COMPLIANCE · 12 MIN READ

SOCI Act Cyber Compliance — A Practical Guide for Australian Critical Infrastructure

What the Security of Critical Infrastructure Act actually requires, where responsible entities most often fall short, and how to evidence the cyber portion of your CIRMP to the board and Home Affairs.

Start a free mission

Why SOCI is now a board-level obligation

The Security of Critical Infrastructure Act 2018 has shifted from a notification regime to a positive security obligation regime. Boards of responsible entities can no longer treat cyber as an operational matter delegated to the CISO — they are accountable for approving a Critical Infrastructure Risk Management Program (CIRMP), attesting to its operation annually, and ensuring incidents are reported within hours, not days.

This guide is written for Australian CIOs, CISOs and company secretaries who need to evidence SOCI compliance without standing up a new program from scratch.

The five obligations that matter

ObligationOwnerCadence
Register of Critical Infrastructure AssetsResponsible entityNotify changes within 30 days
Critical Infrastructure Risk Management Program (CIRMP)Board approves; CISO/CIO operatesAnnual review + annual report to Home Affairs
Mandatory cyber incident reportingOperations + CISO12 hours (critical) / 72 hours (other), written follow-up at 84 hours
Enhanced Cyber Security Obligations (if declared SoNS)Executive + boardOn declaration; ongoing
Ministerial directions and government assistanceCEO + general counselAs directed

What the CIRMP must actually contain

The CIRMP Rules require responsible entities to identify and mitigate material risk across four hazard vectors: cyber and information security, personnel, supply chain, and physical and natural hazards. The cyber portion must align to a recognised framework — Essential Eight Maturity Level One is the most common floor, with ISO/IEC 27001, NIST CSF or AESCSF accepted alternatives.

  • Documented risk assessment covering all four hazard vectors, refreshed annually.
  • Mapped controls anchored to the chosen framework, with evidence of operation.
  • Board approval recorded in the minutes — Home Affairs can request this.
  • An annual report submitted by the responsible entity to the Department.

Mandatory incident reporting — the timeframes you cannot miss

Reporting clocks start the moment the entity becomes aware of an incident, not when it is fully understood. Australian critical infrastructure operators must report:

  • 12 hours — critical cyber security incidents with material impact on availability, to the ACSC.
  • 72 hours — other cyber security incidents with a relevant impact.
  • 84 hours — written follow-up to any initial verbal report.

Practically, this means your incident response runbook needs a pre-drafted SOCI report template, a named on-call notifier, and a board notification path that activates inside the 12-hour window.

FOR RESPONSIBLE ENTITIES

Pressure-test your CIRMP with a free mission.

Run your highest-risk SOCI scenario through FORTE/CYBERx and get a board-ready decision and tactical plan you can map directly back to your risk management program.

Run a free mission

Where responsible entities most often fall short

  • Board approval is informal. Verbal sign-off doesn't survive a Home Affairs request — the minutes need an explicit CIRMP approval resolution.
  • Framework mapping is loose. Picking Essential Eight is the easy part; evidencing Maturity Level One across all eight mitigation strategies is where most programs stall.
  • Supply chain is treated as procurement, not security. SOCI requires the responsible entity to assess and mitigate supply-chain risk, including managed service providers.
  • The 12-hour notifier isn't named. Without a designated on-call notifier with delegated authority, the clock runs out during escalation.
  • Annual reporting is left until June. Treat it as a quarterly artefact and the year-end submission becomes a formality.

Systems of National Significance (SoNS)

A small subset of critical infrastructure assets can be declared Systems of National Significance, triggering Enhanced Cyber Security Obligations. These can include mandatory cyber security exercises, vulnerability assessments, system information sharing and the installation of software for threat detection. If your asset is in scope or borderline, scenario-plan for an SoNS declaration before it arrives.

FAQ

Which entities are captured by the SOCI Act?

The Security of Critical Infrastructure Act 2018 (as amended) captures responsible entities and direct interest holders across 11 sectors including energy, water, communications, data storage and processing, financial services, food and grocery, health, higher education, transport, space, and defence industry. If your organisation owns or operates an in-scope asset, the obligations apply regardless of size.

What is the Critical Infrastructure Risk Management Program (CIRMP)?

Part 2A of the Act requires responsible entities for many asset classes to adopt, maintain and comply with a written CIRMP covering cyber and information security, personnel, supply chain and physical and natural hazards. The cyber portion must align to one of the recognised frameworks — typically ACSC Essential Eight Maturity Level One, ISO/IEC 27001, NIST CSF, AESCSF or an equivalent.

What are the mandatory cyber incident reporting timeframes?

Critical cyber security incidents that materially impact availability must be reported to the Australian Cyber Security Centre within 12 hours of becoming aware. Other cyber security incidents that have or are having a relevant impact must be reported within 72 hours. A written follow-up is also required within 84 hours of the initial verbal report.

Who owns SOCI compliance internally?

The board is accountable. The CIRMP must be approved by the board (or equivalent governing body) and reviewed annually, with an annual report submitted to the Department of Home Affairs. CISOs, CIOs and risk leaders run the program day-to-day, but board sign-off is non-delegable.

What happens if we fail to comply?

Civil penalties apply for non-compliance with CIRMP obligations, mandatory reporting and ministerial directions. More importantly, the government can issue Enhanced Cyber Security Obligations and, for systems of national significance, direct intervention. Reputational and contractual consequences typically exceed the statutory penalty.

Related

Evidence your CIRMP with a defensible decision.

Two free missions. No credit card. Built for Australian responsible entities and their boards.