Australia · Cyber and Infrastructure Security Centre (CISC), Department of Home Affairs
SOCI Act

Security of Critical Infrastructure Act

The legislative framework that imposes cyber-security and risk-management obligations on responsible entities across 11 critical-infrastructure sectors.

Status · SOCI Act 2018 (Cth), as amended

What SOCI Act actually is.

The SOCI Act sets the baseline obligations for Australia's 11 critical-infrastructure sectors including communications, data storage and processing, financial services, water, healthcare, higher education, food and grocery, transport, space, defence industry, and energy. Key obligations include a register of critical-infrastructure assets, mandatory cyber-incident reporting, a Risk Management Program (CIRMP) and, for Systems of National Significance, enhanced cyber-security obligations agreed directly with the Minister.

Applies to

"Responsible entities" for assets across 11 critical-infrastructure sectors. A separate class of "Systems of National Significance" carries additional obligations.

Key requirements

The control areas the framework covers.

Summary of the control families and outcomes the framework drives. Always validate against the official publication for the authoritative wording.

  1. 01

    Register of critical-infrastructure assets

    Provide operational and ownership information to the Register maintained by the CISC.

  2. 02

    Cyber-incident reporting

    Notify the ACSC within 12 hours of a critical incident and 72 hours of any other reportable incident.

  3. 03

    Risk Management Program (CIRMP)

    Identify and mitigate hazards across cyber, personnel, physical and supply-chain domains.

  4. 04

    Enhanced cyber-security obligations

    For Systems of National Significance only - vulnerability assessments, system-information periodic reporting, and cyber-security exercises.

Official source

Read it from the issuing body.

For anything with a regulator or certification body behind it, the authoritative text is what counts - not our summary.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.