In short: SOCI Act compliance is now being audited and enforced, not just monitored. If you’re a responsible entity for a critical infrastructure asset, you likely need a written CIRMP, incident reporting within 12 to 72 hours, and an annual report your board approves. Miss the deadline and you’re not late, you’re non-compliant, and penalties reach $364,000. The Enhanced Rules from June 2026 add new obligations for 9 asset classes, due in 2027 and 2028. If you already know what applies to you and want help closing the gaps, our SOCI Act compliance services page explains how we work.
What is the SOCI Act and who does it apply to?
The SOCI Act is the Commonwealth law that sets security obligations for owners and operators of critical infrastructure assets in Australia. It applies to the responsible entity, usually the operator of the asset rather than the owner of the land or the shares.
If that’s you, the duties sit with you. They can’t be outsourced. Three obligations apply to most in-scope assets:
- Registering the asset and keeping its details current.
- Reporting cyber incidents to the Australian Signals Directorate within 12 hours for a significant impact and 72 hours for a relevant impact.
- Depending on your asset class, maintaining a written risk management program.
What sectors are covered under the SOCI Act?
There are 11 SOCI Act sectors: communications, financial services and markets, data storage or processing, defence industry, higher education and research, energy, food and grocery, health care and medical, space technology, transport, and water and sewerage.
Being in one of these sectors doesn’t automatically put you in scope. The 11 sectors contain 22 defined asset classes, and the obligations attach to the asset classes, not the sector.
Some apply to every in-scope asset, others to a subset. The first task is working out which you hold.
What is CIRMP, and is my organisation required to have one?
A critical infrastructure risk management program, or CIRMP, is a written program that identifies the material risks to your asset and sets out how you manage them. It’s not a cybersecurity plan. Under the 2023 Rules it covers four hazard categories: cyber and information security, personnel, supply chain, and physical security and natural hazards.
The Enhanced CIRMP Rules, in force from 10 June 2026, added credential compromise and lateral movement as further hazards, lifted the accepted cybersecurity frameworks for 9 of the 13 asset classes below, and added four new prescriptive controls.
Not every business in a critical sector carries this obligation. The CIRMP duty applies to 13 defined asset classes:
- Critical broadcasting assets
- Critical domain name systems
- Critical data storage or processing assets
- Critical electricity assets
- Critical energy market operator assets
- Critical gas assets
- Designated hospitals
- Critical food and grocery assets
- Critical freight infrastructure assets
- Critical freight services assets
- Critical liquid fuel assets
- Critical financial market infrastructure assets used in connection with payment systems
- Critical water assets
Critical telecommunications assets carry an equivalent obligation under separate rules. The word critical does real work here: a business that doesn’t meet the criticality tests isn’t captured. Our CIRMP article works through scope in more detail.
What does CIRMP compliance actually require?
Your program has to identify each material risk, describe the controls that minimise or eliminate it, and explain how they’re tested and maintained. A CIRMP isn’t paperwork to file away. It’s evidence, the record a board can point to and a regulator can request, so it has to be a document the business actually uses.
When was the CIRMP deadline, and what happens if we missed it?
Both deadlines have passed. An entity without a program today isn’t late, it’s non-compliant. The obligation commenced on 17 February 2023 with a six month grace period, putting programs in place by 17 August 2023, and the cyber framework requirement followed on 17 August 2024.
Late is still far better than never. When the regulator decides how to respond, it weighs the seriousness of the non-compliance, the need for deterrence, and the entity’s compliance history and regulatory posture. Know where your program falls short and show the work already underway to close it. That’s a stronger position than hearing it first from an auditor.
How often does a CIRMP need to be reviewed and reported on?
You must submit an annual report to your sector regulator within 90 days of the end of the financial year: 28 September, every year. The program itself must be reviewed regularly, and updated whenever your risk profile changes.
The report must be approved by the board, council or other governing body. That’s the requirement organisations most often underestimate. It means the program has to be board-ready months before September.
What cybersecurity framework should we adopt for our CIRMP?
The Rules name five acceptable frameworks. Nine of the 13 asset classes above face a higher standard: broadcasting, domain name systems, electricity, energy market operator, gas, freight infrastructure, freight services, liquid fuel and water. Here’s the base standard, and the higher standard for those nine:
- AS ISO/IEC 27001:2015, lifted to the 2023 version
- ASD Essential Eight at Maturity Level One, lifted to Level Two
- The NIST Framework for Improving Critical Infrastructure Cybersecurity, lifted to NIST CSF 2.0
- The Australian Energy Sector Cyber Security Framework at Security Profile 1, lifted to Profile 2
- The US Department of Energy C2M2 at Maturity Indicator Level 1, lifted to version 2.1 at Level 2
You may also use an equivalent framework, provided you can justify the choice. Essential Eight isn’t compulsory. It’s one accepted path among several, so an entity already committed to ISO 27001 doesn’t have to switch.
The Rules add four prescriptive controls for those nine: phishing-resistant multi-factor authentication, network segregation that lets critical systems run independently for at least three months, supply chain mapping including major suppliers, and AusCheck background checks for critical workers every five years.
Two deadlines apply. By 10 June 2027 you must address the new material risks: failure to patch, unsupported or legacy components, and unauthorised or unsupervised access. Everything else, including the Essential Eight uplift, is due by 10 June 2028.
What are the SOCI Act penalties for non-compliance?
Having no compliant risk management program exposes a body corporate to up to $364,000. A late annual report: up to $273,000.
Penalties are set in penalty units, and the Commonwealth unit rose from $330 to $364 on 1 July 2026. Failing to adopt and maintain a program is 200 units under section 30AC, and a late annual report is 150 units under section 30AG. Under the Regulatory Powers (Standard Provisions) Act 2014, a body corporate can be ordered to pay five times the specified amount.
The fine is rarely the largest consequence. The Act also gives direction and information-gathering powers, and a serious incident at an entity with a deficient program becomes a board problem, not an IT one.
How does a CISC audit work and what do auditors look for?
The Cyber and Infrastructure Security Centre doesn’t wait for incidents. Under section 37, the Secretary can require you to produce documents, including your risk management program. Failing to comply is itself a civil penalty provision.
The Centre has also begun auditing. It ran trial audits across ten sectors in the second half of 2023-24, checking both compliance and program adequacy. Of the nine that concluded, three were fully compliant, four mostly compliant and two partly compliant. Formal compliance monitoring commenced in November 2024.
An audit tests the gap between the document and the operating reality. Entities come unstuck when the program describes controls that were never implemented, when the declared maturity can’t be evidenced, or when nothing has been reviewed since. Our SOCI Act compliance checklist sets out what to have ready.
How do we get started if we are not yet compliant?
Start by confirming scope. Everything else depends on it. Identify your asset classes, confirm whether you’re the responsible entity, and establish which obligations attach. Then assess honestly against your chosen framework and document the gap, including what you can’t yet meet.
That gap assessment becomes both your remediation plan and your evidence that the obligation is being managed, not ignored.
If you’d like an independent view of where you stand, contact our team for a scoped assessment. Plenty of advisers can tell you what the Rules say. ASE Tech is a SOCI-regulated entity with active CIRMP obligations, and ISO 27001 certified: these aren’t obligations we advise on, they’re ones we meet. Twenty years in Australian critical infrastructure means we assess what you need, not what a vendor wants to sell you.
