Security of Critical Infrastructure Act 2018 (SOCI)
Australian legislation mandating security obligations for owners and operators of critical infrastructure assets across 11 sectors, including cyber incident reporting, risk management programs, and enhanced cyber security obligations for systems of national significance.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (22)
Asset Registration
| Code | Title |
|---|---|
| SOCI-1.1 | Register of Critical Infrastructure Assets |
| SOCI-9.1 | Ownership and Control Disclosures |
Compliance Posture
| Code | Title |
|---|---|
| SOCI-7.1 | Penalties and Enforcement Cooperation |
Critical Infrastructure Sectors
The 11 critical infrastructure sectors covered by the SOCI Act
| Code | Title |
|---|---|
| SOCI-SECTOR-COMMS | Communications sector |
| SOCI-SECTOR-DATA | Data storage or processing sector |
| SOCI-SECTOR-DEFENCE | Defence industry sector |
| SOCI-SECTOR-EDU | Higher education and research sector |
| SOCI-SECTOR-ENERGY | Energy sector |
| SOCI-SECTOR-FINANCE | Financial services and markets sector |
| SOCI-SECTOR-FOOD | Food and grocery sector |
| SOCI-SECTOR-HEALTH | Healthcare and medical sector |
| SOCI-SECTOR-SPACE | Space technology sector |
| SOCI-SECTOR-TRANSPORT | Transport sector |
| SOCI-SECTOR-WATER | Water and sewerage sector |
Cybersecurity
| Code | Title |
|---|---|
| SOCI-2.3 | Cyber Hazard Controls |
Enhanced Obligations
| Code | Title |
|---|---|
| SOCI-4.1 | Enhanced Cyber Security Obligations (ECSO) Vulnerability Assessment |
| SOCI-4.2 | ECSO Incident Response Planning |
| SOCI-4.3 | ECSO Cyber Security Exercises |
| SOCI-4.4 | ECSO System Information Sharing |
Governance Reporting
| Code | Title |
|---|---|
| SOCI-2.2 | Annual CIRMP Report to Board |
Government Intervention
| Code | Title |
|---|---|
| SOCI-5.1 | Government Assistance and Direction Powers |
Incident Management
| Code | Title |
|---|---|
| SOCI-3.2 | Incident Classification |
Incident Reporting
| Code | Title |
|---|---|
| SOCI-3.1 | Mandatory Cyber Incident Reporting |
Information Handling
| Code | Title |
|---|---|
| SOCI-6.1 | Information Protection and Classification |
Part 2 - Register of Critical Infrastructure Assets
Requirements for maintaining the Register of Critical Infrastructure Assets
| Code | Title |
|---|---|
| SOCI-S19 | Register of Critical Infrastructure Assets |
| SOCI-S23 | Initial obligation to give information |
| SOCI-S24 | Ongoing obligation to update information |
Part 2A - Critical Infrastructure Risk Management Program (CIRMP)
Requirements for establishing and maintaining a Critical Infrastructure Risk Management Program
| Code | Title |
|---|---|
| SOCI-CIRMP-CYBER | CIRMP hazard vector: Cyber and information security |
| SOCI-CIRMP-PERSONNEL | CIRMP hazard vector: Personnel |
| SOCI-CIRMP-PHYSICAL | CIRMP hazard vector: Physical security and natural hazards |
| SOCI-CIRMP-SUPPLY | CIRMP hazard vector: Supply chain |
| SOCI-S30AC | Obligation to adopt a CIRMP |
| SOCI-S30AD | Compliance with CIRMP |
| SOCI-S30AE | Annual review of CIRMP |
Part 2B - Notification of Cyber Security Incidents
Mandatory cyber incident reporting obligations
| Code | Title |
|---|---|
| SOCI-S30BC | Notification of critical cyber security incidents (12 hours) |
| SOCI-S30BD | Notification of other cyber security incidents (72 hours) |
Part 2C - Enhanced Cyber Security Obligations (Systems of National Significance)
Additional obligations for systems declared as being of national significance
| Code | Title |
|---|---|
| SOCI-S30CB | Statutory incident response planning |
| SOCI-S30CM | Cyber security exercises |
| SOCI-S30CU | Vulnerability assessments |
| SOCI-S30DB | System information access |
Part 3A - Government Assistance (Last Resort Powers)
Ministerial powers to respond to serious cyber security incidents affecting critical infrastructure
| Code | Title |
|---|---|
| SOCI-S35AB | Ministerial authorisation for government assistance |
| SOCI-S35AK | Information gathering directions |
| SOCI-S35AQ | Action directions |
Personnel Security
| Code | Title |
|---|---|
| SOCI-2.5 | Personnel Hazard Controls |
Physical Security
| Code | Title |
|---|---|
| SOCI-2.6 | Physical and Natural Hazard Controls |
Program Governance
| Code | Title |
|---|---|
| SOCI-10.1 | Continuous Improvement and Review |
Risk Management
| Code | Title |
|---|---|
| SOCI-2.1 | Critical Infrastructure Risk Management Program (CIRMP) |
Scope and Applicability
| Code | Title |
|---|---|
| SOCI-1.2 | Sector Coverage Determination |
Sector Specific
| Code | Title |
|---|---|
| SOCI-8.1 | TSSR Telecommunications Sector Security Obligation |
Third-Party Risk
| Code | Title |
|---|---|
| SOCI-2.4 | Supply Chain Hazard Controls |
Your Compliance Coverage
If you comply with Security of Critical Infrastructure Act 2018 (SOCI), you already cover:
TISAX - Trusted Information Security Assessment Exchange
24%
12 controls mapped
Compare →Telecommunications Sector Security Reforms (TSSR)
24%
12 controls mapped
Compare →Protective Security Policy Framework (PSPF) Release 2024
24%
12 controls mapped
Compare →+ 258 more: NIST SP 800-53 Rev 5 (20%), FFIEC Cybersecurity Assessment Tool (CAT) (20%)
See all 261 mapped frameworks ↓Maps to 261 other frameworks
Frequently Asked Questions
What is Security of Critical Infrastructure Act 2018 (SOCI)?
Security of Critical Infrastructure Act 2018 (SOCI) is a compliance framework from Australia with 22 domains and 50 controls. Australian legislation mandating security obligations for owners and operators of critical infrastructure assets across 11 sectors, including cyber incident reporting, risk management programs, and enhanced cyber security obligations for systems of national significance. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Security of Critical Infrastructure Act 2018 (SOCI) have?
Security of Critical Infrastructure Act 2018 (SOCI) has 50 controls organised across 22 domains. The largest domains are Critical Infrastructure Sectors (11 controls), Part 2A - Critical Infrastructure Risk Management Program (CIRMP) (7 controls), Enhanced Obligations (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Security of Critical Infrastructure Act 2018 (SOCI) map to?
Security of Critical Infrastructure Act 2018 (SOCI) maps to 261 other compliance frameworks. The top mapping partners are TISAX - Trusted Information Security Assessment Exchange (24% coverage), Telecommunications Sector Security Reforms (TSSR) (24% coverage), Protective Security Policy Framework (PSPF) Release 2024 (24% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Security of Critical Infrastructure Act 2018 (SOCI) compliance?
Start your Security of Critical Infrastructure Act 2018 (SOCI) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Security of Critical Infrastructure Act 2018 (SOCI) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 50 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.
Get Started Free →Free forever — no credit card required