Legal Insights

Will you be caught by an expanded SOCI for a new era? Your chance to consult on the most extensive reforms to the SOCI Act since its introduction

By
• 22 July 2026 • 6 min read

The Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act) is central to Australia’s critical infrastructure framework, protecting critical infrastructure (CI) assets and the essential services they support from hazards and threats.

Key takeaways 

Earlier this month, the Department of Home Affairs released the Security of Critical Infrastructure – Streamlining and Modernising the SOCI Act Consultation Paper (Consultation Paper). The Consultation Paper proposes 21 reform measures to streamline the SOCI Act and ensure it remains fit for purpose in response to a rapidly evolving threat landscape, including in response to new and emerging technologies and cyber threats.

The reforms propose to create a number of new CI assets and sectors, including health assets (such as laboratories, pathology and blood supply entities), critical logistics and freight assets, distributed energy resource assets and offshore electricity assets, space technologies assets and critical research functions (broadening this beyond the current focus on universities).

The Consultation Paper also flags the expansion of existing CI asset classes to capture: 

  • owners and operators of data centre facilities as critical data storage or processing assets – with the Consultation Paper proposing a starting point of 1 MW IT-rated load being caught. Other proposed pathways to be caught in this asset class are service-based, certification-based and Ministerial designation; and
  • entities that own or operate components of nationally significant submarine cable systems, where those components are most relevant to the cables’ security and restoration, including shore-ends, landing stations, terminal equipment, power feeds and network-management systems. 

For those assets and sectors already covered (or which could become covered) by the SOCI Act, the proposed reforms will also significantly increase compliance obligations. Critical aspects of the proposed reforms which you should consider include:

  • Critical Infrastructure Risk Management Program (CIRMP) processes – the proposed reforms aim to increase governance requirements by making the board (or senior management) accountable for the CIRMP (beyond approval of the CIRMP annual report) and requiring periodic independent assurance for CIRMPs;
  • potential impacts on supply chain arrangements – the proposals include extending SOCI Act obligations to ‘relevant operators’ (such as managed service providers, OEMs or platform administrators) and related corporate group entities, and requiring organisations to assess and manage cyber risks in their own supply chains;
  • the impact on your existing incident response processes, due to the proposed expansion of ‘cyber security incidents’ to include AI and automated systems.

Feedback for the Consultation Paper is open until midnight (AEST) on 31 July 2026.

Where did these reforms come from?

The Department of Home Affairs appointed Dr Jill Slay AM to conduct an independent review of the SOCI Act between November 2025 and January 2026 (Independent Review). The Independent Review involved comprehensive stakeholder engagement and assessed whether the SOCI Act was functioning as intended for critical infrastructure (CI) and to achieve its stated objectives.

The Independent Review’s final report was tabled in Parliament in March 2026. Whilst acknowledging the SOCI Act’s strengths, the Independent Review found significant complexity, regulatory duplication and enforcement weaknesses were leaving the Act ill-equipped to respond to rapidly evolving threats such as those from artificial intelligence, quantum computing and hybrid warfare (including drone technology and space-based threats).

The Independent Review, through 6 broad recommendations, proposed a wholesale legislative restructure to make the SOCI Act more agile and outcome-driven (rather than compliance-focused) and better suited to Australia’s current geopolitical and threat environment.

The Government accepted all 6 recommendations and in response is proposing the legislative reforms to the SOCI Act that are outlines in the Consultation Paper. 

What are the main reforms which are proposed in the Consultation Paper? 

The Consultation Paper seeks feedback on 21 proposed measures – the key objectives and measures are outlined in the table below.

  • Objective: Creating new sectors and assets

    Proposed new sectors and assets include:

