Security of Critical Infrastructure Act 2018 (SOCI)
Australian legislation mandating security obligations for owners and operators of critical infrastructure assets across 11 sectors, including cyber incident reporting, risk management programs, and enhanced cyber security obligations for systems of national significance.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Critical Infrastructure Sectors
The 11 critical infrastructure sectors covered by the SOCI Act
| Code | Title |
|---|---|
| SOCI-SECTOR-COMMS | Communications sector |
| SOCI-SECTOR-DATA | Data storage or processing sector |
| SOCI-SECTOR-DEFENCE | Defence industry sector |
| SOCI-SECTOR-EDU | Higher education and research sector |
| SOCI-SECTOR-ENERGY | Energy sector |
| SOCI-SECTOR-FINANCE | Financial services and markets sector |
| SOCI-SECTOR-FOOD | Food and grocery sector |
| SOCI-SECTOR-HEALTH | Healthcare and medical sector |
| SOCI-SECTOR-SPACE | Space technology sector |
| SOCI-SECTOR-TRANSPORT | Transport sector |
| SOCI-SECTOR-WATER | Water and sewerage sector |
Part 2 - Register of Critical Infrastructure Assets
Requirements for maintaining the Register of Critical Infrastructure Assets
| Code | Title |
|---|---|
| SOCI-S19 | Register of Critical Infrastructure Assets |
| SOCI-S23 | Initial obligation to give information |
| SOCI-S24 | Ongoing obligation to update information |
Part 2A - Critical Infrastructure Risk Management Program (CIRMP)
Requirements for establishing and maintaining a Critical Infrastructure Risk Management Program
| Code | Title |
|---|---|
| SOCI-CIRMP-CYBER | CIRMP hazard vector: Cyber and information security |
| SOCI-CIRMP-PERSONNEL | CIRMP hazard vector: Personnel |
| SOCI-CIRMP-PHYSICAL | CIRMP hazard vector: Physical security and natural hazards |
| SOCI-CIRMP-SUPPLY | CIRMP hazard vector: Supply chain |
| SOCI-S30AC | Obligation to adopt a CIRMP |
| SOCI-S30AD | Compliance with CIRMP |
| SOCI-S30AE | Annual review of CIRMP |
Part 2B - Notification of Cyber Security Incidents
Mandatory cyber incident reporting obligations
| Code | Title |
|---|---|
| SOCI-S30BC | Notification of critical cyber security incidents (12 hours) |
| SOCI-S30BD | Notification of other cyber security incidents (72 hours) |
Part 2C - Enhanced Cyber Security Obligations (Systems of National Significance)
Additional obligations for systems declared as being of national significance
| Code | Title |
|---|---|
| SOCI-S30CB | Statutory incident response planning |
| SOCI-S30CM | Cyber security exercises |
| SOCI-S30CU | Vulnerability assessments |
| SOCI-S30DB | System information access |
Part 3A - Government Assistance (Last Resort Powers)
Ministerial powers to respond to serious cyber security incidents affecting critical infrastructure
| Code | Title |
|---|---|
| SOCI-S35AB | Ministerial authorisation for government assistance |
| SOCI-S35AK | Information gathering directions |
| SOCI-S35AQ | Action directions |
Maps to 572 other frameworks
Frequently Asked Questions
What is Security of Critical Infrastructure Act 2018 (SOCI)?
Security of Critical Infrastructure Act 2018 (SOCI) is a compliance framework from Australia with 6 domains and 30 controls. Australian legislation mandating security obligations for owners and operators of critical infrastructure assets across 11 sectors, including cyber incident reporting, risk management programs, and enhanced cyber security obligations for systems of national significance. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Security of Critical Infrastructure Act 2018 (SOCI) have?
Security of Critical Infrastructure Act 2018 (SOCI) has 30 controls organised across 6 domains. The largest domains are Critical Infrastructure Sectors (11 controls), Part 2A - Critical Infrastructure Risk Management Program (CIRMP) (7 controls), Part 2C - Enhanced Cyber Security Obligations (Systems of National Significance) (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Security of Critical Infrastructure Act 2018 (SOCI) map to?
Security of Critical Infrastructure Act 2018 (SOCI) maps to 572 other compliance frameworks. The top mapping partners are CFTC System Safeguards (17 CFR 37, 38, 39, 49) (40% coverage), TISAX — Trusted Information Security Assessment Exchange (40% coverage), Telecommunications Sector Security Reforms (TSSR) (40% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Security of Critical Infrastructure Act 2018 (SOCI) compliance?
Start your Security of Critical Infrastructure Act 2018 (SOCI) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Security of Critical Infrastructure Act 2018 (SOCI) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 30 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required