Skip to main content

SOCI

What is SOCI?

Security of Critical Infrastructure Act 2018

Australian federal legislation, often searched for as the Security of Critical Infrastructure Act, that imposes positive security obligations on entities responsible for critical infrastructure assets across 11 sectors. It requires a responsible entity to adopt and maintain a risk management program covering all hazards, to report cyber security incidents, and to submit to government assistance measures. A separate tier of enhanced cyber security obligations applies only to assets declared as Systems of National Significance.

Who it applies to

The Act attaches obligations to the responsible entity for a critical infrastructure asset. That is the entity with operational responsibility for the asset, which is not always the owner and not always the parent company.

Eleven sectors are covered, including energy, communications, water, transport, health, financial services, food and grocery, data storage and processing, defence industry, higher education and research, and space technology. Not every asset in a covered sector is a critical infrastructure asset, so the first question is always whether the specific asset meets the definition.

What it requires

The baseline duty is the positive security obligation: adopt a risk management program, keep it current, comply with it, and report annually. The program must address all hazards rather than cyber alone.

Separately, the Act requires reporting of cyber security incidents, and it gives government assistance and information-gathering powers that can be used during a significant incident.

The tiers above the baseline

The Enhanced CIRMP Rules, which commenced in June 2026, raise the standard for nine named asset classes with deadlines in June 2027 and June 2028.

A further set of enhanced cyber security obligations applies only to assets declared as Systems of National Significance. That declaration is made privately by the Minister, so its absence is quiet rather than announced.

Read more

See also

Search all glossary terms

O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.