What is SOCI?
The Security of Critical Infrastructure (SOCI) Act is Australia's legislative framework for protecting critical infrastructure through governance, cyber security, supply chain resilience and risk management. This guide explains what the Act is, who it applies to, what has changed and how organisations can achieve SOCI compliance.
The Security of Critical Infrastructure (SOCI) Act is Australia's legislative framework for protecting critical infrastructure through governance, cyber security, supply chain resilience and risk management. This guide explains what the Act is, who it applies to, what has changed and how organisations can achieve SOCI compliance.
Sections
- Introduction
- SOCI at a Glance
- Key Compliance Areas
- What is SOCI?
- Why was the SOCI Act introduced?
- What does SOCI cover?
- Which organisations are affected?
- The SOCI timeline: Understanding the journey and what has changed
- How are SOCI and CIRMP connected?
- What does a CIRMP cover?
- Why should organisations care about SOCI?
- What do organisations need to do?
- Helpful Government Resources
- FAQ's
Introduction
The Security of Critical Infrastructure (SOCI) Act is Australia's framework for protecting the systems, services and organisations that keep the country running.
While cyber security remains a key component, SOCI compliance extends across governance, physical security, personnel security and supply chain security to help organisations build long-term operational resilience.
Understanding the SOCI Act is no longer just a concern for cyber security teams. Executive leaders, procurement professionals, risk managers, legal teams and suppliers all have a role to play in protecting Australia's critical infrastructure and ensuring essential services remain secure, resilient and available.
SOCI at a Glance

Key Compliance Areas

If your organisation operates - or supplies - a critical infrastructure provider, SOCI requires you to identify, manage and continuously improve risks across your business, not just your cyber security controls.
What is SOCI?
The Security of Critical Infrastructure (SOCI) Act 2018 is Australian legislation designed to protect the essential services and infrastructure that Australians rely on every day.
Originally introduced in 2018, the Act was created to improve the security of Australia's critical infrastructure by increasing transparency around ownership and ensuring the Government could better respond to national security risks. Since then, the legislation has evolved significantly to address the growing threat of cyber attacks, supply chain disruption, insider threats and physical security incidents.
Today, the SOCI Act is much more than a cyber security law. It is a comprehensive risk management framework that requires organisations to identify, manage and continuously improve risks that could impact the delivery of critical services.
The legislation is administered by the Department of Home Affairs, supported by the Critical Infrastructure Security Centre (CISC), with cyber security guidance provided by the Australian Cyber Security Centre (ACSC).
Why was the SOCI Act introduced?
Australia's critical infrastructure is fundamental to the country's economy, national security and everyday life. Services such as electricity, water, healthcare, banking, communications and transport are essential to keeping businesses operating and communities connected.
As these sectors have become increasingly digital and interconnected, they have also become more attractive targets for cyber criminals, nation-state actors and organised crime. A successful attack or major disruption can have widespread consequences, affecting not only individual organisations but also the supply chains, businesses and communities that depend on them.
The SOCI Act was introduced to help organisations build resilience before incidents occur, rather than simply responding after the damage has been done.
Its purpose is to strengthen critical infrastructure protection by encouraging organisations to take a proactive approach to managing security and operational risks.
What does SOCI cover?
One of the most common misconceptions is that SOCI only relates to cyber security.
In reality, SOCI compliance takes a whole-of-business approach to resilience. Organisations are expected to identify and manage risks across several key areas, including:
-
Governance – Establishing clear accountability, board oversight and effective risk management.
-
Cyber Security – Protecting systems, networks and sensitive information from cyber threats.
-
Physical Security – Securing facilities, operational technology and critical assets.
-
Personnel Security – Managing insider threats, access controls and security awareness.
-
Supply Chain Security – Understanding and managing risks introduced by suppliers, contractors and third-party service providers.
Together, these five areas form the foundation of a strong security and resilience programme, helping organisations maintain the availability and integrity of essential services.
Which organisations are affected?
