
Physical security at Australian data centres crossed a significant threshold in December 2024. With Schedules 1 through 4 of the Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024 now in force, data centre security is no longer a matter of operational discretion. For operators classified as critical infrastructure owners, it is a binding legal obligation enforceable by the Cyber and Infrastructure Security Centre.
The Critical Infrastructure Risk Management Program framework requires operators to identify, assess, and manage material risks across defined hazard categories. Physical security controls, including layered access zones, manned guarding, and surveillance infrastructure, must now be demonstrably mapped to those obligations. Providers who cannot evidence compliance alignment are a procurement liability.
This analysis unpacks what the ERP Act actually demands, translates those obligations into specific physical security controls across four operational layers, and maps CISC’s hazard categories to the measures operators must specify. It closes with a procurement-ready framework for evaluating security providers and the single most common compliance gap operators overlook. If you are responsible for a CIRMP, this is your working reference.
Physical Security Is Now a Legal Obligation for Data Centre Operators
Under ERP Act Schedules 1–4 (commenced December 2024), data centre operators classified as critical infrastructure owners must demonstrate layered physical security controls as part of a binding Critical Infrastructure Risk Management Program (CIRMP), not as discretionary hardening. Gaps carry direct penalty risk: CISC holds enforcement authority to issue directions to remedy seriously deficient CIRMP elements.
Supporting rules covering protection of business-critical data and secondary systems commenced 4 April 2025, closing any remaining grace-period assumptions about implementation timelines.
Most operators still treat guards and access systems as operational cost lines rather than compliance deliverables. That distinction matters when CISC requests material risk evidence, and for anyone reconsidering whether physical protection belongs in their network security strategy alongside firewalls and endpoint controls.
Four control layers must be evidenced in your CIRMP:
- Layered access zones with documented zone architecture
- Manned guarding operating under CIRMP-aligned post orders and protocols
- Surveillance with compliant retention records
- Incident response workflows tied directly to your nominated CIRMP hazard categories
Controls that function on the ground but generate no auditable records do not satisfy CIRMP obligations.
What the ERP Act Actually Requires: CIRMP Obligations Unpacked

With the legal foundation set, it is worth unpacking what the CIRMP framework requires in operational terms.
Data centres serving energy, finance, and health sectors are classified as high-consequence assets, facing the most stringent CIRMP obligations. CISC guidance increasingly treats physical and cyber vectors as interdependent. Just as physical security protects your IP assets on site against tangible threats, your CIRMP must treat both vectors as a unified risk picture, not separate silos.
Layer 1: Access Zones and the Perimeter-to-Server-Room Model
Those documentation requirements apply at every physical layer, starting with how your facility is zoned.
A widely adopted zone architecture for CIRMP-aligned facilities follows a four-layer model: perimeter (outer boundary, vehicle exclusion), building envelope (entry points, lobbies), operational floor (raised floor, comms rooms), and critical asset zone (server racks, power infrastructure). Each boundary is typically assigned a distinct access control mechanism, proximity cards at the perimeter, biometric authentication at the operational floor, dual-person authorisation at the critical asset zone, with role-based access matrices tied directly to business-critical system ownership. (No single standard mandates this specific hierarchy; align your zone design to your own hazard assessment.)
Tailgating at internal zone transitions is commonly overlooked. A perimeter breach triggers alarms; an unauthorised person following authorised staff from lobby to server floor does not. Both carry equal weight as CIRMP material risk evidence.
Every access control system must produce time-stamped audit logs. A 90-day minimum is frequently cited in industry practice as a defensible baseline, though no current CIRMP rule specifies a fixed retention period, your hazard assessment should determine the appropriate window.
Mobile patrol services covering external perimeter zones complement fixed controls by generating documented, time-stamped patrol records that contribute directly to your CIRMP hazard management evidence file, something static infrastructure alone cannot produce.
Layer 2: Manned Guarding Standards That Satisfy CIRMP Requirements
Access controls establish where people can go; manned guarding determines what happens when those boundaries are tested.
