What is the SOCI Act, and why is my board suddenly accountable for it?
The Security of Critical Infrastructure Act 2018 (Cth) is the Commonwealth framework for protecting the assets Australia cannot afford to have fail, and if you operate a regulated asset you are a responsible entity with obligations that reach your board.
The obligation most relevant to a board is the Critical Infrastructure Risk Management Program, or CIRMP. Under the CIRMP Rules, administered by the Cyber and Infrastructure Security Centre (CISC), a responsible entity must identify and manage material risks across four hazard vectors: cyber and information security, personnel, supply chain, and physical and natural hazards. Cyber is one quarter of the picture, and the other three reach into workforce screening, supplier management, and physical and facilities resilience.
The reason this lands at board level is structural, not incidental. The Act requires an annual report on the CIRMP to be approved by the board or governing body. That approval is a signed attestation that the organisation understands its risks and is managing them, and it is the point at which critical infrastructure security stops being a technical matter and becomes a governance one.
How did we get here? The SOCI Act from 2018 to 2026
The current moment is the latest step in a decade-long widening, from a narrow 2018 origin covering four sectors to today's regime spanning 11 sectors with board-approved risk management programs.
When the Act commenced on 11 July 2018 it was narrow, covering four sectors, electricity, gas, water, and maritime ports, and doing little more than requiring an asset register and giving government limited last-resort powers. The Security Legislation Amendment (Critical Infrastructure) Act 2021 expanded the regime to 11 sectors, introduced mandatory cyber incident reporting, and gave government assistance powers to respond to serious incidents.
The Security Legislation Amendment (Critical Infrastructure Protection) Act 2022 added the two obligations that define the regime today: the CIRMP, and enhanced cyber security obligations for the highest-criticality assets, known as Systems of National Significance. In late 2024 the Enhanced Response and Prevention Act clarified obligations to protect business critical data and added government consequence-management powers. Each step widened the perimeter or deepened the obligation.
What actually changed in 2026?
Three things moved: the Slay Independent Review pushing the regime from compliance-driven to outcomes-driven, the Enhanced CIRMP Rules in force from 10 June, and a Tranche 2 consultation proposing mandatory independent assurance, a wider perimeter, and higher penalties.
The Independent Review of the SOCI Act by Dr Jill Slay AM, made public on 24 March 2026, made six recommendations, all accepted in principle by the government. Its central conclusion is that the regime should move from being compliance-driven, focused on administration and documentation, to being outcomes-driven, focused on whether an organisation is actually more resilient, with real enforcement behind it.
The Enhanced CIRMP Rules, in force from 10 June 2026, make risk management more prescriptive for higher-risk asset classes, with staged grace periods running to June 2027 and June 2028. The Streamlining and Modernising consultation paper, released by the Department of Home Affairs on 3 July 2026 and open until 31 July 2026, proposes 21 measures including mandatory periodic independent assurance of CIRMPs, review at least every 24 months, a wider regulatory perimeter, and an increase in civil penalties for core risk management duties from 200 to 500 penalty units.
Independent assurance is the change a board should register most clearly. Once assurance of a CIRMP is mandatory and independent, the maturity of your program stops being an internal judgement and becomes visible to an external reviewer. A program that has been quietly under-resourced will not fail quietly. It will be seen.
Who is in scope now, and are we?
The Act covers 11 sectors and 22 asset classes today, and the Tranche 2 proposals would widen the perimeter further, including a new 'relevant operator' concept that can capture managed service providers who never owned an asset.
The consultation proposes to refine and expand asset classes across health, space technology, energy, freight, data, and higher education and research. It also proposes a 'relevant operator' concept, which would extend obligations beyond the asset owner to organisations that exercise material practical control over an asset or a critical function, such as managed service providers.
This is where the maturity spectrum matters, and it is worth naming for the board directly. Some organisations have run a CIRMP for two or three years and are refining a mature program. Others have only recently been captured, or expect to be under the proposed expansions. The regime does not expect every entity to be at the same point, but it does increasingly expect every entity to know where it stands. The risk is not being early or late. The risk is not knowing which you are.
How do I explain this to my board?
Leave the board clear on three things: what the organisation is accountable for, what has changed around it, and what decisions now sit with them, framed as one direction of travel rather than three disconnected updates.
Lead with accountability, not detail. The board's specific duty is the annual approval of the CIRMP, and that duty now sits inside an environment moving toward independent assurance and real penalties. Then locate your own organisation honestly on the maturity curve, because a board that believes it is mature when it is not will be surprised by the first independent assurance, and that surprise is avoidable.
Finally, surface the decisions that are genuinely theirs: whether to make a submission before the consultation closes, whether the program is resourced to meet an outcomes-driven standard, and whether the board is confident it can stand behind its next annual approval.
Five things to put in front of your board
- The board's own dutyThe annual CIRMP report requires board or governing body approval. Confirm the board understands this is an attestation, not a noting item (CIRMP Rules, CISC).
- The direction, not just the detailBrief the three 2026 changes as one shift from compliance-driven to outcomes-driven (Independent Review of the SOCI Act, 24 March 2026).
- The assurance changeFlag that independent assurance of CIRMPs is proposed, which will make program maturity externally visible (Streamlining and Modernising consultation paper, Department of Home Affairs, closes 31 July 2026).
- Our position on the curveState honestly whether the organisation is mature, mid-journey, or newly captured, and what that implies for resourcing.
- The open windowIf the reforms would affect the organisation, note that the consultation is open until 31 July 2026 and decide whether to make a submission.
