The Commonwealth law governing security of Australia's critical infrastructure across eleven sectors, with registration, incident reporting and risk management obligations.
The Security of Critical Infrastructure Act 2018 is the Commonwealth law managing national security risks to Australia's critical infrastructure. It is administered by the Department of Home Affairs through the Cyber and Infrastructure Security Centre, with some obligations overseen by sector-specific regulators.
It applies to responsible entities for critical infrastructure assets across eleven sectors: communications, data storage and processing, defence industry, energy, financial services and markets, food and grocery, health care and medical, higher education and research, space technology, transport, and water and sewerage.
The Act operates in layers, and not every layer applies to every asset:
The CISC moved from an education posture to active compliance enforcement from FY24–25. Civil penalties apply, including for failing to lodge a CIRMP annual report.
Owners and operators of assets listed on the Register of Critical Infrastructure Assets, or assets that should be listed, across the eleven defined sectors.
A common and uncomfortable position. Sector definitions are broad, and organisations in data storage and processing, higher education and food and grocery are frequently surprised to find themselves in scope. Uncertainty is not a defence.
Supply chain is one of the four CIRMP hazard vectors, so responsible entities must manage risks arising from their suppliers. That obligation reaches vendors through contracts.
Energy entities with AESCSF expectations, financial market operators with APRA obligations, hosting providers with Commonwealth requirements. The obligations stack rather than substitute.
Determine whether your asset is a critical infrastructure asset within one of the defined sectors, and which specific obligations have been switched on for your asset class. Not every obligation applies to every asset, and this determination shapes everything after it.
Provide and maintain ownership and operational information on the Register of Critical Infrastructure Assets.
Procedures that can actually meet a 12-hour clock. That is an operational capability question — who decides, who reports, out of hours — not a documentation exercise.
A board-approved written programme across four hazard vectors. This is the largest piece of work and is covered in detail on the CIRMP page.
The CIRMP must be reviewed at least every 12 months, and an annual report submitted to the relevant regulator within 90 days of the end of the financial year, approved by the board before submission.
Where an asset is declared a System of National Significance, additional obligations apply on government direction.
Soveriq starts by establishing which obligations actually apply to your asset, because the SOCI Act is not uniform — obligations are switched on by asset class and several entities over-build against requirements that were never activated for them.
From there we build the incident reporting capability against the real clocks, deliver the CIRMP where required, and prepare the annual report position for board approval.
Where ISO 27001 is held, it supplies much of the risk management, governance and audit machinery the CIRMP expects, and the personnel and supplier controls the other hazard vectors need.
On internal review. Where Soveriq has built your risk management programme, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.
What we will not do. Soveriq does not approve CIRMPs or annual reports, does not speak for the CISC, and does not promise a regulatory outcome.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
If you own or operate an asset listed on the Register of Critical Infrastructure Assets — or one that should be listed — you are a responsible entity. The CISC maintains the register and can advise. Given the obligations have been in force since 2023, uncertainty at this point is itself a compliance risk.
Critical incidents having a significant impact must be reported to ASD within 12 hours; other reportable incidents within 72 hours. These are separate from the ransomware payment reporting obligation under the Cyber Security Act, and separate again from any OAIC notifiable data breach obligation.
No. It sits alongside them. An energy entity may hold SOCI obligations, AESCSF expectations and state requirements at once. A financial market operator may hold SOCI and APRA obligations together.
A small set of assets declared by the Minister as most critical. They carry Enhanced Cyber Security Obligations on top of everything else — incident response planning, cyber exercises and vulnerability assessments on government direction. If this applies to you, you will know.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope