Our SOCI Act compliance services help responsible entities for critical infrastructure assets meet their obligations under the Security of Critical Infrastructure Act 2018: registering assets, reporting cyber incidents, and running a Critical Infrastructure Risk Management Program (CIRMP) that the board can sign off with confidence. Security Solution Consultants (SSC) provides SOCI Act audits, CIRMP assessments and advisory for energy, water, transport, data storage, health, food and other critical infrastructure sectors across Australia.

The SOCI Act is administered by the Cyber and Infrastructure Security Centre in the Department of Home Affairs. It covers critical infrastructure assets across 11 sectors: communications, data storage or processing, defence industry, energy, financial services and markets, food and grocery, health care and medical, higher education and research, space technology, transport, and water and sewerage. Which obligations apply depends on the asset class.
| Obligation | What it requires |
|---|---|
| Register of critical infrastructure assets | Ownership and operational information about the asset, kept up to date |
| Mandatory cyber incident reporting | Report critical cyber incidents with a significant impact within 12 hours, and other incidents with a relevant impact within 72 hours |
| Critical Infrastructure Risk Management Program (CIRMP) | Identify and minimise material risks across four hazard domains, comply with a recognised cyber security framework, and submit a board-approved annual report |
| Enhanced cyber security obligations | For Systems of National Significance: incident response planning, cyber security exercises, vulnerability assessments and system information reporting, when required |
Amendments passed in late 2024 also brought certain data storage systems that hold business critical data within the scope of the critical infrastructure asset they support.

| Hazard domain | What we assess |
|---|---|
| Cyber and information security | Compliance with your chosen cyber framework, critical systems, access, monitoring and incident response |
| Personnel | Critical workers, background checks, insider risk and access when people leave |
| Supply chain | Suppliers and service providers with access to the asset, offshore dependencies and contract controls |
| Physical security and natural hazards | Site security, environmental and natural hazard risks, and recovery arrangements |

The SOCI Act does not require an external audit, but boards must approve an annual CIRMP report and stand behind it. Our audit gives them independent evidence. We review:
The result is a findings report with ratings, a remediation plan with owners and dates, and a short board summary.
Related services: energy sector security and AESCSF assessments, enterprise risk management, and critical infrastructure and OT security training. Read our guide to what the 2026 CIRMP rules mean.
Responsible entities and direct interest holders of critical infrastructure assets across 11 sectors, including energy, water, transport, communications, data storage, health, food and grocery, and financial services. Which obligations apply depends on the asset class.
A Critical Infrastructure Risk Management Program is a written program that identifies and minimises material risks to an asset across four hazard domains: cyber and information security, personnel, supply chain, and physical security and natural hazards.
Within 90 days after the end of the Australian financial year, which is 28 September for a year ending 30 June. The report must be approved by the board, council or other governing body.
No. The Act requires a board-approved annual report, not an external audit. An independent audit gives directors evidence that the program is in place and working before they approve the report.
The CIRMP rules recognise frameworks such as the Essential Eight at maturity level one, ISO/IEC 27001, the NIST Cybersecurity Framework and, for energy, the AESCSF at security profile one, or an equivalent.
Critical cyber incidents having a significant impact must be reported within 12 hours of becoming aware of them, and other incidents having a relevant impact within 72 hours.
Tell us where you are today and what you need to achieve. We will come back with a clear scope, timeline and fixed quote.

Secure your cloud environments & ensure safe migration with compliance-ready.
Stay informed with the latest cybersecurity news and expert tips.
Copyright © 2026 Security Solution Consultants. ABN 87 616 212 063. Tarneit, Victoria 3029, Australia. All Rights Reserved.