SOCI Act 2018 — Security of Critical Infrastructure

The Commonwealth law governing security of Australia's critical infrastructure across eleven sectors, with registration, incident reporting and risk management obligations.

Department of Home Affairs, through the Cyber and Infrastructure Security Centre (CISC), with sector-specific regulators for some asset classes.

What it is

The Security of Critical Infrastructure Act 2018 is the Commonwealth law managing national security risks to Australia's critical infrastructure. It is administered by the Department of Home Affairs through the Cyber and Infrastructure Security Centre, with some obligations overseen by sector-specific regulators.

It applies to responsible entities for critical infrastructure assets across eleven sectors: communications, data storage and processing, defence industry, energy, financial services and markets, food and grocery, health care and medical, higher education and research, space technology, transport, and water and sewerage.

The Act operates in layers, and not every layer applies to every asset:

  • Registration. Providing ownership and operational information for the Register of Critical Infrastructure Assets.
  • Mandatory cyber incident reporting. Critical incidents within 12 hours, other reportable incidents within 72 hours — separate from the ransomware payment reporting obligation under the Cyber Security Act.
  • The Critical Infrastructure Risk Management Program. The centrepiece obligation, covered in detail on the CIRMP page.
  • Enhanced Cyber Security Obligations for the small set of assets declared Systems of National Significance — incident response planning, cyber exercises and vulnerability assessments on government direction.

The CISC moved from an education posture to active compliance enforcement from FY24–25. Civil penalties apply, including for failing to lodge a CIRMP annual report.

Who it's for

Responsible entities for critical infrastructure assets

Owners and operators of assets listed on the Register of Critical Infrastructure Assets, or assets that should be listed, across the eleven defined sectors.

Entities uncertain whether they are captured

A common and uncomfortable position. Sector definitions are broad, and organisations in data storage and processing, higher education and food and grocery are frequently surprised to find themselves in scope. Uncertainty is not a defence.

Suppliers to responsible entities

Supply chain is one of the four CIRMP hazard vectors, so responsible entities must manage risks arising from their suppliers. That obligation reaches vendors through contracts.

Entities holding overlapping obligations

Energy entities with AESCSF expectations, financial market operators with APRA obligations, hosting providers with Commonwealth requirements. The obligations stack rather than substitute.

Why implement it

  • It is law, with civil penalties attached. Failing to lodge a CIRMP annual report carries a civil penalty, and the regulator has moved from education to enforcement.
  • The incident clocks are short. Twelve hours for a critical incident is an operational capability, not a policy. Organisations discover on the day whether they have one.
  • It reaches beyond cyber. Personnel, supply chain and physical hazards are in scope, so a purely technical programme will not satisfy the obligation.
  • Board accountability is explicit. The annual report requires board approval, which puts critical infrastructure risk in front of directors personally.
  • The work is reusable. ISO 27001 and the Essential Eight both feed directly into SOCI obligations rather than sitting alongside them.

How implementation works

1. Establish whether you are a responsible entity

Determine whether your asset is a critical infrastructure asset within one of the defined sectors, and which specific obligations have been switched on for your asset class. Not every obligation applies to every asset, and this determination shapes everything after it.

2. Register the asset

Provide and maintain ownership and operational information on the Register of Critical Infrastructure Assets.

3. Build incident reporting capability

Procedures that can actually meet a 12-hour clock. That is an operational capability question — who decides, who reports, out of hours — not a documentation exercise.

4. Establish the CIRMP where it applies

A board-approved written programme across four hazard vectors. This is the largest piece of work and is covered in detail on the CIRMP page.

5. Review and report annually

The CIRMP must be reviewed at least every 12 months, and an annual report submitted to the relevant regulator within 90 days of the end of the financial year, approved by the board before submission.

6. Handle Enhanced Cyber Security Obligations if declared

Where an asset is declared a System of National Significance, additional obligations apply on government direction.

How Soveriq helps

Soveriq starts by establishing which obligations actually apply to your asset, because the SOCI Act is not uniform — obligations are switched on by asset class and several entities over-build against requirements that were never activated for them.

From there we build the incident reporting capability against the real clocks, deliver the CIRMP where required, and prepare the annual report position for board approval.

Where ISO 27001 is held, it supplies much of the risk management, governance and audit machinery the CIRMP expects, and the personnel and supplier controls the other hazard vectors need.

On internal review. Where Soveriq has built your risk management programme, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.

What we will not do. Soveriq does not approve CIRMPs or annual reports, does not speak for the CISC, and does not promise a regulatory outcome.

What the engagement looks like

  • Module 01 — Gap analysis against your SOCI obligations, starting with which ones actually apply to your asset.
  • Module 02 — Build. Register entries, incident reporting procedures against the 12 and 72-hour clocks, and the CIRMP where required.
  • Module 03 — Internal review ahead of the annual report, subject to the impartiality position above.
  • Module 04 — Representation where the CISC or a sector regulator engages directly.
  • Module 05 — Continuous compliance, including the annual review and report cycle.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Common questions

How do we know if we are a responsible entity?

If you own or operate an asset listed on the Register of Critical Infrastructure Assets — or one that should be listed — you are a responsible entity. The CISC maintains the register and can advise. Given the obligations have been in force since 2023, uncertainty at this point is itself a compliance risk.

What are the incident reporting timeframes?

Critical incidents having a significant impact must be reported to ASD within 12 hours; other reportable incidents within 72 hours. These are separate from the ransomware payment reporting obligation under the Cyber Security Act, and separate again from any OAIC notifiable data breach obligation.

Does the SOCI Act replace our other obligations?

No. It sits alongside them. An energy entity may hold SOCI obligations, AESCSF expectations and state requirements at once. A financial market operator may hold SOCI and APRA obligations together.

What are Systems of National Significance?

A small set of assets declared by the Minister as most critical. They carry Enhanced Cyber Security Obligations on top of everything else — incident response planning, cyber exercises and vulnerability assessments on government direction. If this applies to you, you will know.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope