ORCA Opti

Frameworks

The SOCI Act, explained

Security of Critical Infrastructure obligations for responsible entities.

The Security of Critical Infrastructure Act 2018, the SOCI Act, sets security obligations for the entities that own or operate Australia's critical infrastructure. Amendments through 2021, 2022 and 2024 broadened it well beyond the sectors it first covered.

This page covers who the Act applies to, the core obligations, and where ORCA Opti helps you hold the risk management programme and the incident record the Act now requires.

Start free

What the SOCI Act is

The SOCI Act is administered through the Cyber and Infrastructure Security Centre, with cyber incidents reported to the Australian Signals Directorate. It applies to responsible entities across eleven sectors, including energy, water and sewerage, health care and medical, communications, financial services and markets, data storage or processing, transport, food and grocery, defence industry, higher education and research, and space technology.

Its obligations are not a single checklist. They include maintaining a risk management programme, reporting cyber incidents within set timeframes, keeping the register of critical infrastructure assets current, and, for the most significant assets, enhanced cyber security obligations.

The Act carries real consequences. Its subject is national resilience, and the obligations sit on named responsible entities rather than on an IT function.

Who the SOCI Act applies to

You are likely in scope if you are a responsible entity for a critical infrastructure asset. That includes:

  • Operators in the eleven regulated sectors, from energy and water to health care, data storage and processing, transport and communications.
  • Organisations holding a Critical Infrastructure Risk Management Programme obligation, the CIRMP.
  • Entities responsible for a System of National Significance, which attracts enhanced cyber security obligations.
  • Suppliers and boards who need to evidence how the obligation is being met, not just that someone owns it.

Carrying a SOCI obligation? See how the risk programme and incident record work against your own assets on a walkthrough.

Start free

The core obligations

The duties that most often need a system behind them rather than a spreadsheet:

Risk management programme

A CIRMP identifying and managing material risks to the asset across cyber, personnel, supply chain and physical hazards, reviewed and reported annually with board oversight.

Mandatory incident reporting

Cyber security incidents reported to the ASD within set timeframes: a critical incident within 12 hours, a lesser incident within 72. The clock is short, so the record and the process have to be ready before the incident.

Register of assets

Keeping the register of critical infrastructure assets, including operational and ownership information, current and accurate.

Enhanced obligations for SoNS

For a System of National Significance, additional obligations that can include incident response planning, exercises and vulnerability assessments.

Where ORCA Opti helps

The legal determinations and the reporting decisions are yours. What ORCA does is give the obligations a structured home, so the annual programme is maintained and an incident record can be produced against the clock rather than reconstructed after it.

Opti Core

Holds the risk management programme, the asset register and the control mapping, with review cycles that raise their own tasks and escalate when overdue. Incidents are recorded with their regulatory and contractual impact rated against each one, which is what a 12 or 72 hour reporting decision needs in front of it. An incident can be raised automatically from a failed check.

Opti Cyber

Continuous, dated evidence of your Microsoft and cloud posture feeds the cyber hazard part of the CIRMP, so the programme reflects your live environment rather than a point-in-time snapshot.

AI Guardian

Where AI systems touch a critical asset, AI Guardian records their use and enforces limits at runtime, so AI risk is inside the programme rather than an unexamined gap in it.

What stays yours. Deciding whether an incident is reportable, meeting the statutory timeframe, and signing the annual programme are the responsible entity's own duties. ORCA structures the record and prompts the timeline; it does not make the legal call.

Common questions

See where you stand

Book a walkthrough and we will show you ORCA Opti against the framework you are working to, or start free with the Microsoft 365 or Google Workspace account you already have.

Start free

Join our mailing list

News and updates from ORCA Opti.