The SOCI Act now applies across 11 critical infrastructure sectors, including:
-
Energy
-
Water and Sewerage
-
Healthcare and Medical
-
Communications
-
Financial Services and Markets
-
Transport
-
Data Storage and Processing
-
Food and Grocery
-
Defence Industry
-
Higher Education and Research
-
Space Technology
Importantly, the impact of SOCI extends beyond organisations that directly own or operate critical infrastructure assets.
Many suppliers, technology providers and service partners are now expected to demonstrate strong governance, cyber security and supplier assurance practices because they support organisations that fall within the scope of the legislation. As a result, SOCI is increasingly influencing procurement decisions, third-party risk management and contractual requirements across Australian supply chains.
The SOCI timeline: Understanding the journey and what has changed
The Security of Critical Infrastructure (SOCI) Act has evolved considerably since it was first introduced in 2018. While the original legislation focused on improving visibility of Australia's critical infrastructure assets, today's framework places much greater emphasis on resilience, governance and proactive risk management.
Understanding this journey helps explain why SOCI compliance now extends far beyond cyber security and why organisations are increasingly expected to strengthen their governance, procurement and supply chain assurance practices.

SOCI Timeline
2018 – SOCI Act introduced
The Security of Critical Infrastructure Act 2018 established the legislative framework for protecting Australia's most important infrastructure.
Its primary objectives were to:
-
Improve transparency of ownership.
-
Create a Register of Critical Infrastructure Assets.
-
Strengthen the Australian Government's ability to respond to national security risks.
At this stage, the legislation focused largely on identifying critical assets rather than prescribing how organisations should manage risk.
2021–2022 – Major SOCI reforms
Following a series of significant cyber security incidents affecting critical infrastructure globally, the Australian Government introduced substantial reforms through the Security Legislation Amendment (Critical Infrastructure) Act 2021 and the Security Legislation Amendment (Critical Infrastructure Protection) Act 2022.
These reforms transformed SOCI from an asset registration framework into a comprehensive resilience programme.
Key changes included:
-
Expansion from a small number of sectors to 11 critical infrastructure sectors.
-
Introduction of Positive Security Obligations (PSOs).
-
Mandatory Critical Infrastructure Risk Management Programs (CIRMPs) for many responsible entities.
-
Mandatory cyber incident reporting.
-
Enhanced obligations for Systems of National Significance (SoNS).
The emphasis shifted from "What assets do you own?" to "How are you managing the risks that could disrupt essential services?"
2024–2025 – CIRMP Rules implemented
Following the legislative reforms, organisations began implementing their Critical Infrastructure Risk Management Programs (CIRMPs).
This represented one of the most significant practical changes introduced by the SOCI Act.
Rather than focusing solely on cyber security, organisations were required to establish documented processes for identifying and managing material risks across multiple areas of the business.
2026 – Enhanced CIRMP Rules
The Australian Government has consulted on Enhanced CIRMP Rules, reflecting the continued evolution of Australia's critical infrastructure resilience framework.
The proposed enhancements seek to provide greater clarity around governance, assurance and reporting expectations while encouraging organisations to adopt a more mature and consistent approach to risk management.
Although the core principles remain unchanged, organisations should expect increased emphasis on demonstrating how risks are identified, managed and reviewed over time.
January 2026
Dr Jill Slay AM delivered the Independent Review into the Security of Critical Infrastructure Act 2018 (SOCI Act) on 31 January 2026.
The review’s recommendations are principally directed at reducing complexity and improving the agility, clarity and responsiveness of the SOCI Act, including through targeted legislative reform.
In response, the Department of Home Affairs is progressing a second tranche of reforms.
July 2026
Consultation period ends on 31 July for industry to have it's say on second tranche of reforms.
Since its introduction in 2018, the Security of Critical Infrastructure (SOCI) Act has undergone significant reform to address Australia's rapidly evolving threat landscape.
The original legislation focused primarily on identifying and registering critical infrastructure assets. However, as cyber attacks, ransomware incidents and supply chain disruptions became more frequent and sophisticated, the Australian Government expanded the legislation to strengthen the resilience of organisations operating critical infrastructure.
