Security of Critical Infrastructure Act 2018 (SOCI)
Evidence request list. 35 controls, 35 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
CIRMP
Per SOCI Section 30AC: CIRMP. Requirements include (a) Critical Infrastructure Risk Management Program (CIRMP) covering cyber + personnel + physical + natural hazards + (b) Annual CIRMP Report to Board + Department + (c) board responsibility + senior management oversight + (d) cyber hazard responsibility per CIRMP Rules + (e) align to ISO 31000 + AS/NZS standards.
- SOCI evidence for AUSOCI-2
- CIRMP + 12-hr reporting + enhanced SoNS partial
Enhanced Obligations
Per SOCI Part 2C: Systems of National Significance (SoNS). Requirements include (a) Enhanced Cyber Security Obligations for SoNS including incident response planning + cyber exercises + vulnerability assessments + system information sharing + (b) Continuous Improvement and Review + (c) board engagement + (d) maintain documented programme.
- SOCI evidence for AUSOCI-5
- CIRMP + 12-hr reporting + enhanced SoNS partial
Government Powers
Per SOCI Part 3A: government assistance + direction. Requirements include (a) Government Assistance Measures including information gathering directions + action directions + intervention requests + (b) Authorised Intelligence Officers + (c) ASD response capability + (d) cooperate with government powers including step-in + (e) maintain documentation.
- SOCI evidence for AUSOCI-4
- CIRMP + 12-hr reporting + enhanced SoNS partial
Incident Reporting
Per SOCI Sections 30BC + 30BD: cyber incident reporting. Requirements include (a) Critical Cyber Security Incident reporting within 12 hours of becoming aware to ASD ACSC + (b) Other Cyber Security Incident reporting within 72 hours + (c) maintain incident response capability + (d) cooperate with ASD on response + (e) maintain breach log + tabletops.
- SOCI evidence for AUSOCI-3
- CIRMP + 12-hr reporting + enhanced SoNS partial
Register
Per Australian Security of Critical Infrastructure Act 2018 (SOCI) + 2022 + 2024 amendments: register + coverage. Requirements include (a) Register of Critical Infrastructure Assets per SOCI Section 18 + (b) Sector Coverage Determination across 11 critical infrastructure sectors + (c) Responsible Entity + Direct Interest Holder identification + (d) maintain registration + updates + (e) cooperate with CISC (Cyber and Infrastructure Security Centre).
- SOCI evidence for AUSOCI-1
- CIRMP + 12-hr reporting + enhanced SoNS partial
SOCI Act: Critical Infrastructure Risk Management Program
The CIRMP must address cyber and information security hazards by adopting one of five approved frameworks: AS ISO/IEC 27001, ASD Essential Eight (ML1+), NIST CSF, C2M2 (MIL1+), or AESCSF (SP1+).
- CIRMP cyber annex
- Essential Eight maturity assessment
- cyber controls register
- annual review records
- no Essential Eight mapping
- weak cyber controls
- no annual review
The CIRMP must address personnel hazards including identifying critical workers, ensuring background checks and vetting, minimising risks from malicious or negligent insiders, and proper offboarding procedures.
- personnel screening records
- background check policy
- insider threat program
- training records
- weak screening for privileged roles
- no insider threat program
- missing training
The CIRMP must address physical security and natural hazards including identifying physical critical assets, restricting physical access, incident response plans for unauthorised access, and mitigating natural disaster impacts.
- physical security plan
- natural hazards risk assessment
- site security audits
- BCP documentation
- no natural hazards analysis
- weak site security
- missing BCP integration
The CIRMP must address supply chain hazards including minimising unauthorised access via supply chain, misuse of privileged access by suppliers, disruption of supply chain assets, and over-reliance on specific suppliers.
- supplier risk register
- supply chain mapping
- critical supplier assessments
- contract clauses
- incomplete supply chain map
- no critical supplier identification
- weak contractual controls
A responsible entity for a critical infrastructure asset must adopt a written critical infrastructure risk management program that complies with the CIRMP Rules.
- CIRMP document
- board adoption minutes
- implementation plan
- adoption timeline records
- no CIRMP
- weak board oversight
- missed adoption timeline
A responsible entity must comply with its critical infrastructure risk management program.
- control implementation evidence
- compliance dashboards
- internal audit reports
- remediation plans
- controls not implemented
- no compliance evidence
- weak audit
A responsible entity must review its critical infrastructure risk management program at least once every 12 months and update it as necessary.
- annual review document
- board approval minutes
- annual report submission to CISC
- review findings register
- no annual review
- no board sign-off
- missed CISC submission
SOCI Act: Cyber Security Incident Reporting
A responsible entity must report a critical cyber security incident (with significant impact on availability) to the ACSC within 12 hours of becoming aware of the incident.
