Security of Critical Infrastructure Act 2018 (SOCI)
Australian legislation mandating security obligations for owners and operators of critical infrastructure assets across 11 sectors, including cyber incident reporting, risk management programs, and enhanced cyber security obligations for systems of national significance.
Security of Critical Infrastructure Act 2018 (SOCI) is a compliance framework from Australia with 11 domains and 35 controls that map to 155 other frameworks. The largest domains are SOCI Act: Sector Coverage (11 controls), SOCI Act: Critical Infrastructure Risk Management Program (7 controls), SOCI Act: Enhanced Cyber Security Obligations (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (11)
CIRMP
| Code | Title |
|---|---|
| AUSOCI-2 | Critical Infrastructure Risk Management Program (CIRMP) |
Enhanced Obligations
| Code | Title |
|---|---|
| AUSOCI-5 | Enhanced Cyber Security Obligations and Continuous Improvement |
Government Powers
| Code | Title |
|---|---|
| AUSOCI-4 | Government Assistance Powers and Direction Authority |
Incident Reporting
| Code | Title |
|---|---|
| AUSOCI-3 | Cyber Incident Reporting (12/72 hours) |
Register
| Code | Title |
|---|---|
| AUSOCI-1 | Register and Sector Coverage |
SOCI Act: Critical Infrastructure Risk Management Program
| Code | Title |
|---|---|
| SOCI-CIRMP-CYBER | CIRMP hazard vector: Cyber and information security |
| SOCI-CIRMP-PERSONNEL | CIRMP hazard vector: Personnel |
| SOCI-CIRMP-PHYSICAL | CIRMP hazard vector: Physical security and natural hazards |
| SOCI-CIRMP-SUPPLY | CIRMP hazard vector: Supply chain |
| SOCI-S30AC | Obligation to adopt a CIRMP |
| SOCI-S30AD | Compliance with CIRMP |
| SOCI-S30AE | Annual review of CIRMP |
SOCI Act: Cyber Security Incident Reporting
| Code | Title |
|---|---|
| SOCI-S30BC | Notification of critical cyber security incidents (12 hours) |
| SOCI-S30BD | Notification of other cyber security incidents (72 hours) |
SOCI Act: Enhanced Cyber Security Obligations
| Code | Title |
|---|---|
| SOCI-S30CB | Statutory incident response planning |
| SOCI-S30CM | Cyber security exercises |
| SOCI-S30CU | Vulnerability assessments |
| SOCI-S30DB | System information access |
SOCI Act: Government Assistance Powers
| Code | Title |
|---|---|
| SOCI-S35AB | Ministerial authorisation for government assistance |
| SOCI-S35AK | Information gathering directions |
| SOCI-S35AQ | Action directions |
SOCI Act: Register and Information Obligations
SOCI Act: Sector Coverage
| Code | Title |
|---|---|
| SOCI-SECTOR-COMMS | Communications sector |
| SOCI-SECTOR-DATA | Data storage or processing sector |
| SOCI-SECTOR-DEFENCE | Defence industry sector |
| SOCI-SECTOR-EDU | Higher education and research sector |
| SOCI-SECTOR-ENERGY | Energy sector |
| SOCI-SECTOR-FINANCE | Financial services and markets sector |
| SOCI-SECTOR-FOOD | Food and grocery sector |
| SOCI-SECTOR-HEALTH | Healthcare and medical sector |
| SOCI-SECTOR-SPACE | Space technology sector |
| SOCI-SECTOR-TRANSPORT | Transport sector |
| SOCI-SECTOR-WATER | Water and sewerage sector |
Your Compliance Coverage
If you comply with Security of Critical Infrastructure Act 2018 (SOCI), you already cover:
NIST SP 800-53 Rev 5
29%
10 controls mapped
Compare →FFIEC Cybersecurity Assessment Tool (CAT)
29%
10 controls mapped
Compare →NIST Cybersecurity Framework 2.0
29%
10 controls mapped
Compare →+ 152 more: Singapore Government Instruction Manual on ICT&SS Management (IM8) (29%), SSAE 18 - Attestation Standards (SOC Reporting) (29%)
See all 155 mapped frameworks ↓Maps to 155 other frameworks
What is Security of Critical Infrastructure Act 2018 (SOCI) and who does it apply to?
Security of Critical Infrastructure Act 2018 (SOCI) is a compliance framework from Australia with 11 domains and 35 controls. Australian legislation mandating security obligations for owners and operators of critical infrastructure assets across 11 sectors, including cyber incident reporting, risk management programs, and enhanced cyber security obligations for systems of national significance. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Security of Critical Infrastructure Act 2018 (SOCI) actually require?
Security of Critical Infrastructure Act 2018 (SOCI) has 35 controls organised across 11 domains. The largest domains are SOCI Act: Sector Coverage (11 controls), SOCI Act: Critical Infrastructure Risk Management Program (7 controls), SOCI Act: Enhanced Cyber Security Obligations (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Security of Critical Infrastructure Act 2018 (SOCI) do I already cover?
Security of Critical Infrastructure Act 2018 (SOCI) maps to 155 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (29% coverage), FFIEC Cybersecurity Assessment Tool (CAT) (29% coverage), NIST Cybersecurity Framework 2.0 (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Security of Critical Infrastructure Act 2018 (SOCI)?
Start your Security of Critical Infrastructure Act 2018 (SOCI) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Security of Critical Infrastructure Act 2018 (SOCI) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required