Static guards at a CIRMP-compliant facility are not a commodity hire. Post orders should map directly to your identified CIRMP hazard categories and cover three practical non-negotiables: escalation protocols tied to incident severity thresholds, shift handover documentation, and visitor workflows that produce auditable records.
Guard licensing under applicable state security licensing legislation is a floor requirement, not a differentiator (verify the relevant Act for your jurisdiction). Operators who engage guards without specifying incident documentation requirements end up with staff who are operationally competent but compliance-invisible, generating no CIRMP-admissible evidence.
Providers experienced in high-consequence site guarding, construction, utilities, tend to have post-order templates that already capture escalation and handover requirements, and are worth prioritising in a shortlist.
When evaluating providers, request a sample incident report and shift log. As a practical baseline, test whether provider records capture at minimum: time, location, hazard category, response action, and escalation outcome. CISC has not published a mandated template, but these fields align with the material risk management evidence standard. A provider who cannot produce this sample is not CIRMP-ready regardless of licensing credentials.
Layer 3: Surveillance Systems and the Retention Records CISC Expects
Camera placement must align with your zone architecture. Every access control boundary needs coverage capturing both credential presentation and physical entry. One without the other leaves an evidentiary gap CISC enforcement reviews will identify.
Retention duration is where most operators fall short. Thirty-one-day rolling retention reflects a common default NVR setting rather than a defined compliance floor. Your hazard assessment should determine the appropriate retention window; higher-consequence asset classifications may warrant longer periods to support incident investigations or audit reviews.
Analytics integration matters for compliance, not just operations. Motion detection, tailgating alerts, and after-hours intrusion triggers convert surveillance from a passive archive into an active hazard detection mechanism, which is precisely what the CIRMP obligation to manage material risks requires. Professional security monitoring combining analytics-driven alerts with trained operator response and time-stamped logs produces the same class of compliance artifact as a guarding shift record.
As a matter of good compliance hygiene, document camera specifications, resolution, low-light performance, coverage angles, in your physical security schedule. A robust CIRMP position would document camera capabilities against nominated hazard types, anticipating that any regulator review would assess whether controls are capable of detecting the risks you have identified.
Common Pitfall to Avoid: Operators frequently nominate “unauthorised physical access” as a material hazard but run cameras that cannot resolve a face in low-light conditions. The control exists on paper; the capability does not. Specify minimum technical standards in procurement documentation before installation, not after your first enforcement review.
Layer 4: Incident Response Workflows as CIRMP Compliance Evidence
Your incident response plan must be structured as compliance evidence, not an operational SOP. Each response step must map to a specific identified hazard in your CIRMP and produce a traceable artifact demonstrating material risk remediation occurred.
A workflow structure that serves both operational and CIRMP evidence needs should capture at minimum four elements: the detection trigger (guard observation, CCTV or alarm monitoring alert, access control event); the immediate containment action taken; the escalation pathway to facility management and relevant notification thresholds; and the post-incident documentation output.
Detection is rarely the problem. Post-incident documentation is. The physical response happens, the record does not, leaving no CIRMP-admissible evidence.
Intruder detection, duress alarms, and access control events should feed a unified incident log that both your security guarding team and monitoring provider can write to. Separate records fail audits not because the data is wrong, but because reconstructing a coherent timeline from disconnected sources under CISC scrutiny is unnecessarily difficult.
How physical access failures connect to network intrusion risk is relevant context for structuring escalation thresholds.
Finally, document your drill frequency. CISC guidance expects operators to test risk management controls, and physical security drills with recorded outcomes are among the simplest compliance evidence you can produce.
ERP Act Hazard Categories Mapped to Physical Security Controls
The four layers above each map to a specific CIRMP hazard category. Use this table as your procurement reference.