    • critical hospitals, laboratories, pathology and blood supply entities; 
    • distributed energy resources (such as storage and virtual power-plants);
    • offshore electricity assets; 
    • freight, distribution and supply-chain nodes and logistics platforms;
    • space technology asset classes; and 
    • critical research functions (broadening this beyond the current focus on universities). 
  • Objective: Enhance governance, assurance and accountability
    • Uplift CIRMP governance requirements by allowing CIRMP annual reports to be relied on as evidence in civil penalty proceedings, making boards (or senior management) accountable for the CIRMP (beyond approval of the annual report) and requiring periodic independent assurance for CIRMP design, implementation and effectiveness.
    • Increase maximum penalties for middle-tier breaches of core preventative and assurance obligations to 500 penalty units ($182,000).
    • Introduce the new concept of a ‘relevant operator’ – being a third party (such as managed service providers, OEMs or platform administrators) which exercises material practical control over a CI asset or critical function, where both practical operational authority and material operational dependency on that control must be present.
    • Subject ‘relevant operators’ to direct obligations under the SOCI Act, including targeted registration requirements and limited statutory duties, such as needing to cooperate with the responsible entity's CIRMP obligations, notify the responsible entity of material impacts on the CI asset, and not materially compromise the CI asset.
    • Extend SOCI Act obligations for a CI asset to connected entities within a responsible entity’s corporate group for a CI asset by imposing limited statutory duties.
    • Require responsible entities to assess and manage cyber risks from major suppliers and service providers in their supply chain – through contractual or equivalent measures – and record outcomes as part of their CIRMP.
    • Introduce clearer definitions of ‘critical workers’ and ‘critical components’. 
  • Objective: Expanding existing assets/sectors

    Explicitly clarify that the SOCI Act covers:

    • data centre facilities, storage and hosting providers within the scope of ‘critical data storage or processing asset’ – with the Consultation Paper proposing a threshold of 1 MW for owners and operators of data centre facilities. The paper seeks consultation on this proposed threshold, noting that this threshold is ‘low relative to industry norms’ and would capture most commercial data centre providers and operators; and
    • submarine telecommunications cables and associated infrastructure.
  • Objective: Reduce complexity, duplication and uncertainty
    • Establish a clearer exemptions framework for duplicate regulation.
    • Restructure CI registration, annual reporting and continual notification obligations to reduce compliance friction (but expand the types of registrable information that must be disclosed). 
    • Capture AI and automated systems within the definition of ‘cyber security incidents’.
    • Streamline the Systems of National Significance framework to switch the focus from incident response onto resilience planning.

How will reforms occur?

The Department of Home Affairs is reforming the SOCI Act in two tranches:

  1. The first tranche of reforms will address immediate risk management and intervention issues. Tranche 1 includes:
    1. amendments to the Critical Infrastructure Risk Management Program Rules (CIRMP Rules) covering all-hazards risk management, cyber security, supply chain security, and physical and personnel security for high-risk asset classes. Following consultation in March 2026, these amendments took effect through the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026; and
    2. consultation on proposed amendments to the Ministerial directions framework in Part 3 of the SOCI Act, covering the general directions power in section 32 and new provisions on governance-related conditions, high-risk vendors, delayed continuous disclosure, and civil penalties for non-compliance. Legislative amendments to Part 3 are yet to be implemented.
       
  2. The second tranche focuses on improving the SOCI Act’s underlying legislative framework – the focus of the Consultation Paper.

What this means for the remainder of 2026

Organisations should treat the Consultation Paper's proposed reforms as an early indicator of the Government’s regulatory direction. 

If implemented, the reforms would simplify the SOCI Act, strengthen enforcement and assurance, increase CIRMP compliance requirements, extend SOCI Act obligations to a number of new entities within supply chains and expand the asset coverage.

Affected stakeholders should use the remainder of 2026 to assess the impact on their operations and engage with the consultation process to help shape the reforms before legislation is introduced.

What should you be doing now?

If you operate in a sector covered (or proposed to be covered) by the SOCI Act, the Department of Home Affairs is seeking your submission on the proposed amendments by 31 July 2026.

This is particularly relevant if you operate in one of the new or expanded CI asset classes, including submarine telecommunications cables, data storage or processing, space technology, distributed energy systems, hospitals and health infrastructure, critical freight, and higher education and research.

If you need assistance preparing a submission or assessing how the proposed reforms may affect your organisation, our SOCI Act experts can help.

Brendan Tomlinson

Brendan advises on a wide range of IT transactions and supports clients with IP protection, commercialisation, privacy and cyber security.

View profile

Ooma Khurana

Ooma advises public and private sector clients in information technology, consumer markets and telecommunications sectors, particularly in relation to regulatory compliance and technology.

View profile
By

Recent articles

Online Access