The most significant reforms were introduced through amendments in 2021 and 2022, shifting the focus from asset ownership to proactive risk management and organisational resilience.
Positive Security Obligations (PSOs)
One of the biggest changes was the introduction of Positive Security Obligations (PSOs).
Rather than simply responding to incidents, organisations are now expected to actively identify, assess and manage risks that could impact critical infrastructure.
This includes implementing governance processes, maintaining appropriate security controls and regularly reviewing how risks are managed across the organisation.
Mandatory Cyber Incident Reporting
The reforms also introduced mandatory reporting requirements for eligible cyber security incidents.
Responsible entities must notify the Australian Cyber Security Centre (ACSC) within legislated timeframes when cyber incidents have a relevant or significant impact on critical infrastructure assets.
This enables government agencies to coordinate responses more effectively and improve Australia's overall cyber resilience.
Enhanced Cyber Security Obligations
Some assets have been designated as Systems of National Significance (SoNS) due to their importance to Australia's economy and national security.
Operators of these systems may be subject to additional obligations, including enhanced cyber security measures, increased reporting requirements and greater collaboration with government agencies.
Why these reforms matter
The reforms recognise that today's threats extend well beyond technology.
Cyber-attacks often exploit weaknesses in supplier networks, operational processes or physical security before targeting IT systems. As a result, organisations are expected to take a whole-of-business approach to resilience.
For many organisations, this means closer collaboration between cyber security, procurement, risk management, legal, operations and executive leadership to ensure compliance with the SOCI Act while strengthening long-term organisational resilience.
How are SOCI and CIRMP connected?
One of the most common questions organisations ask is:
"Is CIRMP different from SOCI?"
The answer is no.
Think of it like this:
|
SOCI Act |
CIRMP |
|
The legislation |
The practical framework that helps organisations meet part of the legislation |
|
Defines legal obligations |
Explains how organisations manage risks |
|
Sets the requirements |
Demonstrates compliance |
In simple terms:
The SOCI Act tells organisations what they need to achieve. A Critical Infrastructure Risk Management Program (CIRMP) helps demonstrate how they achieve it.
For many organisations, the CIRMP becomes the operational blueprint for meeting their SOCI compliance obligations.
What does a CIRMP cover?
A Critical Infrastructure Risk Management Program requires organisations to identify, assess and manage material risks that could affect the operation of critical infrastructure.
This typically includes five interconnected areas:
-
Governance – Leadership, accountability and oversight.
-
Cyber Security – Protecting systems, data and operational technology.
-
Physical Security – Safeguarding facilities and critical assets.
-
Personnel Security – Managing insider threats and workforce security.
-
Supply Chain Security – Understanding and managing third-party risks.
These are the same five pillars illustrated in the overview and represent a whole-of-business approach to resilience rather than a technology-only programme.
What's the biggest difference between the old and new rules?
The simplest way to understand the evolution of the SOCI Act is this:
|
Original SOCI Act (2018) |
Proposed SOCI Framework |
|
Focused on identifying critical infrastructure assets |
Focuses on protecting and strengthening critical infrastructure |
|
Primarily concerned with ownership and visibility |
Requires ongoing governance and risk management |
|
Limited regulatory obligations |
Broader compliance obligations across multiple business functions |
|
Cyber security was an important consideration |
Cyber security, physical security, personnel security and supply chain security are all considered essential |
|
Compliance centred around asset information |
Compliance requires continuous improvement and organisational resilience |
Today, SOCI compliance is no longer the responsibility of cyber security teams alone.
Executive leadership, procurement, supplier assurance, operations, legal, HR and risk management all play an important role in helping organisations protect Australia's critical infrastructure.
Learn more
For organisations looking to understand the legislation in greater detail, the following government resources provide practical guidance:
Why should organisations care about SOCI?
For many organisations, SOCI represents more than a legal obligation - it is an opportunity to strengthen resilience, improve governance and build greater trust with customers, regulators and supply chain partners.
Organisations that embrace the principles of SOCI are often better positioned to:
-
Improve enterprise risk management.
-
Strengthen cyber resilience.
-
Reduce supply chain risk.
