The SOCI Act and CIRMP: what they ask of your operational technology

Updated 15 September 2026 · 7 minute read

Australia's Security of Critical Infrastructure Act 2018 was written for boards and regulators, but its weight lands on operational technology: the control systems that keep power, water, ports, rail and fuel moving. This guide reads the Act and the risk management program rules from the control room.

Who the Act covers

The Act started in 2018 with a narrow scope and was expanded twice, in 2021 and 2022, to eleven sectors: communications, data storage and processing, defence industry, energy, financial services and markets, food and grocery, health care and medical, higher education and research, space technology, transport, and water and sewerage.

Within those sectors the Act defines asset classes. If you own or operate one of them you are a responsible entity, and a set of obligations follows. Mining is not a listed sector, though a mine's port, rail or power assets can be.

The four obligations that touch OT

  • Register of critical infrastructure assets: ownership and operational information about the asset, kept current with the Cyber and Infrastructure Security Centre.
  • Mandatory cyber incident reporting: a cyber incident with a significant impact on the availability of the asset must be reported within 12 hours of becoming aware of it; an incident with a relevant impact within 72 hours. The report goes to the Australian Signals Directorate.
  • Critical Infrastructure Risk Management Program (CIRMP): for the asset classes the rules name, a written program that identifies and manages material risks across four hazard domains, including cyber and information security, with an annual report approved by the board.
  • Enhanced cyber security obligations: for assets declared systems of national significance, additional duties such as incident response planning, cyber security exercises and vulnerability assessments on request.

What CIRMP asks for, in practice

The cyber and information security hazard is where OT comes in. The rules require the entity to identify material risks to the asset, minimise or eliminate them so far as is reasonably practicable, and mitigate their impact. The program has to be more than a policy: it needs to name the risks, the controls and the owners.

The rules also require a recognised cyber security framework to be established and maintained. The list includes the Australian Energy Sector Cyber Security Framework at Security Profile 1, the Essential Eight at Maturity Level One, ISO/IEC 27001, the NIST Cybersecurity Framework and the C2M2 at Maturity Indicator Level 1, or an equivalent framework. For energy entities, AESCSF SP-1 is the natural choice because it was written for their operating environment.

What an assessor looks for

  • An asset inventory that includes the OT: controllers, HMIs, engineering workstations, network gear and the protocols between them, not just the corporate fleet.
  • A network that is segmented in fact, with the IT/OT boundary enforced and proven, not drawn on a diagram.
  • Remote access that is controlled: who, from where, for how long, with multi-factor authentication and a record.
  • Monitoring that would actually notice a change in the control network, and someone who would act on it.
  • An incident response plan that covers the plant, with the 12-hour and 72-hour clocks built into it, and evidence it has been exercised.
  • A board that has seen the material risks and signed the annual report knowing what it says.

Where to start

If the program does not yet exist, start with a risk assessment against the framework you intend to adopt and an honest asset inventory. If it does exist, test it: run a tabletop exercise on a control-system scenario and see whether the reporting clock, the vendor call and the safe-shutdown decision are actually in the plan.

The reforms are still moving. The Act was amended again in 2024, and the rules and guidance are updated periodically, so check the current text before relying on a clause.

Sources
  • Security of Critical Infrastructure Act 2018 (Cth), as amended
  • Security of Critical Infrastructure (Critical infrastructure risk management program) Rules
  • Cyber and Infrastructure Security Centre guidance

Questions we get asked

Does CIRMP apply to every critical infrastructure asset?
No. The CIRMP rules name the asset classes the program applies to. Other assets may still carry the register and incident reporting obligations. Check which classes your assets fall into.
Is IEC 62443 an accepted CIRMP framework?
It is not on the list by name. Entities use one of the listed frameworks, or apply to have an equivalent recognised, and use IEC 62443 to design and verify the OT controls underneath it.
What counts as a cyber incident with a significant impact?
In broad terms, an incident that materially disrupts the availability of the asset's essential goods or services. The 12-hour clock applies to those; the 72-hour clock to incidents with a relevant but lesser impact. The plan should decide who makes that call and how.

Want this applied to your plant?

Tell us the site, the systems and the regulator. A consultant will reply, not a sales queue.