Review of the Security of Critical Infrastructure Act 2018 Update
The Security of Critical Infrastructure Act 2018 (Cth) (the "SOCI Act") was introduced to protect essential services and critical infrastructure from interference and has since been expanded through several rounds of reform to cover a wider range of services, infrastructure, hazards and threats, including cyber incidents.
The primary objective of the SOCI Act is to protect Australia's critical infrastructure assets from threats that could disrupt essential services or pose risks to national security.
Importantly, the SOCI Act is not simply a cyber law: it is a multilayered, national resilience framework which imposes obligations on asset owners, operators and investors and gives the Commonwealth significant intervention powers. It creates compliance obligations running through the life of an asset, from ownership and structuring to day-to-day operations and incident response.
An independent review by Dr Jill Slay concluded that the SOCI Act requires major legislative changes to:
- Remove duplication with other regulatory frameworks (e.g. APRA’s CPS 230/234 and the Privacy Act);
- Move to a penalty-based enforcement model;
- Expand scope to cover AI, hyperscale cloud, CDNs, space assets and drone-related assets;
- Mandate cyber threat intelligence sharing; and
- Expand incident reporting to an all-hazards model.
The Government accepted all six recommendations and is running a legislative reform program with the Tranche 1 reforms taking effect in June 2026, and the consultation period for Tranche 2 open until 31 July 2026.
Tranche 1
Enhanced Critical Infrastructure Risk Management Program Rules
Tranche 1 advances two pieces of legislative reform addressing immediate risk management, prevention and intervention settings under the SOCI Act.
The Critical Infrastructure Risk Management Program ("CIRMP") rules require responsible entities to manage material risks across all hazards (cyber, physical, personnel and supply chain) and minimise or eliminate them so far as reasonably practicable. The enhanced rules commenced on 10 June 2026, with 12 or 24 months to implement, depending on the requirement.
The enhanced CIRMP rules apply to critical:
- Broadcasting assets;
- Domain name systems;
- Electricity assets;
- Energy market operator assets;
- Freight infrastructure assets;
- Freight services assets;
- Gas assets;
- Liquid fuel assets; and
- Water assets.
Responsible entities for the above assets must comply with both baseline and enhanced CIRMP requirements, which include:
- Requirements to address additional material risks, including:
- Impairment prejudicing Australia’s social stability, economic stability, national security or defence;
- Compromise or impairment connected to foreign ownership, control or influence;
- Offshore or remote access to critical components; and
- Offshore or remote access to business-critical data.
- Incorporating additional information in a CIRMP for specific hazards, including:
- Cyber and information security, including patch/update management, legacy system replacement and new technology risks;
- A personnel security plan addressing unauthorised access, credential misuse, non-worker access and worker onboarding/offboarding;
- Supply chain risks affecting availability, integrity, reliability or confidentiality of critical components or data; and
- Physical security and natural hazards, including access controls and security measures for workers, visitors and the public.
- Implementing processes to ensure critical workers are suitable, including AusCheck background checks on pre-employment and every five years thereafter.
- Implementing a system for assessing existing or proposed major suppliers, including legislative risks (particularly foreign government exposure) and their access, influence and control over the asset.
Proposed Amendments to the Ministerial Directions Powers in Part 3 of the SOCI Act
Under Part 3 of the SOCI Act, the Minister for Home Affairs may direct a responsible entity to do or refrain from doing a specified thing when satisfied there is a risk of an act or omission prejudicial to security and the threshold criteria are met, subject to consultation with the responsible entity.
Proposed Tranche 1 amendments to the Ministerial directions powers include:
Amendments to the Existing Directions Power in Section 32 of the SOCI Act
- Removes the requirement for an Adverse Security Assessment from ASIO in favour of ASIO advice, to reduce delays in time-sensitive cases.
Introduction of a Conditions Power
- Introduces a new conditions power to allow the Minister to impose targeted conditions (e.g. cyber-security baseline controls, minimum Australian director requirements) where ownership, control or governance arrangements create a material national security risk. Conditions would be reviewed within 12 months to assess their ongoing necessity.
- Non-compliance would be enforced under the SOCI Act, including through civil penalty orders.
- Given the potential for interplay with Foreign Investment Review Board conditions, it remains to be seen how these regimes will operate together in practice.
Restrictions on the Use of High-Risk Vendors, Products or Services
- Introduces a vendor-risk direction power enabling coordinated removal, remediation or restriction of a vendor’s products, equipment, services or technologies presenting a material national security risk. For example, the Minister could direct responsible entities to cease using a specified product or service by a set date.
- The proposal is that this power is subject to guardrails requiring the Minister to weigh economic, social and asset-availability impacts, including where replacements may lack like-for-like functionality.
Exceptions to Continuous Disclosure Requirements for Cyber Incidents
- Two options are proposed for delaying disclosure of cyber incidents to prevent broader harm:
- Using section 111AT of the Corporations Act to delay disclosure in circumstances outlined in published guidance.
- Adding a new directions power allowing the Minister to direct non-disclosure of a cyber incident for a prescribed period.
Increase Civil Penalty Provisions
- Increases the maximum civil penalty for non-compliance with a Part 3 direction to 2,000 penalty units.
