SOCI Act reforms 2026: What the proposed changes could mean for critical infrastructure
Australia's Security of Critical Infrastructure (SOCI) Act could be heading for its biggest overhaul since the framework was introduced.
Australia's Security of Critical Infrastructure (SOCI) Act could be heading for its biggest overhaul since the framework was introduced.
Sections
- Introduction
- The 21 Proposed SOCI Act Reforms
- SOCI reforms 2026: At a glance
- Why is the SOCI Act changing again?
- What are the major SOCI reforms proposed for 2026?
- What could change for CIRMP?
- Why is supply chain security becoming more important?
- Could SOCI change how suppliers are assessed?
- What could the reforms mean for procurement?
- How does AI feature in the proposed SOCI reforms?
- Why do the 2026 SOCI reforms matter?
- What should organisations do now?
- What happens next?
- Helpful resources
- FAQ's
Introduction
Following an Independent Review of the SOCI Act, the Department of Home Affairs launched a second tranche of reforms aimed at making the legislation simpler, clearer and better suited to today's critical infrastructure landscape.
The 21 Proposed SOCI Act Reforms
The consultation proposes 21 measures spanning everything from artificial intelligence and Systems of National Significance to governance, managed service providers and supply chain cyber security assurance.

But what does that actually mean for organisations?
In this guide, we break down the proposed 2026 SOCI Act reforms - why they’re happening, what could change, and what organisations responsible for or supplying Australia’s critical infrastructure need to consider next.
Important: These reforms are proposed and are not yet law. However, now is the time to understand what could change, identify potential gaps and strengthen existing processes. Preparing early can help organisations stay ahead rather than react when new requirements take effect.
SOCI reforms 2026: At a glance
What is changing?
The Australian Government is considering 21 measures to streamline and modernise the SOCI Act.
Why now?
An Independent Review conducted in 2026 found that SOCI has strengthened Australia's critical infrastructure framework, but parts of it have become complex, duplicative and difficult to apply.
Who could be affected?
Organisations across critical infrastructure sectors including energy, transport, water, communications, healthcare, financial services and defence, as well as the suppliers, managed service providers and technology partners they depend on.
Is it law yet?
No. The July reforms are currently proposals following consultation.
What areas are being considered?
Asset coverage, reporting, AI-related cyber incidents, governance, assurance, penalties, managed service providers, corporate groups and supply chain cyber security.
What should organisations do now?
Understand which proposals could affect their organisation, review existing SOCI and CIRMP arrangements and consider where stronger evidence of risk management and supplier assurance may be needed.
Why is the SOCI Act changing again?
The Security of Critical Infrastructure Act 2018 has significantly changed how Australia protects the infrastructure and essential services the country depends on.
However, regulation also needs to evolve.
The Independent Review of the SOCI Act found that the framework had improved asset visibility, incident reporting and board-level awareness of critical infrastructure risk. But it also identified a recurring problem: complexity.
Organisations can face overlapping requirements across SOCI and other Commonwealth, state, territory and sector-specific regulations. Some definitions no longer reflect how modern infrastructure is owned, operated or delivered, while existing assurance processes do not always demonstrate whether risk management controls are actually working.
The review therefore recommended moving towards a simpler and more outcome-focused approach.
In practical terms, the Government is trying to answer a bigger question:
Can SOCI become easier to comply with while becoming more effective at protecting Australia's critical infrastructure?
The proposed reforms are designed around three broad objectives:
-
Reduce complexity, duplication and uncertainty.
-
Modernise which sectors and assets are covered.
-
Strengthen governance, assurance and accountability.
What are the major SOCI reforms proposed for 2026?
There are 21 individual measures in the consultation paper.
For most organisations, however, it's easier to understand them as three major areas of change.
1. Making SOCI simpler to navigate
One of the strongest themes emerging from the Independent Review was that the SOCI framework has become difficult to navigate.
The Government is therefore considering changes designed to reduce unnecessary administration and make obligations clearer.
Proposals include:
-
A clearer exemptions framework.
-
Simplifying the Register of Critical Infrastructure Assets.
-
Simplifying annual CIRMP reporting.
-
Clarifying notification requirements.
-
Simplifying the framework for Systems of National Significance (SoNS).
-
Better recognition of equivalent regulatory requirements.
The intention isn't simply to remove obligations. It is to make it clearer what organisations need to do, when they need to do it and how they can demonstrate compliance.
For organisations operating across multiple regulatory frameworks, this could be particularly important.
2. Modernising what counts as critical infrastructure
Critical infrastructure looks very different today than it did when the original SOCI Act was introduced in 2018.
Cloud services, distributed energy, digital platforms, interconnected supply chains and increasingly sophisticated technology dependencies have changed how essential services operate.
The consultation therefore considers changes to the way SOCI captures areas including:
-
Submarine telecommunications cables.
-
Data storage and processing.
-
Space technology.
-
Healthcare and medical infrastructure.
-
Distributed energy resources.
-
Offshore electricity assets.
-
Critical freight.
-
Higher education and research.
