Availability

In development — available from November 2026

The TSRMP assessment is in development, with the functionality described below. If you would like to hear when it is released, get in touch and we will let you know.

The obligation moved

Telecommunications security obligations sat in Part 14 of the Telecommunications Act 1997 — the TSSR reforms — until 4 April 2025, when Schedule 5 of the Enhanced Response and Prevention Act 2024 commenced and moved them into the SOCI Act. They are now given effect by the Security of Critical Infrastructure (Telecommunications Security and Risk Management Program) Rules 2025. Entities working from TSSR-era documentation are working from a superseded regime.

Who the Rules apply to

The Rules attach to nominated telecommunications assets — critical telecommunications assets held by:

  • a carrier
  • a carriage service provider supplying 20,000 or more active carriage services, counted across broadband, fixed line, public mobile and voice-only services
  • a carriage service provider where the responsible entity knows the asset connects to carriage services supplied to a Commonwealth entity

Carriers carry additional obligations: a higher cyber security framework target, and notification to the Secretary of Home Affairs of changes to services or systems likely to materially affect the ability to protect the asset.

The four hazard vectors

A TSRMP must identify hazards posing a material risk to the asset, address minimising or eliminating that risk, and address mitigating the impact where a hazard occurs — across four vectors:

  • Cyber and information security — including remote access to operational control and monitoring systems
  • Personnel — the risk from people with access to the asset
  • Supply chain — third parties, vendors and dependencies
  • Physical security and natural hazards — site access and environmental exposure

The Rules treat a stoppage of the asset’s function for an unmanageable period, and interference with a billing and charging system, as material risks.

The cyber security framework requirement

The cyber vector is addressed by adopting and complying with one of five named frameworks:

  • AS/NZS ISO/IEC 27001:2023
  • Essential Eight Maturity Model (Australian Signals Directorate)
  • Framework for Improving Critical Infrastructure Cybersecurity (NIST)
  • Cybersecurity Capability Maturity Model (US Department of Energy)
  • 2020–21 AESCSF Framework Core (AEMO)

Carrier assets are set a Level 1 target within 18 months of the Rules applying to the asset, and Level 2 within 30 months. Relevant carriage service provider assets are set Level 1 within 18 months, maintained thereafter and updated according to the threat environment.

What the assessment will cover

The TSRMP assessment will carry the same working model as our other enterprise assessments:

  • Structured around the four hazard vectors, with scoring and evidence capture against each
  • Multi-site portfolio mode, rolling every site into one view while keeping each site separately scored
  • Period tracking and year-over-year comparison, so successive assessments are directly comparable
  • Self-assessment with independent reviewer override and evidence-confidence ratings side by side
  • Evidence register and full audit log — a chronological record of who changed what and when
  • Word and Excel exports — narrative report, gap register, evidence register and prioritised remediation plan
  • Optional AI features, off by default, running under your own provider key
  • Runs on your device — your assessment data stays local unless you enable the optional AI features

What You Receive

Narrative Word Report

Board-ready report covering each hazard vector and the nominated cyber security framework, for internal circulation and governing body review.

Gap Register

Findings mapped to the hazard vector they sit under, with risk ratings, exportable to Excel for remediation tracking.

Evidence Register

Evidence captured against each item with confidence ratings and a full audit trail of reviewer activity.

Prioritised Remediation Plan

Actions ranked by risk and implementation effort, structured to support the framework maturity timeline.

Consistent methodology enables periodic reassessment and year-over-year comparison across sites.

Want to know when the TSRMP assessment is released?

Tell us a little about your organisation and we will let you know when it is available and walk you through what it covers.

Register your interest

What this is

CyberAssure tools are structured self-assessments. They help you evaluate your own readiness, identify gaps, prioritise remediation and prepare for formal assessment. They are not a certification, conformity assessment, audit or legal advice, and CyberAssure is not a notified body, accredited certifier or auditor.

On coverage

We design our question sets to address the requirements we identify as applicable, and we publish a coverage map showing which provisions each question is drawn from. Because these regimes evolve, and because which requirements apply depends on facts about your own organisation and products, we cannot warrant that a question set addresses every requirement applicable to you. Identifying the full scope of your obligations remains your responsibility.

CyberAssure is not affiliated with, endorsed by, or accredited by the Department of Home Affairs, the Cyber and Infrastructure Security Centre, the Australian Communications and Media Authority, or any standards or regulatory body.

Often Used Alongside

Organisations frequently combine this assessment with complementary frameworks to address multiple governance requirements.

Critical Infrastructure

ECSO Readiness Assessment

Readiness for the Enhanced Cyber Security Obligations under SOCI Act Part 2C, for Systems of National Significance.

Learn more
Cyber Framework

Essential Eight Assessment

One of the five frameworks named in the TSRMP Rules — score the eight strategies across Maturity Levels 1–3.

Learn more

Have questions about how our assessments work?

Read the Enterprise Assessment FAQ →