Skip to main content
Critical Infrastructure · SOCI Act

The SOCI Act in 2026:
every obligation,
mapped.

The Security of Critical Infrastructure Act 2018 has been amended in almost every year since 2021, and most published guidance describes a version of it that no longer exists. Data storage systems are now part of the asset. Government assistance powers now reach all serious incidents, not just cyber. A regulator can now direct you to rewrite a deficient risk management program with 14 days' notice. And since June 2026, nine asset classes carry a second tier of prescriptive obligations on top of everything else.

This guide maps the Act as it actually stands in 2026: who is in scope, what each obligation tier requires, what the 2024 amendments changed, and which deadlines between now and June 2028 are real. It is written from the legislation itself, with the amending Acts and rules linked throughout.

Written by practitioners who hold ISO 27001 certification and advise critical infrastructure operators on security governance and SOCI compliance. We are not lawyers, and this is analysis of the legislation rather than legal advice.

01 / What the Act became

The SOCI Act is not one obligation. It is a tiered system that has grown a new layer roughly every eighteen months.

The Security of Critical Infrastructure Act 2018 began as a narrow instrument about foreign ownership and asset registers in four sectors. What operators must comply with in 2026 is the product of successive amendment, and understanding which layer each obligation came from is the fastest way to understand the whole.

2018
The original Act
Register of Critical Infrastructure Assets and information-gathering powers, focused on electricity, gas, water and ports.
2021–22
SLACI and SLACIP amendments
Expansion to 11 sectors, mandatory cyber incident reporting, government assistance powers for serious cyber incidents, the CIRMP obligation (Part 2A), and Systems of National Significance with enhanced cyber obligations.
2024
Enhanced Response and Prevention Act
Assented 29 November 2024. Data storage systems holding business critical data become part of the asset, government assistance extends from cyber incidents to all serious incidents, a new power to direct variation of a deficient CIRMP, telecommunications security regulation moves into the SOCI Act, and protected information rules are reformed.
2026
Enhanced CIRMP rules
Commenced 10 June 2026. A second, prescriptive tier of CIRMP requirements for nine higher-risk asset classes: Essential Eight maturity level two, phishing-resistant MFA, network segregation, AusCheck vetting of critical workers, supply chain mapping and FOCI assessment.

The practical consequence: any SOCI guidance that predates December 2024 is describing a materially different Act, and anything that predates June 2026 is missing the layer with the largest budget impact. Both waves are unpacked below.

02 / Who is in scope

Eleven sectors define the perimeter, and since 2024 the perimeter includes your data storage systems.

The Act applies to responsible entities and direct interest holders of critical infrastructure assets across 11 sectors. Whether a specific asset is captured depends on the asset class definitions in the Act and the Definitions Rules, which set thresholds such as generation capacity or customer numbers.

Communications
Data storage or processing
Defence industry
Energy
Financial services and markets
Food and grocery
Health care and medical
Higher education and research
Space technology
Transport
Water and sewerage

The data storage extension

The most underappreciated change of the 2024 amendments sits in new subsection 9(7). A data storage system is now taken to be part of the critical infrastructure asset where four conditions are met: the responsible entity owns or operates it, it is used in connection with the asset, it stores or processes business critical data, and a hazard with a material risk of impacting the system also carries a material risk of a relevant impact on the asset.

The Act's own note spells out what follows: registration obligations take the system into account, the CIRMP must cover it, and incident reporting extends to relevant impacts on it. The old comfort that SOCI stops at the operational estate and leaves corporate data platforms alone is gone. If your customer database, historian or billing platform meets the four conditions, it is inside the perimeter, and an incident affecting it can start the reporting clock.

Telecommunications entered by a different door. Schedule 5 of the 2024 Act moved security regulation for critical telecommunications assets into the SOCI Act and broadened the definition to assets owned or operated by carriers and carriage service providers and used in connection with supplying a carriage service. Carriers who previously dealt with security obligations under the Telecommunications Act now find them consolidated here, with SOCI's enforcement machinery behind them. The detail sits in the Telecommunications Security and Risk Management Program (TSRMP) Rules 2025, which carry their own annual report obligation; CISC's annual report form now covers Part 2A, Part 2AA and TSRMP reports in one place.

