AESCSF explained: security profiles, maturity levels and what an assessment involves

Updated 15 September 2026 · 6 minute read

The Australian Energy Sector Cyber Security Framework (AESCSF) is the cyber framework written for Australia's electricity, gas and liquid fuel operators. It is the one most energy entities choose to meet their SOCI risk management obligations, and it is the assessment we are asked to run most often.

Where it comes from

AESCSF was developed by the Australian Energy Market Operator with industry and government. It builds on the US Department of Energy's Cybersecurity Capability Maturity Model (C2M2) and its energy-sector variant, with Australian additions such as privacy management. Version 2 of the framework is the current one.

It is a maturity framework, not a control checklist. It asks how well established each practice is, not only whether a control exists.

Domains, practices and maturity indicator levels

The framework is organised into domains: areas such as asset and configuration management, threat and vulnerability management, situational awareness, identity and access, event and incident response, supply chain, workforce and cyber security programme management. Each domain contains practices.

Each practice is placed at a Maturity Indicator Level. MIL-1 practices are the basics, often performed ad hoc. MIL-2 practices are documented, resourced and repeatable. MIL-3 practices are managed, measured and improved. An organisation's answers across the practices produce its maturity picture per domain.

Security profiles: which practices you must meet

Not every operator needs every practice. AESCSF begins with a criticality assessment that considers factors such as the size of the load or generation an entity serves and the consequence of its loss. The result places the entity in a Security Profile: SP-1 for lower criticality, SP-2 and SP-3 for higher. The profile decides which practices, and at which maturity level, are expected.

SP-1 is the profile named in the CIRMP rules as an accepted cyber security framework, which is why many entities target it first. Higher-criticality entities are expected to reach SP-2 or SP-3.

How an assessment runs

  • Scope: which entity, which sites, which systems, and the target profile.
  • Evidence: policies, procedures, network designs, asset registers, access records, monitoring output, exercise reports. Interviews with the people who run the plant, not just the security team.
  • Scoring: each practice is assessed as implemented, partially implemented or not implemented, with the evidence recorded, in AEMO's toolkit.
  • Findings: the practices below the target profile, why, and what would close each one. A new site can be assessed against its design, with the operational practices flagged for reassessment once it is running.
  • Roadmap: for entities moving from SP-1 to SP-2, a sequenced plan that fits the outage calendar and the budget cycle.

The mistakes that cost time

  • Answering for the corporate IT environment when the question is about the control system.
  • Claiming a practice because a document exists, when the practice is not performed.
  • Treating the criticality assessment as a formality. Get the profile right and the rest of the work is sized correctly.
  • Leaving the roadmap until after the report. The gaps are known during the assessment; the plan can start then.
Sources
  • AEMO, Australian Energy Sector Cyber Security Framework v2 and toolkit
  • Security of Critical Infrastructure (Critical infrastructure risk management program) Rules

Questions we get asked

Is AESCSF only for electricity?
No. It applies to electricity, gas and liquid fuel operators, with sector-specific criticality assessments.
How long does an SP-1 assessment take?
It depends on the size of the estate and how ready the evidence is. A single site with a cooperative operations team is a matter of weeks from kick-off to report.

Want this applied to your plant?

Tell us the site, the systems and the regulator. A consultant will reply, not a sales queue.