The objective is to ensure critical infrastructure protection reflects how essential services actually operate today rather than relying on definitions created for an earlier technology and operating environment.
3. Increasing governance, assurance and accountability
Perhaps the most important shift is from simply demonstrating that a risk management process exists to demonstrating that it works.
The proposed reforms consider stronger requirements around:
-
CIRMP governance and assurance.
-
Civil penalties.
-
Operations and maintenance providers.
-
Managed service providers.
-
Cooperation between companies within corporate groups.
-
Supply chain cyber security assurance.
-
Specified risk information.
-
Critical workers and components.
For boards and executive teams, this potentially means greater emphasis on evidence and outcomes rather than documentation alone.
What could change for CIRMP?
The Critical Infrastructure Risk Management Program (CIRMP) remains central to SOCI compliance.
The proposed reforms indicate that the Government wants greater confidence that CIRMP arrangements are not simply documented but are operating effectively in practice.
Importantly, this consultation should not be confused with the Enhanced CIRMP Rules 2026, which have already come into effect for specified asset classes.
The wider SOCI consultation looks further ahead at how governance and assurance could be strengthened across the broader legislative framework.
The direction is increasingly clear:
SOCI compliance is moving from proving you have a process to demonstrating that the process is effectively managing risk.
Why is supply chain security becoming more important?
One of the most significant proposals - particularly for procurement, supplier assurance and third-party risk teams - is Measure 19: Supply Chain Cyber Security Assurance.
Critical infrastructure organisations increasingly depend on third parties to operate essential services.
These can include:
-
Managed service providers.
-
Software vendors.
-
Cloud and hosting providers.
-
Operational technology providers.
-
Specialist equipment manufacturers.
-
Contractors and service partners.
A cyber security weakness within one of these organisations can therefore become a risk to the critical infrastructure asset itself.
Existing CIRMP requirements already require responsible entities to manage supply chain hazards. However, the consultation identifies a gap around how organisations assess cyber risks from major suppliers.
The Government is considering clearer expectations for assessing suppliers whose products, services or access are material to the security, availability, integrity, reliability or operation of critical infrastructure.
Could SOCI change how suppliers are assessed?
Potentially, yes.
The consultation recognises a problem that will be familiar to many procurement and supplier assurance teams: duplication.
Suppliers can be asked to complete multiple security assessments containing similar questions in different formats.
For large suppliers this creates administration. For smaller suppliers it can become a significant burden.
The proposed approach considers whether recognised cyber security certifications or accreditations could provide a more efficient way for organisations to evidence supplier cyber due diligence, where those certifications are appropriate and relevant.
It also recognises that not every supplier can simply be replaced.
Critical infrastructure organisations may depend on specialist operational technology, proprietary equipment, international platforms or suppliers operating in concentrated markets.
The proposed framework therefore considers how organisations could document exceptions, introduce alternative controls and demonstrate that any remaining risk is understood and appropriately managed.
This is an important development because it moves supplier assurance towards a more risk-based and proportionate approach rather than treating every supplier in exactly the same way.
What could the reforms mean for procurement?
SOCI is increasingly relevant to procurement teams because third-party relationships can directly influence the security and resilience of critical infrastructure.
If the proposed reforms progress, procurement and supplier management teams may need greater visibility of:
-
Which suppliers are considered critical or material.
-
What access suppliers have to systems and assets.
-
What cyber security controls suppliers maintain.
-
Where suppliers and services are located.
-
Foreign ownership, control or influence.
-
Dependencies on individual suppliers.
-
How quickly suppliers report security incidents.
-
Whether recognised certifications can provide assurance.
-
What happens when a supplier cannot meet standard requirements.
This reinforces an important point from the wider SOCI framework:
Critical infrastructure security is not solely a cyber security responsibility.
Procurement, risk, legal, operations, cyber security and executive leadership increasingly need to work together to understand and manage third-party risk.
What about managed service providers?
Managed service providers (MSPs) are another area receiving greater attention.
Many critical infrastructure organisations outsource important operational, technology and security functions to third parties.
The consultation recognises that these providers can have significant access to, or influence over, critical infrastructure operations.
This means organisations may need to think beyond whether a supplier simply meets contractual requirements and consider the dependency and operational risk created by the relationship itself.
For organisations with highly outsourced operating models, understanding these dependencies could become increasingly important to SOCI compliance.
How does AI feature in the proposed SOCI reforms?
Artificial intelligence also appears within the proposed reforms.
The Government is considering changes to the definition of a cyber security incident so that it works more clearly when automated systems, software agents or AI-enabled tools are involved in causing or facilitating an incident.
This doesn't create a separate "AI compliance" regime under SOCI.
Instead, it reflects the reality that cyber incidents are changing and existing definitions need to remain effective as automated and AI-enabled technologies become more widely used.
For organisations, the broader message is straightforward: SOCI needs to remain relevant as technology and threats evolve.
Why do the 2026 SOCI reforms matter?
It would be easy to view the consultation as another regulatory update.
The bigger picture is more important.
The original SOCI framework helped Australia identify critical assets and establish baseline security obligations. The next phase appears increasingly focused on whether those controls deliver meaningful security and resilience outcomes.
