SOCI
What is SOCI?
Security of Critical Infrastructure Act 2018
Australian federal legislation, often searched for as the Security of Critical Infrastructure Act, that imposes positive security obligations on entities responsible for critical infrastructure assets across 11 sectors. It requires a responsible entity to adopt and maintain a risk management program covering all hazards, to report cyber security incidents, and to submit to government assistance measures. A separate tier of enhanced cyber security obligations applies only to assets declared as Systems of National Significance.
Who it applies to
The Act attaches obligations to the responsible entity for a critical infrastructure asset. That is the entity with operational responsibility for the asset, which is not always the owner and not always the parent company.
Eleven sectors are covered, including energy, communications, water, transport, health, financial services, food and grocery, data storage and processing, defence industry, higher education and research, and space technology. Not every asset in a covered sector is a critical infrastructure asset, so the first question is always whether the specific asset meets the definition.
What it requires
The baseline duty is the positive security obligation: adopt a risk management program, keep it current, comply with it, and report annually. The program must address all hazards rather than cyber alone.
Separately, the Act requires reporting of cyber security incidents, and it gives government assistance and information-gathering powers that can be used during a significant incident.
The tiers above the baseline
The Enhanced CIRMP Rules, which commenced in June 2026, raise the standard for nine named asset classes with deadlines in June 2027 and June 2028.
A further set of enhanced cyber security obligations applies only to assets declared as Systems of National Significance. That declaration is made privately by the Minister, so its absence is quiet rather than announced.
Read more
- Three Things Called "Enhanced" in Your SOCI Obligations
The regime now has three obligation layers and two of them are called enhanced. They apply to different populations, are triggered differently, and demand different things. Which ones you can look up today, and which one arrives privately.
- What Your TSRMP Needs to Contain for Telco Assets
Telecommunications assets have specific requirements under the SOCI Act TSRMP framework. What the risk management program needs to cover and where most entities leave gaps.
See also
- CIRMP Critical Infrastructure Risk Management Program The risk management program that responsible entities must establish and maintain under the SOCI Act.
- PSO Positive Security Obligation The requirement under Part 2A of the SOCI Act for responsible entities to adopt and maintain a critical infrastructure risk management program.
- SoNS Systems of National Significance A subset of critical infrastructure assets privately declared by the Minister under Part 6A of the SOCI Act, on the basis that a disruption would have cascading consequences for other critical infrastructure.
- Responsible Entity Under the SOCI Act, the entity that has operational responsibility for a critical infrastructure asset.
O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.