What Is the AESCSF? A Guide for Australian Energy Organisations (2026)

by | Security Resources

First Published:

August 18, 2026

Content Written For:

Small & Medium Businesses

Large Organisations & Infrastructure

Government

Read Similar Articles

The Australian Energy Sector Cyber Security Framework (AESCSF) is the cyber security maturity framework published by the Australian Energy Market Operator (AEMO) for organisations in the electricity, gas and liquid fuels sub-sectors. It measures an organisation’s cyber capability across 11 domains and sets target maturity through Security Profiles matched to how critical the organisation is to Australia’s energy system.

Since June 2026 the framework carries regulatory weight it did not have before. The enhanced Critical Infrastructure Risk Management Program (CIRMP) Rules name the 2023 AESCSF Framework Core, met at Security Profile 2, as a compliance pathway for critical energy assets under the Security of Critical Infrastructure (SOCI) Act, with the grace period ending in June 2028. This guide explains how the framework works, who it applies to and what the 2026 changes require.

Key Takeaways

  • AEMO publishes the AESCSF for the electricity, gas and liquid fuels sub-sectors. It is built on the US Department of Energy’s C2M2 maturity model, adapted for Australian conditions.
  • Version 2 (2023) spans 11 domains containing 354 practices and anti-patterns. Practices carry Maturity Indicator Levels; targets are set by Security Profiles SP-1 to SP-3.
  • The June 2026 enhanced CIRMP Rules require critical electricity, gas, liquid fuel and energy market operator assets using the AESCSF pathway to meet Security Profile 2, with the transition window closing in June 2028.
  • Alternatives under the same rules: the Essential Eight at Maturity Level Two, AS ISO/IEC 27001:2023, NIST CSF 2.0, C2M2 v2.1 at MIL-2, or an equivalent framework with justification.
  • Entities whose chosen framework does not mandate phishing-resistant multi-factor authentication must implement it anyway under the new credential compromise requirements.

What Is the AESCSF?

AEMO developed the AESCSF with industry and government to give Australian energy organisations a common way to assess and uplift cyber security capability. Rather than prescribing a fixed control list, it is a maturity model: it describes practices at increasing levels of sophistication and lets each organisation measure where it stands, domain by domain.

The framework’s foundation is the US Department of Energy’s Cybersecurity Capability Maturity Model (C2M2), extended with Australian-specific elements and aligned to the energy sector’s operating reality, including operational technology environments where a control that suits a corporate network would be impractical or unsafe.

How the Framework Is Structured

ElementWhat it is
DomainsEleven logical groupings of cyber capability, each with its own objectives.
ObjectivesTarget achievements within each domain, numbered per domain.
PracticesPositive security activities. Version 2 contains 354 practices and anti-patterns across the 11 domains.
Anti-patternsNegative patterns that should not be present. Nine of the 11 domains include them.
Maturity Indicator Levels (MILs)Each practice carries a MIL from MIL-1 to MIL-3 indicating its relative maturity. Maturity is assessed independently for each domain.
Security Profiles (SPs)SP-1 to SP-3 bundle target MILs across the framework into a single target state matched to organisational criticality.

The anti-patterns are the framework’s most distinctive feature. A domain score is not only about what you do; it also falls if assessors find practices that should not exist, such as flat networks between corporate and control systems. That makes the AESCSF harder to game with paperwork than a pure control checklist.

Security Profiles and Criticality

Your target profile is not a free choice. The framework provides criticality assessment tools that classify each organisation by its potential impact on the energy system, and the resulting criticality band sets the Security Profile you are expected to meet. A small embedded generator and a transmission operator are measured with the same yardstick but held to different marks.

SP-1 represents foundational capability. SP-2 requires the majority of practices to operate at MIL-2, meaning controls are documented, resourced and repeatable rather than ad hoc. SP-3 is the target for the most critical operators.

What Changed in Version 2

AEMO released AESCSF version 2 in 2023. It aligned the framework to C2M2 version 2.1, expanded coverage across the electricity, gas and liquid fuels sub-sectors, and grew the practice set to 354 practices and anti-patterns. AEMO has since added a Lite version and priority practices guidance for distributed and consumer energy resources (DER/CER) organisations, extending the framework to smaller participants in the energy ecosystem.

Version 2 also matters legally: the 2023 AESCSF Framework Core is the specific document the enhanced CIRMP Rules incorporate, so assessments against version 1 do not satisfy the new requirements.

