Back to blog
Australia & APAC

The SOCI Act: what critical infrastructure entities in Australia must actually do

Asset registration, mandatory incident reporting on a 12 and 72 hour clock, and an annually reported risk management programme. Which sectors are covered and how the Essential Eight fits in.
GRC Copilot Team
The SOCI Act: what critical infrastructure entities in Australia must actually do

The Security of Critical Infrastructure Act reaches far more Australian organisations than most people expect. Successive amendments widened it from four sectors to eleven, pulling in data storage and processing, health care, higher education, food and grocery, and financial services alongside the traditional energy and water entities.

If you are a responsible entity for a critical infrastructure asset, you have obligations that are statutory rather than contractual — and they have deadlines measured in hours.

The covered sectors

The Act designates critical infrastructure assets across communications, financial services and markets, data storage or processing, defence industry, higher education and research, energy, food and grocery, health care and medical, space technology, transport, and water and sewerage.

Being in one of these sectors does not automatically make you a responsible entity — the definitions turn on asset-level criteria and thresholds. That determination is the first thing to establish, and it is a legal question rather than a security one.

Obligation 1: register your asset

Responsible entities must provide and keep current information about their critical infrastructure assets in the register maintained by the Cyber and Infrastructure Security Centre — including operational information and interest and control information.

Like the NIS2 registration duty in Europe, this is a standalone and independently enforceable obligation. It is also the cheapest one to satisfy and the most awkward to explain having missed.

Obligation 2: report cyber incidents, fast

  • 12 hours for a critical cyber security incident that has had, or is having, a significant impact on the availability of the asset.
  • 72 hours for an incident that has had, or is having, a relevant impact on the asset.

Reports go to the Australian Signals Directorate. A verbal report is permitted, with a written record to follow within a defined period.

The 12-hour clock is the operational challenge. It runs on wall-clock time, it starts when you become aware, and it does not wait for your investigation to reach a conclusion. Decide in advance who can authorise a report out of hours, and build the process to report early with partial information.

Evidence your cyber hazard controls

GRC Copilot ships the Essential Eight as four maturity-level assessments, which is how most Australian entities demonstrate the cyber component of a risk management programme.

Obligation 3: the risk management programme

Where the rules have been switched on for an asset class, responsible entities must have and comply with a critical infrastructure risk management programme. It must identify hazards to the asset, minimise or eliminate the material risk of those hazards, and mitigate the impact if they occur — across four hazard categories:

  • Cyber and information security
  • Personnel — including the risk from trusted insiders
  • Supply chain
  • Physical and natural hazards

The programme must be reviewed regularly, and an annual report must be submitted and approved by the board or equivalent governing body. That board approval requirement is the part that changes behaviour — it puts the programme in front of directors on a schedule.

Where the Essential Eight fits

For the cyber and information security hazard, the rules point to established frameworks, and the Essential Eight is the recognised Australian yardstick. In practice most entities demonstrate that hazard category through an Essential Eight maturity position, often supported by ISO 27001 or the ASD Information Security Manual for the surrounding management system.

This is why SOCI obligations and Essential Eight programmes usually run together: the Act creates the obligation, the Essential Eight provides the measurable answer.

Systems of national significance

A small subset of assets may be privately declared systems of national significance, attracting enhanced cyber security obligations — which can include statutory incident response planning, cyber security exercises, vulnerability assessments, and system information sharing. If this applies to you, you will know, because the declaration is made to you directly.

What to do this quarter

  1. Establish, with legal input, whether you are a responsible entity and for which assets.
  2. Confirm your register entry exists and is current.
  3. Test your ability to report inside 12 hours, out of hours, with incomplete information.
  4. Map your existing controls to the four hazard categories and find which one is thinnest — it is usually personnel or supply chain, not cyber.
  5. Get the annual report onto the board calendar rather than treating it as a compliance artefact.

Frequently asked questions

Does the SOCI Act require the Essential Eight specifically?

Not by name in the way a contract might. The risk management programme obligation requires you to address cyber and information security hazards against a recognised framework, and the Essential Eight is the standard Australian means of demonstrating that.

What counts as a critical cyber security incident?

One having a significant impact on the availability of the asset — broadly, materially disrupting the essential service it provides. Define your interpretation and escalation thresholds in advance so the judgement is not improvised at 2am.

Do the obligations apply to our cloud providers?

Data storage or processing is itself a designated sector, so a provider may be a responsible entity in its own right. Your obligations remain yours regardless; supply chain is one of the four hazard categories precisely because provider dependence is a risk to your asset.

How does this interact with the Privacy Act?

They are separate regimes with separate triggers. A single incident can require a SOCI report to ASD within 12 hours and a notifiable data breach assessment under the Privacy Act on its own timeline. Build one process that satisfies both rather than discovering the overlap during an incident.

Key takeaways

  • Eleven sectors are covered, and the definitions turn on asset-level criteria — get a legal determination.
  • Registration is a standalone, independently enforceable duty.
  • The 12-hour reporting clock runs on wall-clock time and starts at awareness.
  • Board approval of the annual risk management report is what puts this in front of directors.
#soci-act #critical-infrastructure #australia #cirmp #incident-reporting #compliance