AI use to the ten guardrails now, ahead of the mandatory standards. Build a shadow AI policy. Brief board on AI risk ownership.

In force

4 Mar 2026

Cyber Security (Security Standards for Smart Devices) Rules 2025

Security standards for smart devices commenced

In force

Department of Home Affairs

Part 2 of the Cyber Security Act 2024 (Cth) commenced on 4 March 2026, alongside the Security Standards for Smart Devices Rules 2025. Manufacturers, importers and distributors supplying relevant connectable products (consumer IoT and smart devices) to the Australian market must meet baseline security standards aligned with ETSI EN 303 645: unique default passwords, a vulnerability disclosure policy, and defined minimum security update periods. Products manufactured before 4 March 2026 are not required to comply.

Who is affected

Manufacturers, importers and distributors of consumer connectable products supplied to the Australian market.

What to do

If you supply connectable consumer products in Australia, confirm ETSI EN 303 645 alignment, publish a vulnerability disclosure policy, and produce a statement of compliance on request.

Closed

5 Jun 2026

OAIC public consultation

Children's Online Privacy Code (Phase 3 consultation closed)

Closed

Office of the Australian Information Commissioner

OAIC released the exposure draft of the Children's Online Privacy Code on 31 March 2026. Phase 3 consultation (with children, parents and providers) closed on 5 June 2026. The Code introduces age assurance, default high privacy settings, and stricter handling rules for personal information of users under 18. The final Code must be registered by 10 December 2026.

Who is affected

Any business operating online services likely to be accessed by children under 18: schools and EdTech providers, retail and consumer platforms, social and messaging, gaming, healthcare platforms supporting paediatric care.

What to do

Map services likely to be used by under-18s. Review default privacy settings, data collection minimisation, and parental consent flows ahead of the Code being registered by 10 December 2026.

In force

1 Jul 2026

APRA CPS 230 transition deadline

CPS 230 now applies to smaller APRA-regulated entities

In force

Australian Prudential Regulation Authority (APRA)

Smaller superannuation entities and non-significant financial institutions had until 1 July 2026 to comply with CPS 230 Operational Risk Management. That transition date has now passed, so the standard applies across the regulated population. The core obligations are the same as for larger entities; APRA applies proportionality to the depth of documentation and testing.

Who is affected

Non-significant financial institutions, smaller mutual ADIs, smaller insurers, and small APRA superannuation funds.

What to do

Run the four-phase readiness pathway: critical operations identification, tolerance levels, material service provider register, and annual continuity testing.

Closed

12 Jul 2026

ASD public consultation

Essentials for enterprise IT consultation closed

Closed

Australian Signals Directorate (ASD)

ASD ran public consultation on the evolution of the Essential Eight into a new framework called Essentials for enterprise IT. The consultation closed on 12 July 2026. ASD will now work through submissions before publishing the final framework, with the Essential Eight remaining current guidance throughout a roughly two-year transition. The mitigation strategies behind today's Essential Eight remain the foundation.

Who is affected

Any Australian organisation tracking Essential Eight maturity, particularly enterprise and regulated industry operators.

What to do

Continue ML1 to ML3 work as planned. Document your current maturity with evidence so you are ready to map across when the successor framework lands.

Pending

10 Dec 2026

Privacy (Children's Online Privacy) Code 2026

Children's Online Privacy Code must be registered

Pending

Office of the Australian Information Commissioner

The final Children's Online Privacy Code must be registered by 10 December 2026, which is also the commencement date for other Privacy Act reforms. The Code complements the broader Privacy Act reform and the Social Media Minimum Age legislation. Once registered, the Code is binding on providers within scope.

Who is affected

Online service providers within the Code's scope. Likely to include EdTech, consumer apps and platforms, gaming services, and social media services accessed by users under 18.

What to do

Confirm whether your service is within scope. Build the age assurance, parental consent, and default high privacy settings into your roadmap before registration.

In force

Stage 1 in force

Scams Prevention Framework Act 2025 (Cth)

Scams Prevention Framework, sector rules in draft

In force

Treasury / ASIC / ACMA / ACCC

The Scams Prevention Framework Act 2025 (Cth) introduces a principles-based regime requiring designated sectors to prevent, detect, disrupt, respond to and report scams. Stage 1 of the SPF is in force. Treasury released the draft sector rules and codes on 28 May 2026, with mandatory sector obligations expected to commence in 2027 once the rules are finalised. Failure to meet obligations can result in significant civil penalties and customer reimbursement in some cases.

Who is affected

Initially designated sectors: banks and other ADIs, large telecommunications carriers and carriage service providers, and certain large digital platforms (social media, search, paid ads).

What to do

Designated entities should review the draft sector rules and begin scoping detection, disruption, customer warning and reimbursement workflows. Other entities should monitor sector-specific code obligations as they harden.

Pending

Tranche 2

Commencement subject to amending legislation

Removal of the Privacy Act small business exemption

Pending

Attorney-General's Department

The Australian Government has accepted in principle the recommendation from the Privacy Act Review Report to remove the small business exemption. Once commenced, approximately 2.5 million Australian businesses currently exempt under the $3 million turnover rule will be brought under the Australian Privacy Principles, the Notifiable Data Breaches scheme, and OAIC enforcement.

Who is affected

Approximately 2.5 million Australian businesses currently under the $3M turnover exemption.

What to do

Begin the six-month readiness pathway now. Build the personal information inventory, publish the policy, and rehearse breach response before commencement.

In force

Ongoing

Mandatory since 2018; small business extension pending

Notifiable Data Breaches scheme

In force

Office of the Australian Information Commissioner

Entities covered by the Privacy Act must assess suspected eligible data breaches within 30 days and notify the OAIC and affected individuals as soon as practicable once an eligible breach is identified. OAIC received 1,205 notifications across 2025, the highest annual total since the scheme commenced. The NDB scheme will extend to small business as the small business exemption is removed.

Who is affected

All entities currently covered by the Privacy Act, and previously-exempt small businesses once the exemption is removed.

What to do

Run an annual breach response rehearsal. Ensure the 30-day assessment clock and OAIC notification form are part of the runbook.

In force

Ongoing

Cyber insurance renewal cycle

Cyber insurance proposal form requirements

In force

Australian cyber insurance market

Australian cyber insurance underwriters now consistently require evidence of six operational controls on proposal forms: MFA on all users (especially privileged), EDR or MDR on all endpoints, tested backups including Microsoft 365, an incident response plan, patch management cadence, and security awareness training. Renewals through 2025 and 2026 are also beginning to ask about the statutory privacy tort and AI governance.

Who is affected

Any Australian business carrying cyber insurance, management liability, or directors and officers liability.

What to do

Map your controls to the six insurer requirements before renewal. Brief broker on tort and AI governance posture.

How to use this calendar

Pin this page in your board pack. Treat the live rows as already-running compliance obligations, the pending rows as known commencement dates to plan against, and the consultation rows as a window to submit a view before they harden into policy.

None of the rows above are interpretation. Each is sourced from the relevant Australian Government department, regulator or primary legislation. Updated at the end of each quarter, or sooner if a commencement date is announced.

The calendar is just the input

Real Bytes runs the operational work behind each row.

Privacy Act readiness, ransomware reporting playbooks, AI governance, board reporting cadence, and ASD-aligned cybersecurity maturity. The calendar above tells you what is changing. We help you stay ahead of it without scrambling at commencement.

This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.