SOCI Act Reforms 2026: What Critical Infrastructure Operators Need to Know
The Security of Critical Infrastructure Act 2018 (SOCI Act) is changing, and the first tranche of reform has already taken effect. Following an independent review delivered in early 2026, the Australian Government has enacted enhanced risk management rules for high-risk critical infrastructure asset classes, with a second, broader tranche of reform now closed for consultation. Here’s what’s actually changed, what’s still coming, who it affects, and what to do next.
What is the SOCI Act?
The Security of Critical Infrastructure Act 2018 is the Commonwealth law that manages national security risks to Australia’s critical infrastructure. It’s administered by the Cyber and Infrastructure Security Centre (CISC) and covers sectors, including energy, water, communications, data storage and processing, financial services, healthcare, transport, food and grocery, higher education and research, space technology, and national defence.
Most operators across the Acts 11 covered sectors are required to maintain a Critical Infrastructure Risk Management Program (CIRMP), a documented, board-approved program identifying and managing risks across four hazard categories: cyber and information security, personnel, supply chain, and physical and natural hazards.
Why is the SOCI Act being reformed now?
An independent review of the Act found the SOCI Act has succeeded in lifting baseline governance, board awareness, and incident visibility across critical infrastructure sectors, but it’s become too complex, with regulatory duplication, and remains too compliance-driven rather than outcomes-driven. The Government accepted all six of the review’s recommendations in principle and is running the response as two tranches.
What’s actually changed: Tranche 1 (now in force)
The first tranche of reform opened for consultation on 25 March 2026 and closed 1 May 2026. It covered two connected initiatives: amendments to the Ministerial Directions Powers under Part 3 of the Act, and an Exposure Draft of enhanced CIRMP Rules.
The enhanced CIRMP Rules have since been made and commenced on 10 June 2026, with implementation periods of 12 or 24 months depending on the requirement. They apply to several designated high-risk asset classes: critical broadcasting, domain name systems, electricity, energy market operator, freight infrastructure, freight services, gas, liquid fuel, and water assets. These asset classes now face more prescriptive obligations across all four hazard vectors, notably an active requirement to manage the risk posed by unsupported, unpatched, or superseded software and hardware, rather than simply documenting that such systems exist.
For many operators, that shift exposes a more basic problem first: you can’t actively manage the risk of a system you don’t have real-time visibility into. Observability, knowing what’s running, how it’s performing, and where it’s degrading before it fails, is increasingly the prerequisite layer underneath CIRMP compliance, not a separate initiative from it.
The amendments to Ministerial Directions Powers have not yet been legislated. If enacted, they would broaden the government’s ability to respond to incidents affecting critical infrastructure, including a new power letting the Minister direct non-disclosure of a cyber incident for a prescribed period where public disclosure would compromise national security. Non-compliance with a Ministerial direction would carry a significantly higher civil penalty than a standard CIRMP breach, up to 2,000 penalty units, and 10,000 penalty units for corporations – at the current $330 penalty unit rate, that takes corporate exposure from $412,500 today to $3.3 million, underscoring how seriously the Government treats non-compliance at this level.
What’s proposed: Tranche 2 (consultation closed 31 July 2026)
A second, broader consultation paper, Streamlining and Modernising the Security of Critical Infrastructure Act 2018, was released on 3 July 2026 and closed for submissions on 31 July 2026. It sets out 21 proposed measures, including:
- Expanding the classes of critical infrastructure assets covered by the Act, including space industry assets, health assets, and critical research assets
- Increasing the maximum civil penalty for breaches of core risk management duties, including the obligation to have, maintain, comply with, review and update a CIRMP, from 200 to 500 penalty units (currently around $182,000)
- Mandatory periodic independent assurance of CIRMPs, with review required at least every 24 months, shifting CIRMP maturity from an internal judgement call to something an external reviewer signs off on
- Simplifying reporting to a single annual compliance report in an approved format
As this consultation has now closed, expect the Government’s response and any resulting legislation to progress over the coming months. It’s worth monitoring rather than treating as settled.
Governance expectations are more explicit
Boards are expected to formally approve the CIRMP, set risk appetite, and receive regular (not annual) reporting on cyber risk. A CIRMP that was approved once and left unreviewed is unlikely to meet the standard the reformed framework expects, and the proposed mandatory independent assurance requirement would make that gap visible to an external reviewer rather than staying an internal matter.
Implementation periods give time, but not much
Under the now-commenced CIRMP Rules, implementation periods of 12 or 24 months apply depending on the requirement. For operators starting from a low baseline, this is a tighter runway than it looks.
Who does this affect?
CIRMP obligations currently apply across all 11 SOCI-regulated sectors, with additional sector-specific programs for telecommunications and other areas. The commenced reforms particularly sharpen requirements for the asset classes designated as high-risk, and the Tranche 2 proposals would extend coverage further, including to space technology, hospitals and health infrastructure, distributed energy resources, offshore electricity, and critical research assets. Given the scope of the review, most SOCI-regulated entities should expect their obligations to tighten to some degree, even those outside the current high-risk designation.
Adoption and readiness vary significantly by sector. Energy sector operators have generally been proactive, with mature alignment to the Australian Energy Sector Cyber Security Framework (AESCSF) already in place. Other sectors are earlier in the journey, and the breadth of the 11-sector scope has left many organisations genuinely unsure whether, or how, the reforms apply to them.
What should operators do now?
- Confirm whether the commenced CIRMP Rules apply to your asset class. The high-risk asset classes listed above are already subject to the enhanced obligations. Not every entity is affected equally.
- Re-check your CIRMP’s board governance trail. Has your CIRMP been approved by your board in the last 12 months, with risk appetite set and documented? A CIRMP that exists but hasn’t been genuinely reviewed at board level is a gap the reforms are specifically designed to close, and one that mandatory independent assurance, if legislated, would surface externally.
- Inventory privileged access and legacy systems. The commenced rules move from requiring awareness of unsupported or legacy systems to requiring active management of the risk they carry. That starts with knowing what you have: every account, every system, human and machine.
- Get real visibility into system health, not just system existence. Knowing a legacy asset exists is different from knowing whether it’s degrading, unpatched, or behaving abnormally right now. Observability tooling gives operators the continuous, evidence-based visibility that both the commenced CIRMP Rules and the proposed independent assurance requirement are effectively asking for.
- Track Tranche 2. The broader asset-class and penalty reforms are now through consultation and awaiting the Government’s response. Organisations that engage now are better placed than those that wait for a final instrument.
Where to go for more detail
The Cyber and Infrastructure Security Centre (CISC) is the primary source for SOCI Act guidance, consultation papers, and factsheets on each reform schedule. The Department of Home Affairs also runs town halls and consultation sessions through the Trusted Information Sharing Network (TISN) for regulated entities wanting direct engagement with the reform process.
Want a practical starting point for assessing your own readiness?
Talk to our team about identity security and observability for critical infrastructure, and where the gaps typically sit for operators like you.