03 / Obligation one: the register

The register is the easy tier, and the one entities most often let go stale.

Responsible entities and direct interest holders must provide operational and ownership information to the Register of Critical Infrastructure Assets and keep it current as ownership, control and operational arrangements change. It is administratively light next to what follows, which is exactly why it drifts: acquisitions close, operating models change, offshore support arrangements are stood up, and the register still describes the entity as it looked at first registration.

A stale register is a poor first impression with a regulator you will meet again on harder questions. It is also now a bigger surface than it was, because the section 9(7) extension means the asset the register describes includes data storage systems that nobody thought about when the original entry was made.

04 / Obligation two: incident reporting

Two clocks, both starting from awareness, and a third one running under a different Act.

Part 2B requires responsible entities to report cyber security incidents to the Australian Signals Directorate through ReportCyber.

12 hrs
Critical incidents
Incidents having a significant impact on the availability of the asset. The clock starts when you become aware, not when the incident began.
72 hrs
Other reportable incidents
Incidents that have had, are having, or are likely to have a relevant impact on the asset. The threshold is lower than most operators assume.

The Cyber Security Act 2024 added a separate 72-hour clock for ransomware payments, with its own channel. An entity hit by ransomware can owe SOCI reporting, ransomware payment reporting and Privacy Act notification simultaneously, on different timelines, to different bodies. The organisations that meet a 12-hour clock have classification criteria front-line responders can apply without waiting for senior sign-off, pre-delegated authority to lodge an initial report, and an escalation chain that works at 2am. That is a capability built through exercising, not a paragraph in a policy.

05 / Obligation three: the CIRMP

A board-approved risk management program across four hazard domains, reported annually, and now variable on direction.

Part 2A requires responsible entities of specified asset classes to adopt and maintain a written Critical Infrastructure Risk Management Program under the CIRMP Rules. The program must identify hazards with a potential relevant impact on the asset and set out how material risks are minimised, eliminated or mitigated across four domains: cyber and information security, personnel, supply chain, and physical and natural hazards.

Two features give the CIRMP its weight. It must be approved by the board or governing body, and the entity must submit an annual report to the regulator within 90 days of the end of the financial year; the reporting window for 2025-26 closed on 28 September 2026. The report is an attestation carried by the directors who approve it, and since the 2024 amendments it must also disclose any government direction to vary the program and how the entity responded.

What the four domains require in practice, including the operational technology coverage that most first-generation CIRMPs missed, is covered in depth in our energy and critical infrastructure SOCI guide. The short version: a CIRMP describing controls for the corporate network while the control systems that actually run the asset go unmentioned is not a thin program, it is one that does not address the asset.

06 / The enhanced tier

Since June 2026, nine asset classes carry a second layer of prescriptive requirements, and the expensive obligations run to 2028.

The enhanced CIRMP rules commenced on 10 June 2026 and apply to critical broadcasting, domain name system, electricity, energy market operator, freight infrastructure, freight services, gas, liquid fuel and water assets. Affected entities must satisfy both the baseline and the enhanced requirements.

The headline items: the cyber framework condition rises to Essential Eight maturity level two (or equivalent under ISO 27001, NIST CSF 2.0, C2M2 or AESCSF at specified profiles), phishing-resistant multi-factor authentication with central logging, network segregation built so critical systems can run independently for at least three months during recovery, AusCheck background checks or security clearances for critical workers, supply chain mapping with defined maximum acceptable outages, and vendor assessment for foreign ownership, control or influence.

The deadlines are staged: a small set of obligations falls due on 10 June 2027, and everything capital-intensive on 10 June 2028. Our dedicated guide to the enhanced CIRMP rules works through each requirement at clause level, including why the widely reported deadline split is wrong and what the three-month segregation element means for an OT estate. If you operate one of the nine classes, read it next; the 2028 obligations are multi-year programmes that need to start now.

07 / Government powers

The government's hand has strengthened twice: all-hazards assistance powers, and the right to order your CIRMP rewritten.