Tranche 2
Streamlining and Modernising the SOCI Act
The Government is also consulting on 21 proposed measures to streamline and modernise the SOCI Act, with the consultation period open until 31 July 2026, addressing broader concerns with the Act’s structure and operation.
Key Measures Targeted at Reducing Complexity, Duplication and Uncertainty
Several measures are being considered to amend and uplift the SOCI Act to reduce complexity, duplication and uncertainty, including:
- Exemptions Framework: A clearer exemptions framework providing relief where another law or framework delivers equivalent outcomes, with equivalence criteria and review/revocation powers.
- Register: A more adaptable Register of Critical Infrastructure Assets, allowing different information and notification requirements by asset class or entity.
- Reporting: Limiting reporting to an annual compliance report in an approved, published format, with group reporting for corporate groups under consideration.
- Cyber Security Incident: Clarifying the definition so unauthorised access, modification or impairment via AI or automated tools is not excluded, with reporting thresholds unchanged.
- SoNS: Simplifying the Systems of National Significance framework, including asset-specific resilience planning and required cyber security exercises.
- Submarine Cables: Clarifying that the critical telecommunications asset framework applies to nationally significant submarine cable systems with an Australian landing.
- Data Storage or Processing Asset: Replacing the current customer/data-handling-based definition, which has created uncertainty, with provider-facing criteria to capture data centres, large service-layer providers and certain certified hosting providers via three pathways:
- Facility-based: major shared physical infrastructure, with a threshold referencing 1 MW-rated IT load;
- Service-based: large cloud, hosted infrastructure, managed hosting and disaster recovery providers, with thresholds by revenue, customers, data volume or headcount; and
- Certification-based: providers certified under the Hosting Certification Framework as suitable for sensitive government information.
Key Measures for Modernising and Refining Sector and Asset Coverage
The Government also proposes to clarify or introduce new asset classes across several sectors, including:
- Space Technologies: New asset classes for:
- Ground segment infrastructure (command, telemetry, tracking, uplink/downlink and mission operations for satellites);
- Positioning, navigation and timing support infrastructure;
- Earth observation data infrastructure; and
- Space situational awareness infrastructure.
Thresholds for each class would be developed through further consultation.
- Health Care and Medical: More consistent CIRMP obligations for critical hospitals, plus new classes for:
- Critical blood supply operations;
- Critical pathology systems operating at significant scale; and
- High-containment or specialised laboratory functions with material public health, biosecurity, national security or economic consequences if disrupted.
- Distributed Energy Resources: Updating the electricity framework for distributed generation, storage, demand-response and aggregation/dispatch platforms.
- Offshore Electricity Assets: Removing the geographic limitation so offshore assets are captured.
- Critical Freight: Broadening coverage to nationally significant freight nodes, interfaces and logistics platforms.
- Higher Education and Research: Replacing the critical education class with a narrower class focused on nationally significant sensitive research (not limited to universities).
Governance, Assurance and Accountability
Amendments have also been proposed to governance, assurance and accountability, particularly around the CIRMP framework:
- CIRMP Governance and Assurance: Reforming the CIRMP regime to:
- Allow annual compliance reports to be relied on in civil penalty proceedings;
- Require governing body approval and oversight of a responsible entity’s CIRMP, which must be reviewed at least every 24 months; and
- Introduce independent assurance of CIRMP design and effectiveness, reviewed every three years.
- Graduated Civil Penalty Settings: Increasing the middle penalty tier to strengthen deterrence for non-compliance with obligations and duties around risk identification, preparedness, assurance, testing and remediation.
- Relevant Operators: A new "relevant operator" concept for third parties with control over an asset but who are not the responsible entity, clarifying that each responsible entity retains CIRMP-compliance obligations while the relevant operators are subject to limited statutory duties (e.g. cooperation).
- Corporate Group Cooperation: A limited statutory duty on a connected group entity to cooperate where a responsible entity has a material CIRMP dependency on that group entity.
- Supply Chain Cyber Security Assurance: Clarifying how CIRMP should address cyber assurance for major suppliers through governance, procurement, technical controls and monitoring, with certification or accreditation supporting due diligence.
- Specified Risk Information: A mechanism for the Secretary of the Department of Home Affairs to identify risk, hazard or guidance material that entities must consider in CIRMP governance and review.
- Critical Workers and Critical Components: The current definitions to be replaced and refined.
Next Steps
Organisations that are directly regulated as ‘responsible entities’ under the SOCI Act, or which are indirectly subject to its requirements as a result of being in the supply chain for critical infrastructure assets, should continue to monitor developments in this space and regularly review and update their risk identification, management and mitigation plans and practices.
Please contact a member of our team if you would like to discuss the steps your organisation can take in relation to the SOCI Act and the current Government consultation.
White & Case means the international legal practice comprising White & Case LLP, a New York State registered limited liability partnership, White & Case LLP, a limited liability partnership incorporated under English law and all other affiliated partnerships, companies and entities.
This article is prepared for the general information of interested persons. It is not, and does not attempt to be, comprehensive in nature. Due to the general nature of its content, it should not be regarded as legal advice.
© 2026 White & Case LLP