New regulations introduce specific obligations for providers managing third-party-owned critical information infrastructure.
Effective 13 July 2026, the Cybersecurity (Providers of Essential Service Responsible for Cybersecurity of Third-Party-Owned Critical Information Infrastructure) Regulations 2026 establish the technical criteria, forms, and timelines for obligations under Part 3A of the Cybersecurity Act 2018.
Why it mattersLawyers must ensure their clients who provide cybersecurity services for third-party critical infrastructure are compliant with these new prescriptive timelines and technical standards.