AESCSF and the SOCI Act: What Changed in June 2026

Under the SOCI Act, responsible entities for critical infrastructure assets must run a Critical Infrastructure Risk Management Program and align it to a recognised cyber security framework. The Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026, registered on 9 June 2026, raised that bar for nine asset classes, including critical electricity, gas, liquid fuel and energy market operator assets.

For those assets, the framework options and required levels are now:

FrameworkRequired level
2023 AESCSF Framework Core (AEMO)Security Profile 2
Essential Eight Maturity Model (ASD)Maturity Level Two
AS ISO/IEC 27001:2023As specified in the standard
NIST Cybersecurity Framework (CSF) 2.0As specified in the document
C2M2 Version 2.1 (US Department of Energy)Maturity Indicator Level 2
An equivalent frameworkMust achieve security equivalent to the conditioned options above

Existing critical infrastructure assets have 24 months from commencement, so the enhanced framework requirements bite in June 2028. The rules also specify four material risks every enhanced CIRMP must address (unpatched systems, legacy technology, and the deployment of and attacks using advanced or emerging technology), and they require phishing-resistant multi-factor authentication where the chosen framework does not already mandate it. Our SOCI Act compliance services cover the CIRMP obligations end to end.

For energy participants the practical consequence is simple: if your CIRMP references the AESCSF, an SP-1 result that satisfied the original rules will not satisfy the enhanced rules. The gap between SP-1 and SP-2 is a two-year uplift programme for many organisations, and the window is already running.

AESCSF, Essential Eight or ISO 27001?

Energy organisations already inside the AESCSF assessment cycle usually stay with it: the framework speaks the sector’s language, covers operational technology and is what AEMO and market peers benchmark against. Organisations with a corporate-IT-dominated environment sometimes prefer the Essential Eight at Maturity Level Two, which is narrower but highly prescriptive, or ISO 27001 where certification also serves commercial assurance. The honest answer is that the best framework is the one your environment can evidence: the CIRMP annual report is approved by your board and submitted to the regulator, so the choice must survive scrutiny.

How to Reach Security Profile 2

  • Confirm your criticality and scope. Run the criticality assessment, then define which assets and environments the assessment covers, including OT.
  • Self-assess against version 2. Score every domain honestly, anti-patterns included. An inflated self-assessment only moves the pain to the audit.
  • Gap-plan to SP-2. Map every practice below target, prioritising domains where anti-patterns or MIL-1 scores concentrate.
  • Uplift with evidence. Treat each closed gap as a control that must produce records, because the CIRMP annual report and any regulator engagement will ask for them.
  • Reassess annually. Maturity decays; the framework assumes a cycle, not a one-off project.

How CyberPulse Helps

CyberPulse runs AESCSF-aligned maturity assessments, SP-2 gap analysis and uplift programmes for energy sector organisations, and builds and audits the surrounding SOCI Act CIRMP obligations: the risk management program itself, the four hazard vectors, incident reporting readiness and the board-approved annual report. Where the Essential Eight or ISO 27001 is the better fit for your environment, our GRC and advisory team supports those pathways too.

CyberPulse
Energy sector operator? Get a fixed-price AESCSF gap assessment mapped to your SOCI CIRMP obligations.

AESCSF FAQs

Is the AESCSF mandatory?

The framework itself is not legislation. Its force comes from two places: AEMO’s sector assessment program, and the SOCI Act’s CIRMP Rules, which name the 2023 AESCSF Framework Core as a recognised framework. For critical energy assets under the enhanced rules, meeting a named framework at the required level, or an equivalent, is mandatory.

What is the difference between a MIL and a Security Profile?

A Maturity Indicator Level describes how mature a single practice or domain is. A Security Profile is the target state: it defines which MILs you must reach across the whole framework, based on your criticality.

Does the AESCSF apply outside the energy sector?

It was built for electricity, gas and liquid fuels, and those are the sub-sectors AEMO supports with tooling and guidance. Other critical infrastructure sectors use different frameworks under the CIRMP Rules; water operators, for example, typically align to ISO 27001, the Essential Eight or NIST CSF 2.0.

We are at SP-1 now. How urgent is the uplift?

The enhanced CIRMP grace period ends in June 2028 for assets that were critical infrastructure assets when the rules commenced in June 2026. Working back from a board-approved annual report, an SP-1 to SP-2 uplift across 11 domains with evidence behind it is a programme measured in years, not quarters. Starting in the final year is how operators end up attesting to gaps.

About the Author

CyberPulse is an Australian cyber security and compliance firm whose team includes former chief information security officers and experienced cyber risk practitioners. We work with critical infrastructure operators on SOCI Act obligations, framework-aligned maturity uplift and the evidence that stands behind a board-approved CIRMP annual report.

External Resources