Winner, TechNews Fast 50 | ARN Innovation

SOCI Act and Critical Infrastructure Compliance | Australia

CyberPulse works with Australian critical infrastructure operators on their obligations under the Security of Critical Infrastructure Act 2018. We assess and build Critical Infrastructure Risk Management Programs, align them to a recognised framework such as the Essential Eight, ISO 27001, the NIST Cyber Security Framework or the AESCSF, and prepare the evidence your board needs to approve the annual report.

Trusted by leading Australian organisations

CyberPulse clients include Veolia, Sydney Roosters, Utopia Digital, Meshed and Nexigen Digital.

Veolia - CyberPulse clientSydney Roosters - CyberPulse clientUtopia Digital - CyberPulse clientMeshed - CyberPulse clientNexigen Digital - CyberPulse client

Why SOCI Act Compliance Matters

Meet the Annual Reporting Deadline

The CIRMP annual report must be approved by your board, council or other governing body and given to the regulator within 90 days of the end of the Australian financial year. Programs that start in the final month rarely produce a report anyone is comfortable approving.

Satisfy Board-Level Accountability

The Act puts approval of the report in the hands of your governing body. A documented program with traceable evidence is what lets a board approve on an informed basis rather than on assurance alone.

Cover All Four Hazard Vectors

A Critical Infrastructure Risk Management Program has to address cyber and information security, personnel, supply chain, and physical and natural hazards. Programs assembled by the security team alone tend to leave the other three thin, and that shows in an annual report.

Meet Incident Reporting Windows

An incident with a significant impact must be reported within 12 hours of you becoming aware of it, and within 72 hours where the impact is relevant. Those windows are only achievable where detection, triage and escalation already work.

Make One Framework Do the Work

The CIRMP Rules accept ISO 27001, the Essential Eight at maturity level one, the NIST Cyber Security Framework, the Cybersecurity Capability Maturity Model at maturity indicator level one, and the AESCSF Framework Core. Choosing the right one means existing work counts instead of being duplicated.

Answer Partner and Procurement Questions

Operators and their suppliers increasingly ask each other to evidence SOCI alignment before contracting. A current program answers those questions without a scramble each time one arrives.

Some of the frameworks we support

ISO 27001ISO 42001AICPA SOC 2PCI DSSACSC Essential EightAPRA CPS 234NIST

 

Our SOCI Compliance Services

Assessment | CIRMP Development | Managed Compliance

At CyberPulse we make your SOCI programme clear and achievable, with fixed-price engagements and hands-on experience of the frameworks the CIRMP Rules recognise.

CIRMP Development and Framework Alignment

  • Build or uplift the program across all four hazard vectors
  • Align to the Essential Eight at maturity level one, ISO 27001, the NIST Cyber Security Framework or the AESCSF
  • One risk register, documented controls, named owners
  • Existing certifications mapped in rather than repeated

Managed SOCI Compliance and Annual Reporting

What a Critical Infrastructure Risk Management Program Must Cover

The CIRMP Rules took effect in February 2023. A responsible entity has to identify each material risk to the asset and then minimise or eliminate it across four hazard vectors. Each vector needs documented controls and evidence behind them, not a policy statement on its own.

Cyber and Information Security Hazards

Unauthorised access, misuse or interference with the systems that run the asset. This is the vector a recognised framework does the work for, whether that is the Essential Eight at maturity level one, ISO 27001, the NIST Cyber Security Framework or the AESCSF.

Personnel Hazards

The risk that a critical worker with access to the asset acts against your interests, and the quieter risk that vetting, role changes and offboarding leave access in place after it should have been removed.

Supply Chain Hazards

Dependencies on suppliers, managed service providers and vendors who can affect the availability or integrity of the asset. Assessment has to be proportionate and evidenced, not a questionnaire sitting in a folder.

Physical and Natural Hazards

Site access, environmental events and anything else that can interrupt the asset physically. Cyber controls do not cover this vector, and it is one regulators look for specifically.

All four vectors sit inside one program with one annual report. CyberPulse builds it as a single risk register with named owners, rather than four disconnected workstreams that have to be stitched together at reporting time.

Our track record in numbers

350+
Satisfied clients
500+
Certifications achieved
400+
Security assessments conducted

The SOCI Compliance Process in Australia

A SOCI program follows a clear sequence. Knowing the stages up front lets you plan resourcing around the annual reporting deadline rather than against it.

1

Asset and Obligation Scoping

The first question is which of your assets the Act actually captures. We work through asset class by asset class to establish which are critical assets, which obligations are switched on for each, and who the responsible entity is. Getting this wrong at the start is what produces either a program that misses an asset or one that over-reaches.

2

Framework Selection and Gap Assessment

The CIRMP Rules accept ISO 27001, the Essential Eight at maturity level one, the NIST Framework for Improving Critical Infrastructure Cybersecurity, the United States Department of Energy Cybersecurity Capability Maturity Model at maturity indicator level one, and the 2020-21 AESCSF Framework Core. You may also use an equivalent framework if you can justify the equivalence. We help you choose the one that fits the environment you actually run, then assess against it.

3

CIRMP Design Across All Four Vectors

Cyber and information security, personnel, supply chain, and physical and natural hazards go into one program with one risk register, documented controls and named owners. Where you already hold ISO 27001 or an Essential Eight programme, that work is mapped in rather than repeated.

4

Remediation and Evidence

Closing the gaps that matter to the asset, with evidence captured as the work happens. Evidence reconstructed weeks later is the most common reason a program reads weaker on paper than it is in practice.

