SOCI Act for Critical Infrastructure Resilience

Critical infrastructure resilience - SOCI compliance

Practical approaches to achieving strategic and operational outcomes through strong risk, resilience and compliance management that goes beyond compliance for critical infrastructure operators

  • Cybersecurity
  • Cybersecurity services
  • Cyber governance & compliance

Thales supports critical infrastructure achieve positive business outcomes beyond compliance through tailored cyber advisory, risk management and compliance solutions.

What do you need to know about SOCI?

  1. Check asset status

    Review your current asset portfolio relative to the SOCI requirements and Cyber and Infrastructure Security Centre (CISC) guidance, consider if anything has changed over the last 12 months.

  2. Identify critical assets

    The Cyber and Infrastructure Security Centre will not engage with you directly to advise entities that they are critical infrastructure in most cases. You need to review the critical infrastructure asset rules to see if any of your assets are critical.

  3. Prepare for attestation

    Consider your timeframe for attestation and whether you have reviewed your assets, updated your risk management plan and have prepared your Board for attestation by 28th September 2025.

Annual attestation - Knowing your obligations

The Security of Critical Infrastructure Act 2018 (SOCI Act) imposes security and risk management obligations on entities in designated critical infrastructure sectors. Regulated entities must adopt an “all hazards” approach and manage material risks across four domains: personnel, cyber, physical and supply chain.

Entities must also complete an annual attestation on the adequacy of their Critical Infrastructure Risk Management Program (CIRMP). The next attestation is 28 September 2026; preparation should include reviewing CIRMP design and operating effectiveness and confirming Board oversight to support timely completion.

Comprehensive ISO27001 ISMS services
  • SOCI Act: Key considerations checklist for attestation

Understanding Australia’s security of critical infrastructure requirements

Practical approaches to performing positive security obligations

Meeting the requirements of the SOCI Act - including Positive Security Obligations (PSOs) and Enhanced Security Obligations (ESOs) - can be complex, especially given how deeply these rules impact the entire organisation.

A successful approach starts with clear stakeholder mapping and strong executive sponsorship to align security and business priorities. Understanding who the obligations apply to - from technical teams to business leaders - is key to building an effective, compliant security program.

SOCI Act: Practical Approaches to Performing Positive Security Obligations
  • SOCI Act: Practical approaches to performing positive security obligations

SOCI data amendments

The Security of Critical Infrastructure Act 2018 (Cth) (SOCI) was amended in late 2024 to capture the data storage systems that hold business critical data of those organisations captured under the Critical Infrastructure regime. In practice, this will also require entities to consider the risks to those data storage systems that are holding business critical data as part of their CIRMP, according to guidance from the Cyber and Infrastructure Security Centre this must occur before 28 May 2025. 

Obligation under SOCI Act 

Practice Performance 

Key Stakeholders 

Asset Registration 

(Part 2) 

The asset registration process requires details of the assets’ ownership, location and operation to be lodged with the regulator through a web portal. Changes to ownership or operation require the portal record to be re-submitted within 6 months of the change. 

GRC 

Site/Facility managers 
CEO/CFO 
Legal 
CISO/CIO* 

*Asset details should be identified to the SOC to support them in determining which assets are critical assets that have been registered to support cyber notification processes. 

Protected Information (Part 2) and Business critical data 

Entity information security policy and information classification requirements should describe a process for defining, determining and managing protected information and business critical data and for engaging SOCI stakeholders if either data set is affected in an incident. For less mature organisations a definition of what constitutes these information types will be of value if policy does not already provide a table for information classification specifically covering these. 

CISO/CIO 
GRC 
Site/Facility managers 

Data provider notifications (12F((3)) 

Business critical information to be defined. GRC to notify data centres that they hold critical infrastructure asset data/business critical information. 

GRC 
CISO/CIO 

High level guidance

The Security of Critical Infrastructure Act 2018 (Cth) (SOCI) was amended in late 2024 to capture the data storage systems that hold business critical data of those organisations captured under the Critical Infrastructure regime. In practice, this will also require entities to consider the risks to those data storage systems that are holding business critical data as part of their CIRMP, according to guidance from the Cyber and Infrastructure Security Centre this must occur before 28 May 2025.

  1. Data storage systems

    Review data storage systems to understand which systems are business critical, undertaking a gap analysis between your existing requirements and amended SOCI requirements and SOCI to understand any uplift requirements.

  2. Business-critical systems

    Review the risk environment surrounding your business-critical systems, including recent incidents, control testing and assurance reports, risk registers and outcomes of BCP testing, uplifting through risk workshops as required.

  3. Business-critical data

    Adopt a low compliance risk appetite approach and develop or redevelop your CIRMP, aligning with better practice across CI entities. Review your current definition and application of ‘Business Critical Data’ against the legislative definition found in Section 5 of SOCI.

Thales is a sovereign critical infrastructure entity with a long-standing record of delivering national security outcomes for Australia and, through the legacy of Australian Defence Industries, has supported sovereign capability for the ADF for more than 100 years; under the Deed, Thales and the Commonwealth share responsibility for sustaining industrial capability, strategic facilities and the secure handling of critical intellectual property in support of Australia’s defence and national security, positioning Thales to advise on tailored, outcomes-focused SOCI solutions that protect value without unnecessarily constraining value creation.

Our solutions to meet SOCI obligations

Related solutions

Compliance with AusPayNet annual assessment

Driving trust and resilience through AusPayNet annual security assessments.

  • Cybersecurity
  • Cybersecurity services
  • Cyber governance & compliance

Achieve AESCSF compliance with expert assessment service

Strategic cyber resilience through AESCSF excellence

  • Cybersecurity
  • Cybersecurity services
  • Cyber governance & compliance

Cybersecurity standards and compliance

Regulatory frameworks and practical guidance for resilient organisations

  • Cybersecurity
  • Cybersecurity services
  • Cyber governance & compliance

Contact us for more information about our solutions

Frequently asked questions