-
Enhance procurement and supplier assurance processes.
-
Improve business continuity and incident response.
-
Demonstrate good governance to regulators and stakeholders.
Even organisations that are not directly regulated under the SOCI Act may find that customers, particularly those operating critical infrastructure, increasingly expect evidence of robust security and risk management practices during procurement and supplier assurance activities.
What do organisations need to do?
Complying with the Security of Critical Infrastructure (SOCI) Act is not about completing a single project or ticking a compliance box. It requires organisations to build an ongoing programme of governance, risk management and continuous improvement.
While specific obligations vary depending on the organisation and the assets it operates, most SOCI compliance programmes follow six practical steps.
1. Understand whether SOCI applies
The first step is determining whether your organisation owns, operates or supports assets covered by the SOCI Act.
Even organisations that are not directly regulated may be expected to demonstrate strong security and resilience if they supply critical infrastructure operators.
2. Identify material risks
Organisations should assess risks that could impact the availability, integrity or reliability of critical infrastructure.
This includes reviewing:
-
Cyber security risks
-
Physical security risks
-
Personnel risks
-
Supply chain risks
-
Natural hazards
-
Operational resilience
Understanding these risks forms the foundation of an effective Critical Infrastructure Risk Management Program (CIRMP).
3. Strengthen governance
Strong governance is central to SOCI compliance.
Organisations should ensure:
-
Executive accountability is clearly defined.
-
Boards receive regular risk updates.
-
Policies and procedures remain current.
-
Risk management processes are regularly reviewed.
-
Compliance activities are documented and evidenced.
Good governance demonstrates that security is embedded throughout the organisation rather than managed solely by technical teams.
4. Improve supplier assurance
One of the biggest changes introduced through the SOCI reforms is the increased focus on supply chain security.
Organisations should understand:
-
Who their critical suppliers are.
-
Which suppliers present the greatest risk.
-
How supplier risks are assessed.
-
Whether suppliers meet recognised security standards.
-
How supplier performance is monitored over time.
Organisations need to be asking
-
Do we understand supplier ownership and dependencies?
-
How resilient are suppliers to disruption? Do we have alternatives?
-
Can we evidence supplier cyber resilience?
-
Who has access to critical systems?
For procurement teams, SOCI reinforces the importance of robust supplier due diligence and ongoing third-party risk management.
5. Prepare for incident reporting
Eligible cyber incidents must be reported within legislated timeframes.
Organisations should establish clear incident response procedures, define reporting responsibilities and ensure escalation processes are understood across the business.
6. Continuously improve
SOCI compliance is an ongoing journey.
Threats, technologies and regulatory expectations continue to evolve, making regular reviews essential.
Leading organisations routinely:
-
Review their CIRMP.
-
Assess supplier performance.
-
Conduct risk assessments.
-
Test business continuity plans.
-
Improve cyber resilience.
-
Update governance processes.
Continuous improvement not only supports compliance but also strengthens organisational resilience and builds confidence among customers, regulators and stakeholders.
Helpful Government Resources
The Australian Government provides a range of guidance, tools and legislative resources to help organisations understand their obligations under the Security of Critical Infrastructure (SOCI) Act.
Website:
https://www.cisc.gov.au
Whether you're beginning your SOCI compliance journey or reviewing an existing programme, the following resources are valuable starting points.
Critical Infrastructure Security Centre (CISC)
Website:
https://www.cisc.gov.au/
The Critical Infrastructure Security Centre is the primary source of guidance for organisations affected by the SOCI Act.
It provides information on:
-
Security of Critical Infrastructure legislation
-
Critical Infrastructure Risk Management Programs (CIRMP)
-
Positive Security Obligations
-
Systems of National Significance (SoNS)
-
Incident reporting requirements
-
Industry guidance and consultations
Australian Cyber Security Centre (ACSC)
Website:
https://www.cyber.gov.au
The ACSC provides practical cyber security advice, threat intelligence and guidance to help organisations improve resilience.