5

Annual Report and Board Approval

The report must be approved by your board, council or other governing body and given to the regulator within 90 days of the end of the Australian financial year. We assemble the evidence pack, brief the board on what it is approving, and keep the submission on schedule.

SOCI Compliance Cost in Australia

SOCI programme cost varies with how many of your assets the Act captures, the framework you align to, and how much of your current control set is already evidenced. Understanding the components helps you plan the investment around the annual reporting deadline rather than against it.

1

Component 1: Asset Scoping and Gap Assessment

Establishing which assets are critical assets, which obligations are switched on for each, and where the current program sits against your chosen framework. This is the fastest component and produces the clearest picture of both your position and the work ahead.

2

Component 2: CIRMP Design and Remediation

Building the program across all four hazard vectors, closing the gaps that matter to the asset, and capturing evidence as the work happens. Scope here depends heavily on what you already hold: an existing ISO 27001 or Essential Eight programme maps in rather than being repeated.

3

Component 3: Annual Report and Ongoing Assurance

Assembling the evidence pack, briefing the board ahead of approval, submitting inside the 90 day window, and keeping the program current as the asset changes. This is the component that recurs every year.

What Does SOCI Compliance Cost in Australia?

Cost is driven by the number and class of assets the Act captures, the framework you align to, and how much existing control evidence you can carry across. An operator with a single critical asset and a mature ISO 27001 programme sits at the light end. A multi-asset operator starting without a documented program sits well above it. We scope and fix the price after the asset review, so the number you see is the number you pay.

Fixed price, scoped per asset

CyberPulse delivers SOCI engagements Australia-wide on a fixed-price basis, so you have cost certainty from the asset review through to the annual report. Contact us for a scoped estimate against your asset classes and timelines.

Why CyberPulse?

Expertise

Award-winning consultants with deep SOCI Act, AESCSF, ISO 27001 and NIST Cyber Security Framework expertise

Fixed-Price

Fixed-price delivery model with predictable costs and timelines

Support

End-to-end support from gap assessment through to ongoing managed compliance and board reporting

FAQ – SOCI Act and Critical Infrastructure Compliance

What is the SOCI Act and who does it apply to?

The Security of Critical Infrastructure Act 2018 is Australian legislation administered by the Cyber and Infrastructure Security Centre. It applies an all hazards framework across eleven critical infrastructure sectors. Obligations are switched on by asset class rather than by sector alone, so the first question for any operator is which of its assets the Act actually captures.

What is a CIRMP and what must it cover?

A Critical Infrastructure Risk Management Program requires a responsible entity to identify each material risk to the asset and then minimise or eliminate it across four hazard vectors: cyber and information security, personnel, supply chain, and physical and natural hazards. The CIRMP Rules took effect in February 2023.

When is the CIRMP annual report due and who approves it?

The annual report must be given to the regulator within 90 days of the end of the Australian financial year, and it must be approved by the board, council or other governing body of the responsible entity.

Which cyber security frameworks satisfy the CIRMP Rules?

The Rules recognise AS ISO/IEC 27001:2015, the ASD Essential Eight Maturity Model at maturity level one, the NIST Framework for Improving Critical Infrastructure Cybersecurity, the United States Department of Energy Cybersecurity Capability Maturity Model at maturity indicator level one, and the 2020-21 AESCSF Framework Core. You may also use an equivalent framework provided you can justify the equivalence.

How quickly must a cyber security incident be reported?

An incident with a significant impact on a critical infrastructure asset must be reported within 12 hours of the entity becoming aware of it. Where the impact is relevant rather than significant, the window is 72 hours. Both windows depend on detection and escalation that already work.

We already hold ISO 27001. Does that count?

Yes. AS ISO/IEC 27001:2015 is one of the recognised frameworks for the cyber and information security hazard vector. Existing certification is mapped into the CIRMP rather than repeated, which usually removes a large part of the work. The other three hazard vectors still need to be addressed.

How does the AESCSF fit with SOCI?

The AESCSF was developed for the Australian energy sector and its Framework Core is one of the frameworks named in the CIRMP Rules. CyberPulse works with operators using the AESCSF as well as the Essential Eight, ISO 27001 and the NIST Cyber Security Framework, and helps you choose the one that suits the environment you actually run.

Do you offer fixed-price SOCI engagements?

Yes. CyberPulse scopes SOCI work after the asset review and then fixes the price, covering the gap assessment, CIRMP design and the annual report cycle, so you have cost certainty from the outset.

Trusted by Critical Infrastructure Operators

What stands out is the depth of expertise. CyberPulse brings real command of the standards and the threat landscape, and applies it with judgement rather than box-ticking. Year on year they strengthen our security and compliance maturity and give leadership confidence that risk is genuinely understood, not just documented.
VeoliaRaghu Gandhy, Chief Information Security Officer, Veolia

Ready to Meet Your SOCI Obligations?

Book a Complimentary 30 minute  Compliance Strategy Call

No obligation. A 30-minute call with a consultant.

What is the Security of Critical Infrastructure Act 2018?

The Security of Critical Infrastructure Act 2018 is Australian legislation administered by the Cyber and Infrastructure Security Centre. It applies an all hazards framework across eleven critical infrastructure sectors and places three main duties on responsible entities: keeping ownership and operational information current in the Register of Critical Infrastructure Assets, reporting cyber security incidents inside defined windows, and maintaining a Critical Infrastructure Risk Management Program with an annual report approved by the board.

Obligations are switched on by asset class rather than by sector alone, so the first question for most operators is which of their assets the Act actually captures. CyberPulse works through that scoping question first, then builds the program and the evidence that supports it.