Skip to main content
Regulation 5 min read

Three Things Called "Enhanced" in Your SOCI Obligations

The regime now has three obligation layers and two of them are called enhanced. They apply to different populations, are triggered differently, and demand different things. Which ones you can look up today, and which one arrives privately.

Darragh Downey

Principal Consultant, O/IT Cyber


The critical infrastructure regime now contains three separate obligation layers, and two of them are called “enhanced”. They apply to different populations, they are triggered in different ways, and they demand different things.

I have sat in meetings where two people agreed they were subject to “the enhanced obligations” and turned out to mean entirely different regimes. So it is worth being precise.

Layer one: the positive security obligation

The baseline. If you are the responsible entity for a critical infrastructure asset in a covered sector, you carry it.

The core duty is to adopt, maintain and comply with a critical infrastructure risk management program, review it regularly, and report on it annually. The program has to address all hazards — cyber, personnel, physical, natural and supply chain — not cyber alone.

It is a standing obligation. Nobody has to tell you it applies. You do not get a letter.

Layer two: the enhanced CIRMP requirements

This is new, and it is the one most likely to catch people out.

The Enhanced CIRMP Rules commenced in June 2026. They create a two-tier structure inside the risk management program itself: baseline requirements, and a set of enhanced requirements that sit on top for nine named asset classes — critical broadcasting, domain name systems, electricity, energy market operator, freight infrastructure, freight services, gas, liquid fuel and water assets.

If you operate one of those, you meet both tiers, and the enhanced requirement prevails where the two are inconsistent.

What it demands is materially more:

  • The cyber maturity target moves up a level. For energy entities nominating the AESCSF, that means Security Profile 2.
  • Phishing-resistant multi-factor authentication, and logging.
  • Network protection and segregation for critical systems.
  • Explicit treatment of unsupported and legacy systems.
  • Higher standards for personnel vetting, supply chain management and physical security.

The deadlines are staged: June 2027 for the first tranche, including material risks and access management, and June 2028 for the rest, including the cyber framework compliance.

This layer is triggered by what class of asset you operate. It is public, it is knowable, and you can look it up today.

Layer three: the enhanced cyber security obligations

Different regime, similar name.

These attach only to assets declared as Systems of National Significance. That declaration is made privately by the Minister, on the basis that disruption to the asset would cascade into other critical infrastructure.

The obligations here are operational rather than programmatic: maintaining and exercising a cyber security incident response plan, undertaking vulnerability assessments, providing system information to government. They are also applied selectively — a declaration does not switch on every obligation at once.

This layer is triggered by a ministerial decision, delivered privately. Being large, important or well known does not make an asset a System of National Significance. Being told does.

The distinction that actually matters

Triggered byKnowable in advanceDemands
Positive security obligationOperating a critical infrastructure assetYesA risk management program across all hazards
Enhanced CIRMP requirementsOperating one of nine named asset classesYesHigher cyber, personnel, supply chain and physical standards
Enhanced cyber security obligationsA private ministerial declarationNoDemonstrated operational response capability

The practical consequence is about sequencing. Layers one and two you can plan for, because you can determine today whether they apply. Layer three you cannot, so the sensible posture is to build layers one and two properly and keep your asset and dependency picture accurate enough that a declaration would not mean starting over.

Three mistakes

Assuming a declaration you do not have. Some entities build response programmes on the assumption that they must be a System of National Significance. Declarations are private, so the absence of one is quiet rather than announced. If nobody has told you, you are not in layer three.

Hearing “enhanced” and checking the wrong regime. The most common version: an energy operator reads about the enhanced cyber security obligations, concludes they do not apply because there is no declaration, and misses that the enhanced CIRMP requirements apply to their asset class regardless. Those have a 2028 deadline attached.

Treating the layers as a maturity ladder. They are not three levels of the same thing. Layer one is all-hazards risk management. Layer two raises the standard of that program for higher-consequence asset classes. Layer three is cyber operational readiness for nationally significant systems. Doing layer one extremely well does not produce layer three as a by-product.

Where they share foundations

Building with all three in mind is not wasted effort. An accurate asset inventory serves every layer. So does a clear map of interdependencies — the same analysis that satisfies the risk management program is what makes a nationally significant asset’s cascading impact assessable in the first place. So does knowing precisely which systems are in scope and who operates them.

Get the boundary right and the rest is tractable. Get it wrong and every layer is built on sand.


Not sure which layers apply to your assets, or what each one requires you to demonstrate? Get in touch.

Share LinkedIn Email