Useful resources include:
-
Essential Eight
-
Cyber security advisories
-
Incident response guidance
-
Threat reports
-
Cyber security planning resources
Department of Home Affairs
Website:
https://www.homeaffairs.gov.au
The Department of Home Affairs oversees Australia's critical infrastructure policy and publishes information relating to SOCI reforms, consultations and national security initiatives.
Federal Register of Legislation
Website:
https://www.legislation.gov.au
For organisations requiring the official legislation, the Federal Register of Legislation provides the current version of the Security of Critical Infrastructure Act 2018, associated rules and amendment history.
Additional frameworks that support SOCI compliance
While not mandatory under the legislation, many organisations use recognised standards and frameworks to strengthen their security and governance programmes.
These include:
-
ACSC Essential Eight
-
ISO/IEC 27001 Information Security Management
-
ISO 31000 Risk Management
-
ISO 22301 Business Continuity Management
-
NIST Cybersecurity Framework
-
Protective Security Policy Framework (PSPF)
These frameworks can complement SOCI compliance by helping organisations establish mature governance, cyber security and operational resilience capabilities.
Quick Tip
If your organisation is unsure whether the SOCI Act applies, or you're reviewing supplier assurance processes, begin with the guidance available from the Critical Infrastructure Security Centre. It provides practical information for both regulated entities and organisations supporting Australia's critical infrastructure supply chains, making it an excellent starting point for understanding your obligations and identifying areas for improvement.
FAQs
What is the SOCI Act?
The Security of Critical Infrastructure (SOCI) Act is Australian legislation that strengthens the security and resilience of organisations operating critical infrastructure. It introduces obligations covering cyber security, supply chain risk, governance, physical security and incident reporting.
Who needs to comply with SOCI?
Organisations that own or operate regulated critical infrastructure assets must comply with the SOCI Act. Businesses that supply products or services to these organisations may also be required to demonstrate strong security and resilience practices to satisfy customer requirements.
Does SOCI only apply to cyber security?
No. SOCI is a whole-of-business resilience framework. It covers cyber security, physical security, personnel security, governance, supply chain risk and operational resilience.
What is a Critical Infrastructure Risk Management Program (CIRMP)?
A CIRMP is a documented program that identifies and manages material risks affecting critical infrastructure assets. Depending on the asset class, organisations may be required to maintain a CIRMP and submit annual reports demonstrating its effectiveness.
What industries are covered by SOCI?
The SOCI Act currently applies across eleven sectors, including energy, communications, healthcare, financial services, transport, water, food and grocery, defence, higher education and research, data storage and processing, and space technology.
How does SOCI affect suppliers?
Many regulated organisations now assess suppliers for cyber security, governance and operational resilience. Suppliers may be asked to complete security questionnaires, provide evidence of certifications such as ISO 27001 or Essential Eight maturity, or undergo regular assurance assessments as part of procurement and ongoing supplier management.
What happens if an organisation doesn't comply with SOCI?
Failure to comply with applicable obligations may result in regulatory enforcement, including penalties for failing to establish required risk management programs, report cyber incidents or meet other obligations under the Act.
How is SOCI different from ISO 27001?
ISO 27001 is an international information security management standard. SOCI is Australian legislation focused on protecting critical infrastructure through broader governance, resilience and risk management obligations. Many organisations use ISO 27001 to support their SOCI compliance programme.
What role does procurement play in SOCI compliance?
Procurement teams help organisations understand supplier risk, assess critical vendors, monitor third-party security and ensure contracts include appropriate security requirements. Because supply chain hazards are explicitly recognised under the CIRMP requirements, procurement has become an important contributor to SOCI compliance.
How can organisations prepare for SOCI compliance?
Organisations should:
- Determine whether the Act applies to their assets.
- Identify material cyber, physical, personnel and supply chain risks.
- Develop or review their CIRMP.
- Assess supplier security and resilience.
- Implement governance and board oversight.
- Review incident reporting processes.
- Continuously monitor and improve security controls.
These activities support both compliance and long-term operational resilience.
Ready to take action?
Related Resources
Want to keep learning?
Explore more resources below, check out our FAQs, or bookmark this page. We update it regularly to stay ahead of new trends in supplier risk.
