ECSO Readiness Assessment
Readiness for the Enhanced Cyber Security Obligations under SOCI Act Part 2C, for Systems of National Significance.
Learn moreStructured around the Telecommunications Security and Risk Management Program obligations that apply to carriers and carriage service providers under the SOCI Act.
Availability
The TSRMP assessment is in development, with the functionality described below. If you would like to hear when it is released, get in touch and we will let you know.
Telecommunications security obligations sat in Part 14 of the Telecommunications Act 1997 — the TSSR reforms — until 4 April 2025, when Schedule 5 of the Enhanced Response and Prevention Act 2024 commenced and moved them into the SOCI Act. They are now given effect by the Security of Critical Infrastructure (Telecommunications Security and Risk Management Program) Rules 2025. Entities working from TSSR-era documentation are working from a superseded regime.
The Rules attach to nominated telecommunications assets — critical telecommunications assets held by:
Carriers carry additional obligations: a higher cyber security framework target, and notification to the Secretary of Home Affairs of changes to services or systems likely to materially affect the ability to protect the asset.
A TSRMP must identify hazards posing a material risk to the asset, address minimising or eliminating that risk, and address mitigating the impact where a hazard occurs — across four vectors:
The Rules treat a stoppage of the asset’s function for an unmanageable period, and interference with a billing and charging system, as material risks.
The cyber vector is addressed by adopting and complying with one of five named frameworks:
Carrier assets are set a Level 1 target within 18 months of the Rules applying to the asset, and Level 2 within 30 months. Relevant carriage service provider assets are set Level 1 within 18 months, maintained thereafter and updated according to the threat environment.
The TSRMP assessment will carry the same working model as our other enterprise assessments:
Board-ready report covering each hazard vector and the nominated cyber security framework, for internal circulation and governing body review.
Findings mapped to the hazard vector they sit under, with risk ratings, exportable to Excel for remediation tracking.
Evidence captured against each item with confidence ratings and a full audit trail of reviewer activity.
Actions ranked by risk and implementation effort, structured to support the framework maturity timeline.
Consistent methodology enables periodic reassessment and year-over-year comparison across sites.
Tell us a little about your organisation and we will let you know when it is available and walk you through what it covers.
Register your interestCyberAssure tools are structured self-assessments. They help you evaluate your own readiness, identify gaps, prioritise remediation and prepare for formal assessment. They are not a certification, conformity assessment, audit or legal advice, and CyberAssure is not a notified body, accredited certifier or auditor.
We design our question sets to address the requirements we identify as applicable, and we publish a coverage map showing which provisions each question is drawn from. Because these regimes evolve, and because which requirements apply depends on facts about your own organisation and products, we cannot warrant that a question set addresses every requirement applicable to you. Identifying the full scope of your obligations remains your responsibility.
CyberAssure is not affiliated with, endorsed by, or accredited by the Department of Home Affairs, the Cyber and Infrastructure Security Centre, the Australian Communications and Media Authority, or any standards or regulatory body.
Organisations frequently combine this assessment with complementary frameworks to address multiple governance requirements.
Readiness for the Enhanced Cyber Security Obligations under SOCI Act Part 2C, for Systems of National Significance.
Learn moreOne of the five frameworks named in the TSRMP Rules — score the eight strategies across Maturity Levels 1–3.
Learn moreHave questions about how our assessments work?
Read the Enterprise Assessment FAQ →