| CIRMP Hazard Category | Physical Security Control | Required Compliance Artifact |
|---|---|---|
| Unauthorised physical access | Layered access zones with biometric or card-based enforcement | Time-stamped access logs with role-based audit trail |
| Physical damage or sabotage | Manned guarding with documented post orders and incident response protocols | Shift logs, incident reports, escalation records |
| Surveillance and reconnaissance | CCTV mapped to zone boundaries with analytics integration | Retention-compliant footage archives, alert logs, monitoring response records |
| Supply chain and contractor access | Visitor management systems, escort protocols, contractor access logs | Contractor access registers integrated into CIRMP documentation |
Note: These hazard sub-categories represent a practical interpretation of CIRMP obligations for physical security planning purposes. CIRMP Rules do not currently prescribe this specific taxonomy, operators should define sub-categories within their own hazard assessment.
The fourth row reflects emerging 2026 CISC guidance on supply chain risk; operators should build contractor access controls into their CIRMP documentation now, recognising this area continues to develop.
This table is also a vendor evaluation tool. Ask every provider tendering for guarding or surveillance contracts to populate the artifact column for their service. Providers who cannot are not CIRMP-ready, regardless of operational claims. For Melbourne portfolio operators, ABCO’s managed physical security model is structured to produce artifacts across all four categories.
What to Demand from Your Physical Security Provider
Specify CIRMP alignment in tender documents explicitly. A state security licence is a floor requirement, not evidence of compliance capability. Require providers to demonstrate their service model generates audit-admissible records as a shortlisting condition. Before evaluating whether a guard service is genuine protection or a compliance liability, request a sample documentation package: a shift log, an incident report, and an access control audit extract. Test each against your CIRMP requirements before contract award.
Contractual retention commitments are non-negotiable. If your provider purges incident records at 30 days but your CIRMP requires a longer retention window, that gap is your enforcement exposure. Lock retention periods and format standards into the contract.
For CCTV and alarm monitoring, specify that alert logs must be supplied in a format compatible with your CIRMP risk register. Most providers can deliver this; almost none will unless you require it in writing.
The fastest readiness test is one question: “Can you show me how your service generates evidence of material risk management?” A provider who answers clearly is likely compliant-capable. One who asks what CIRMP means is not.
Actionable Takeaways and a Common Pitfall to Avoid
Once you have the right providers in place, compliance work shifts to your own house.
- Audit first. Map each of the four layers (access zones, manned guarding, surveillance, incident response) against what your current controls produce. Identify gaps before CISC does.
- Update contracts now. Embed explicit documentation, retention periods, and audit trail formats into every physical security contract before your next review cycle. The Enhanced CIRMP Rules 2026 provide 12 to 24-month grace periods for compliance, but that window closes faster than procurement cycles move.
- Brief your providers. Share your CIRMP hazard categories with your guarding, CCTV, and patrol providers. Those who cannot engage with CIRMP requirements should be replaced.
Pro Tip: Specify required artifacts before you sign, not after your first compliance review.
The Conclusion below distils the single differentiator that separates operators who pass scrutiny from those who don’t.
Frequently Asked Questions
Q: When did ERP Act physical security obligations commence for Australian data centre operators? Schedules 1–4 commenced December 2024. Rules for protection of business-critical data and secondary systems commenced 4 April 2025.
Q: Does every data centre in Australia need a CIRMP? No. CIRMP obligations apply to operators classified as critical infrastructure owners under the SOCI Act. If your facility stores or processes data for energy, finance, or health sectors, classification is likely.
Q: What enforcement powers does CISC have over physical security? CISC can direct critical infrastructure entities to remedy seriously deficient CIRMP elements, with escalating consequences for non-compliance.
Q: What data centre security standards should our CIRMP physical security section reference? CIRMP guidance prescribes no specific technical standards. Physical security controls must be documented against your specific hazard assessment, not a generic standard.
Q: Can our existing security provider satisfy CIRMP requirements? Only if they can produce CIRMP-aligned audit artifacts: shift logs, incident reports, access records, and monitoring alert logs in retention-compliant formats. Operational capability alone is insufficient.
Conclusion

Physical security under the ERP Act is no longer a facilities management afterthought; it is a documented, auditable legal obligation with real enforcement consequences. Your existing provider may be operationally strong and still leave you exposed. The differentiator is documentation, and the operators who treat security records as a strategic compliance asset will be the ones who pass scrutiny with confidence.