The government assistance regime introduced in 2021 allowed intervention in serious cyber incidents, from information gathering through action directions to, as a last resort, ASD intervention. Schedule 2 of the 2024 Act extended that regime from serious cyber incidents to serious incidents. A physical attack, a natural hazard cascading into service failure, or a supply chain collapse can now trigger the same machinery.

The section 30AI variation direction

The sharper new instrument is quieter. Under new section 30AI, a relevant official, meaning the Secretary of Home Affairs or a senior officer of your Commonwealth regulator, can direct an entity to vary its CIRMP where the program has a serious deficiency: one posing a material risk to national security, the defence of Australia, or social or economic stability. The entity must be consulted first, gets a minimum of 14 days to comply, and faces a civil penalty of 250 penalty units for failing to. The direction and the entity's response must be disclosed in the next annual report, in front of the board that approved the program the regulator just found deficient.

This changes the quality bar in a way the original CIRMP obligation never did. Before section 30AI, a weak program risked a finding of non-compliance. Now it risks a regulator drafting your remediation scope for you, on their timeline. The entities least likely to meet a 14-day variation deadline are precisely the ones running the CIRMP as an annual documentation exercise, because they have no standing risk management cadence to absorb it.

Systems of National Significance

For assets declared SoNS, the Minister can switch on enhanced cyber security obligations: incident response planning, cyber security exercises, vulnerability assessments and provision of system information to ASD. Declarations are not public, and the 2024 amendments tightened the machinery around notifying relevant parties of declarations. If you operate anything plausibly in this category, the enhanced obligations are best treated as a matter of when.

The threat picture explains the trajectory. ASD's Annual Cyber Threat Report 2024-25 records ASD notifying critical infrastructure entities of potential malicious activity on their networks more than 190 times, up 111% on the prior year, with state-sponsored actors pre-positioning for disruptive effects in the event of crisis or conflict. Parliament has responded by giving the regulator reach that matches that assessment, and there is no sign of the direction reversing: Home Affairs opened public consultation on a further round of amendments to streamline and modernise the Act in July 2026.

08 / The timeline that matters

Between now and mid-2028, the deadlines are staged. The mistake is reading the far ones as distant.

Now: every obligation from the 2018 Act, the 2021-22 amendments and the 2024 Act is in force. The 2024 Act's schedules commenced on a staged basis through 2025 under its own commencement table, so data storage coverage, all-hazards assistance powers, section 30AI directions and the telecommunications provisions all apply today.

28 September each year: the CIRMP annual report window closes, 90 days after the end of the financial year. Each report is a board attestation, and each year's report is read against the last.

10 June 2027: for the nine enhanced asset classes, the first tranche of enhanced obligations falls due: additional material risks including FOCI and offshore access, patching and legacy technology risk processes, and personnel access management.

10 June 2028: the rest, including the framework uplift to Essential Eight maturity level two, phishing-resistant MFA, the three-month segregation standard, critical worker vetting at scale, and supply chain mapping. These are the capital programmes, which is why treating 2028 as far away is the most expensive misreading available. A maturity uplift across an OT estate and a segregation architecture rebuild are not eighteen-month projects.

What to do this quarter: confirm in writing which of your assets sit in which tier, test one critical system for genuine operational independence and document what breaks, review the register for staleness against the section 9(7) extension, and run one incident scenario with the 12-hour clock live. Those four exercises will tell you more about your real position than any gap assessment bought off a shelf.

09 / How Cliffside helps

We help operators build SOCI compliance that survives an incident, a regulator, and a board's questions.

Cliffside works with critical infrastructure operators on the governance, testing and evidence problems the SOCI Act creates. We do not sell template CIRMPs, because a template cannot tell you whether your critical systems can actually run independently for three months, and that is the question your budget turns on.

Our work typically covers security governance and CIRMP development, incident response testing against the SOCI reporting clocks, technical assurance across IT and OT boundaries, and supply chain risk assessment for the vendor obligations the enhanced rules introduced.

If your programme already covers most of this and what you need is a second opinion before the next annual report, we will tell you that too.

Talk to us or call our team on (02) 8916 6389.

Working Through SOCI Obligations?

We help responsible entities work out where they genuinely stand across the Act's tiers and build a programme that reaches the 2027 and 2028 deadlines without wasted spend. Start with an honest conversation.

Talk to us →