The 2027 dates at a glance

What falls due, and when.

The headline dates across the three sectors BayRisk works in. The detail, and the gap behind each, is set out below.

DateSectorWhat is due
10 Dec 2026All sectorsPrivacy Act automated decision-making transparency commences, and bites into 2027.
10 Jun 2027Energy & utilitiesEnhanced CIRMP first-tranche obligations fall due for the nine designated asset classes.
30 Jun 2027Professional servicesAML/CTF program in place, compliance officer appointed, enrolled, and customer due diligence running.
1 Jul 2027All sectorsGroup 3 mandatory climate disclosure begins, for financial years starting on or after this date.
1 Jul to 30 Sep 2027Professional servicesFirst AML/CTF compliance report due to AUSTRAC. The concrete 2027 deadline.
28 Sep 2027Energy & utilitiesAnnual board-attested CIRMP report, 90 days after the 30 June year end.
2026 to 2028Financial servicesAPRA CPS 230 supervision escalates, moving to business-as-usual ongoing supervision.
By sector

What 2027 asks of your sector.

Energy & utilities

SOCI and critical infrastructure.

  • 10 June 2027 is the hard date. The first tranche of enhanced CIRMP obligations falls due for the nine designated asset classes (electricity, energy market operator, gas, liquid fuel, water, broadcasting, DNS, freight infrastructure and freight services). It covers additional material risks including foreign ownership, control or influence, offshore or remote access, patching and legacy technology risk processes, and personnel access management.
  • 28 September 2027: the annual board-approved CIRMP report, as every year, 90 days after the 30 June year end.
  • Around mid-2027: the Essential Eight begins to be deprecated, with a replacement under ASD consultation and both running in parallel. Full retirement is expected around mid-2028.
  • On the horizon: further SOCI amendments from the Slay review, likely including new powers for the Minister to direct an entity to cease using a specified vendor, product or service that presents a material security risk.
  • The one after 2027: AESCSF Security Profile 2 across the domains, board-attested, by 30 June 2028.
The gap most firms have not closed

Most teams have read the instrument and mapped it onto their existing cyber program. Far fewer have resolved foreign ownership, control and influence across their suppliers, put personnel access management in place, dealt with legacy and patching as a governed process, and made the shift from a documented position to one that is proven and board-attested on any given day.

Talk through your CIRMP position →
Financial services

APRA and beyond.

  • CPS 230 supervision escalates. APRA reviews a second subset of entities across 2026 to 2027, with heightened supervision where a material event occurs or an entity is a material service provider outlier, then moves to business-as-usual ongoing supervision in 2027 to 2028. The register and event notifications need to be real, not on paper.
  • CPS 230 targeted amendments for non-traditional service providers are in consultation and likely to progress through 2027, and fourth-party expectations keep tightening.
  • Mandatory climate disclosure: Group 3 applies to financial years beginning on or after 1 July 2027, with Group 2 already reporting from July 2026. The May 2026 Budget proposed raising the Group 3 entry thresholds and opened a consultation on assurance and supplier information, so the edges are moving while the core holds. Scope 3 becomes mandatory from each entity's second reporting year.
  • Scams Prevention Framework: sector codes for banks are phasing in across 2026 to 2027.
  • FAR is fully in force and embedding, with accountability implications that tie directly into CPS 230.
The gap most firms have not closed

The register and the event notifications exist, but they have to operate in practice under a regulator now moving to ongoing supervision. The harder edge is fourth-party visibility behind material service providers, and, for many, getting Group 3 climate reporting ready before the first financial year that starts on or after 1 July 2027.

Pressure-test your CPS 230 position →
Professional services

AML Tranche 2: law, accounting, real estate, conveyancing, TCSPs and precious metals.

  • 2027 is the first full year inside the regime (obligations commenced 1 July 2026). The message from AUSTRAC is to prove it works in daily operations, not on paper.
  • 30 June 2027: AUSTRAC expects the compliance checklist complete, the entity enrolled, an AML/CTF compliance officer appointed, the program in place, and customer due diligence running.
  • 1 July to 30 September 2027: the first AML/CTF compliance report is due. This is the concrete 2027 deadline.
  • AUSTRAC focus for the year: programs running in practice, higher-quality suspicious matter reporting, and intensified supervision of virtual asset providers. Enforcement risk rises.
  • Further out: the customer due diligence transition and the first independent evaluations sit in 2029.
The gap most firms have not closed

Many firms are enrolled on paper. The 2027 test is whether the program actually runs day to day, produces higher-quality suspicious matter reporting, and can stand behind a defensible first compliance report between July and September 2027.

Get ready for your first AML report →
Across all three sectors

Two obligations that catch everyone.

  • Privacy Act: automated decision-making transparency commences 10 December 2026 and bites into 2027, with second-tranche privacy reforms progressing behind it.
  • Climate: Group 3 mandatory reporting from 1 July 2027 catches mid-sized firms in every sector, not only financial services.
Frequently asked

2027 deadlines, answered.

When is the enhanced CIRMP first-tranche deadline?

10 June 2027. The first tranche of enhanced CIRMP obligations under the SOCI Act falls due for the nine designated asset classes, covering additional material risks including foreign ownership, control or influence, offshore or remote access, patching and legacy technology, and personnel access management. The annual board-attested CIRMP report is then due 28 September 2027.

When is the first AML Tranche 2 compliance report due?

Between 1 July and 30 September 2027. Tranche 2 obligations commenced 1 July 2026, so 2027 is the first full year in the regime, and AUSTRAC expects programs enrolled, an AML/CTF compliance officer appointed and customer due diligence running by 30 June 2027.

When does Group 3 mandatory climate reporting start?

For financial years beginning on or after 1 July 2027. Group 3 catches many mid-sized firms across every sector, and Scope 3 emissions become mandatory from each entity's second reporting year. The May 2026 Budget proposed raising the Group 3 entry thresholds, so the edges are still moving.

What is APRA doing on CPS 230 in 2027?

Escalating supervision. APRA reviews a second subset of entities across 2026 to 2027, with heightened supervision where a material event occurs or an entity is a material service provider outlier, before moving to business-as-usual ongoing supervision in 2027 to 2028. The register and event notifications need to be operating in practice, not on paper.

Free resource

Get the 2027 readiness checklist.

A concise, one-page checklist of what your sector needs in place for 2027, and by when. Enter your work email and we will send it through.

Download the checklist

Business email required.

We'll use your details to send the checklist and occasional relevant BayRisk updates. Personal email domains (Gmail, Outlook and similar) aren't accepted.

Turn the calendar into a plan

Know your 2027 dates. Now make them provable.

A short, private briefing to map your sector's 2027 obligations against where you actually stand, and what to move first.

Book a 30-minute briefing

This page is general information, not legal or compliance advice, and dates and obligations are summarised as at September 2026 from the Cyber and Infrastructure Security Centre and the Federal Register of Legislation (enhanced CIRMP Rules F2026L00701), APRA (CPS 230, CPG 230), AUSTRAC (Tranche 2 timeline and 2026 to 2027 priorities), Treasury and ASIC (AASB S2 mandatory climate disclosure) and the OAIC (Privacy Act reforms). Confirm every date against the relevant regulator before relying on it.