SOCI Act Obligations in Brief
Which obligations apply depends on your asset class. For operators of critical electricity, gas, water and liquid fuel assets, among others, they include:
Register of Critical Infrastructure Assets
Ownership and operational information about the asset, given to the Cyber and Infrastructure Security Centre (CISC) and kept up to date.
Mandatory cyber incident reporting
Reports to the Australian Signals Directorate's Australian Cyber Security Centre (ACSC): within 12 hours of becoming aware of a cyber security incident that is having a significant impact on the availability of the asset, and within 72 hours for an incident having a relevant impact.
Critical infrastructure risk management program (CIRMP)
A written program that identifies material risks across four hazard domains (cyber and information security, personnel, supply chain, and physical security and natural hazards) and, so far as reasonably practicable, minimises or eliminates them. An annual report, approved by the board or equivalent governing body, is due within 90 days after the end of the financial year.
A recognised cyber framework
Under the CIRMP rules, responsible entities must comply with one of AS ISO/IEC 27001:2015, the Essential Eight Maturity Model at Maturity Level One, the NIST Cybersecurity Framework, the C2M2 at Maturity Indicator Level 1, the AESCSF Framework Core at Security Profile 1, or an equivalent framework. The transition period for this requirement ended on 17 August 2024.
Systems of National Significance
Assets declared to be Systems of National Significance carry enhanced cyber security obligations, such as incident response planning, cyber security exercises and vulnerability assessments.
Amendments passed in late 2024 tightened the Act further: data storage systems that hold business-critical data for an asset are now treated as part of it, and the regulator can direct an entity to fix a seriously deficient risk management program.
Making Sure Your CIRMP Covers OT
The cyber section of a CIRMP is usually written by the corporate IT security team, against a framework designed for corporate IT. The ACSC itself says the Essential Eight was designed for internet-connected IT networks and may not suit operational technology. Yet for a water, energy or gas operator, the material risks that matter most are to the physical process: chemical dosing at a treatment plant, pumps or compressors stopping, a substation tripping, telemetry going dark across hundreds of sites.
A program that reports a healthy Essential Eight score while the SCADA network is flat, accounts are shared and vendors have always-on remote access is not managing the material risk. Closing that gap is the work I do.
How I Help
CIRMP review for OT
Reading your program against the control systems you actually run: are the OT assets identified, are their material risks assessed, and do the controls it describes exist on site?
OT risk assessment
An IEC 62443-3-2 based OT cybersecurity risk assessment that gives the CIRMP real evidence for the operational technology part of the cyber hazard domain.
Framework selection and mapping
Choosing the named framework that suits your organisation and mapping your OT controls to it, so IEC 62443 design work also counts towards SOCI compliance. For energy operators that is often AESCSF Security Profile 1.
Incident reporting readiness for OT
Deciding in advance what a "significant impact on availability" looks like for your asset, how a SCADA event reaches the person who must report it inside 12 hours, and practising it.
OT supply chain and vendor access
The supply chain hazard domain in OT terms: integrator and vendor remote access, support contracts, spares and obsolescence, and the security you require of service providers under IEC 62443-2-4.
Board reporting
A plain-English briefing on OT risk for the directors who have to approve the annual report.
Operating a critical water asset? See SCADA and OT cybersecurity for water utilities.
This page is a practical summary from a cybersecurity consultant, not legal advice. Confirm your obligations with your legal advisers or the Cyber and Infrastructure Security Centre.Last reviewed October 2026.
Frequently Asked Questions
Does the SOCI Act require IEC 62443?
No. The CIRMP rules name five cyber frameworks (ISO/IEC 27001, the Essential Eight at Maturity Level One, the NIST Cybersecurity Framework, C2M2 at MIL 1 and AESCSF Security Profile 1) or an equivalent. IEC 62443 isn't one of them, but it is well suited to designing OT controls, and those controls can be mapped to whichever named framework you report against.
When is the CIRMP annual report due?
Within 90 days after the end of the Australian financial year, which means by late September, and it must be approved by your board, council or other governing body.
What are the SOCI Act cyber incident reporting timeframes?
Within 12 hours of becoming aware of a cyber security incident that is having a significant impact on the availability of the asset, and within 72 hours for one having a relevant impact. Reports go to the Australian Signals Directorate's ACSC, and a verbal report must be followed up in writing.
Who regulates the SOCI Act?
The Cyber and Infrastructure Security Centre (CISC), in the Department of Home Affairs, administers the Act. Cyber incident reports go to the Australian Signals Directorate.
Is this legal advice?
No. I'm a cybersecurity consultant, not a lawyer. I help with the technical and risk management side of the Act; confirm your legal obligations with your advisers or the CISC.
Related Services
- OT Cybersecurity Risk AssessmentAn IEC 62443-3-2 assessment of your SCADA and control systems, safe for live plant.
- AESCSF AssessmentsFacilitated AESCSF self-assessments and uplift plans for electricity and gas operators.
- Water Utility SCADA & CybersecuritySCADA, telemetry and OT security for water and wastewater utilities and councils.
- IEC 62443 ConsultingZones and conduits, security levels, CSMS and system requirements, applied to your OT.
Bring OT Into Your CIRMP
A short call is enough to see where your program stands for OT and what to tackle before the next annual report.