High Severity
Unconstrained Registration Fees and Requirements
The Authority can unilaterally set annual registration fees for critical information infrastructure owners "as determined by the Authority" with no specified limits or proportionality requirements. Combined with 10's broad CII definition (including "digital services" and ministerial discretion), this could capture businesses unexpectedly. The Authority also determines "any other matter relating to registration" through guidelines—creating unpredictable compliance obligations without parliamentary oversight or exemptions for smaller operators.