That means organisations may increasingly be expected to demonstrate not only that the right policies, controls and risk management processes are in place, but that they are effective in practice. .png?width=3800&height=2200&name=The%2021%20Proposed%20SOCI%20Act%20Reform%20Measures%20(1).png)
What should organisations do now?
The July consultation has closed and the proposals are not yet law, so organisations should avoid treating every proposed measure as a new compliance requirement.
However, waiting until legislation changes may not be the best approach either.
Organisations can start by asking five simple questions:
1. Do we understand our current SOCI obligations?
Confirm which assets and entities fall within the existing framework and whether current SOCI and CIRMP requirements are being met.
2. Can we demonstrate that our CIRMP works?
Look beyond documentation and consider whether controls, governance and risk management processes can be evidenced in practice.
3. Do we know which suppliers are genuinely critical?
Identify the suppliers, service providers and technologies that could materially affect critical infrastructure operations.
4. How do we assure those suppliers?
Review whether supplier assessments are proportionate to risk and whether certifications, evidence and ongoing monitoring provide meaningful assurance.
5. Are procurement, cyber and risk teams working together?
Supplier security increasingly crosses traditional organisational boundaries. Clear ownership and information sharing can help avoid gaps between procurement, cyber security, risk and operational teams.
What happens next?
The Department of Home Affairs will use stakeholder feedback to inform decisions on the final legislative package, subordinate instruments, implementation sequencing and supporting guidance. The consultation is now closed, following the Government's consideration of the recommendations from the Independent Review of the SOCI Act.
Importantly, some of the detailed thresholds and technical boundaries are expected to be developed through subsequent consultation and subordinate legislation. This includes areas such as data centres, distributed energy resources, space technology, critical research and critical workers.
That means the direction of travel is becoming clearer, but some of the practical details are still to come.
Organisations operating in - or supplying - Australia's critical infrastructure should therefore continue monitoring developments rather than assuming the July proposals represent the final requirements.
View the Department of Home Affairs SOCI Act consultation
Helpful resources
For authoritative information on the proposed reforms, organisations should refer to the Department of Home Affairs consultation on proposed amendments to streamline and modernise the Security of Critical Infrastructure Act 2018. The consultation materials explain the proposed measures, the findings of the Independent Review and the Government's objectives for the next phase of SOCI reform.
Department of Home Affairs – SOCI Act consultation
Department of Home Affairs – SOCI consultation paper (PDF)
The Critical Infrastructure Security Centre (CISC) also provides practical guidance on existing SOCI regulatory obligations, including the Register of Critical Infrastructure Assets, cyber incident reporting and Critical Infrastructure Risk Management Programs (CIRMPs).
For a legal perspective,Allens' “SOCI Act 2.0: Sweeping reforms proposed to Australia's critical infrastructure framework” provides a detailed analysis of the potential implications for regulated entities, including changes affecting CIRMP, suppliers, managed service providers and the scope of regulated assets.
FAQs
Are the 2026 SOCI reforms already law?
No. The measures outlined in the July 2026 consultation are proposals. The consultation closed on 31 July 2026 and stakeholder feedback will inform the Government's final policy and legislative decisions.
How many SOCI reforms are being proposed?
The consultation paper contains 21 proposed measures, grouped broadly around reducing complexity, modernising sector and asset coverage, and strengthening governance, assurance and accountability.
Why is the SOCI Act being reformed?
An Independent Review found that SOCI has strengthened Australia's critical infrastructure framework but also identified complexity, duplication and difficulties applying some requirements in practice.
Will the SOCI reforms affect CIRMP?
Potentially. The proposals include measures relating to CIRMP governance, assurance, annual reporting and dependencies on suppliers and other organisations.
Are the Enhanced CIRMP Rules 2026 part of this consultation?
No. The Enhanced CIRMP Rules 2026 are a separate reform process and are already in effect for specified critical infrastructure asset classes.
Will SOCI affect supply chain and procurement teams?
Increasingly, yes. The proposed reforms specifically address supply chain cyber security assurance and the risks created by major suppliers and service providers.
What is Supply Chain Cyber Security Assurance under SOCI?
The proposed measure would clarify how responsible entities assess and manage cyber risks arising from major suppliers whose products, services, access or role are material to critical infrastructure.
Could supplier certifications support SOCI compliance?
The consultation considers whether recognised certification or accreditation could provide a more efficient way to evidence supplier cyber due diligence where the certification is current, relevant and appropriately scoped.
How could AI affect SOCI compliance?
The proposed reforms would clarify how the definition of a cyber security incident applies where automated systems, software agents or AI-enabled tools are involved.
What should organisations do about the proposed SOCI reforms now?
Organisations should continue complying with existing requirements while assessing how the proposals could affect their governance, CIRMP, supplier assurance and critical infrastructure risk management arrangements.
Ready to take action?
Related Resources
Want to keep learning?
Explore more resources below, check out our FAQs, or bookmark this page. We update it regularly to stay ahead of new trends in supplier risk.