- incident detection records
- ASD ACSC notification log
- 12-hour timer evidence
- incident triage procedure
- missed 12-hour window
- weak triage
- no notification template
A responsible entity must report other cyber security incidents (with relevant impact on availability, integrity, or reliability) to the ACSC within 72 hours of becoming aware of the incident.
- incident classification records
- 72-hour notification log
- ASD ACSC correspondence
- post-incident reports
- misclassified incidents
- missed 72-hour window
- incomplete reporting
SOCI Act: Enhanced Cyber Security Obligations
The responsible entity for a system of national significance must prepare, adopt, and maintain a written cyber security incident response plan and provide a copy to the Secretary.
- statutory IR plan
- plan testing records
- plan submission to Home Affairs
- annual review documentation
- no statutory plan
- untested plan
- missed submission
The responsible entity must undertake cyber security exercises to test preparedness and submit an evaluation report within 30 days of completing the exercise.
- exercise plans
- exercise reports
- after-action reviews
- participation evidence
- no exercises
- weak after-action review
- no government participation
The responsible entity must undertake vulnerability assessments of the system to identify vulnerabilities for remediation.
- vulnerability assessment reports
- assessment scope documentation
- remediation tracking
- submission to Home Affairs
- narrow scope
- no remediation tracking
- missed submission
The responsible entity may be required to provide system information to the government to enable development of a near-real-time threat picture.
- system information access procedure
- data sharing agreements
- access logs
- compliance attestation
- no procedure
- weak access logging
- incomplete data sharing
SOCI Act: Government Assistance Powers
The Minister may authorise government assistance in response to a cyber security incident that has seriously prejudiced or is likely to seriously prejudice the social or economic stability, defence, or national security of Australia.
- ministerial authorisation records
- request documentation
- response procedures
- communication protocols
- no preparedness procedure
- weak communication
- missing legal review
Following Ministerial authorisation, the Secretary may direct a responsible entity to provide information relevant to responding to the incident.
- information gathering response procedure
- direction tracking log
- compliance records
- legal review documentation
- no response procedure
- delayed compliance
- missing documentation
Following Ministerial authorisation, the Secretary may direct a responsible entity to take specified actions to respond to the incident.
- action direction response procedure
- implementation records
- compliance evidence
- lessons learned reports
- no response procedure
- weak implementation
- no documentation
SOCI Act: Register and Information Obligations
The Secretary must keep a Register of Critical Infrastructure Assets containing operational and ownership information provided by responsible entities.
- register entries
- asset descriptions
- interest holder records
- submission confirmations
- incomplete asset detail
- stale interest holder data
- missed submission
A responsible entity for a critical infrastructure asset must provide prescribed information to the Secretary for inclusion in the Register within prescribed timeframes.
- initial information submission
- asset characterization records
- ownership documentation
- submission timeline log
- missed initial deadline
- incomplete characterization
- no documentation
A responsible entity must notify the Secretary of changes to information in the Register within prescribed timeframes.
- change tracking log
- 30-day notification records
- amended register entries
- submission confirmations
- delayed change notification
- missed material changes
- no tracking
SOCI Act: Sector Coverage
Covers critical telecommunications assets, critical broadcasting assets, and critical domain name system assets.
- asset identification records
- sector-specific risk assessments
- regulator engagement log
- compliance attestations
- unclear asset scope
- weak sector risk view
- no regulator engagement
Covers critical data storage or processing assets.
- data storage asset register
- business critical data identification
- sector-specific controls
- regulator correspondence
- no business critical data identification
- weak controls
- no regulator engagement
Covers critical defence industry assets.
- defence asset register
- DISP membership records
- sector controls documentation
- Defence engagement log
- no DISP membership
- weak sector controls
- missing Defence engagement
Covers critical education assets.
- research asset register
- foreign interference controls
- UFIT guidelines compliance
- sector engagement records
- no foreign interference framework
- weak research data controls
- no sector engagement
Covers critical electricity assets, critical gas assets, critical energy market operator assets, and critical liquid fuel assets.
- energy asset register
- AEMO compliance records
- AESCSF maturity assessment
- sector controls
- no AESCSF assessment
- weak AEMO engagement
- incomplete asset register
Covers critical banking assets, critical superannuation assets, critical insurance assets, and critical financial market infrastructure assets.
- financial services asset register
- APRA CPS 234 compliance records
- sector controls
- regulator correspondence
- weak CPS 234 alignment
- incomplete asset register
- no regulator engagement
Covers critical food and grocery assets.
- food sector asset register
- supply chain risk records
- sector controls documentation
- regulator engagement log
- weak supply chain mapping
- no sector engagement
- incomplete asset register
Covers critical hospitals.
- healthcare asset register
- Privacy Act compliance records
- sector controls
- patient safety integration
- no patient safety integration
- weak privacy controls
- incomplete asset register
Covers critical space technology assets.
- space asset register
- Australian Space Agency engagement
- sector controls
- supply chain mapping
- weak agency engagement
- no sector controls
- incomplete asset register
Covers critical port assets, critical freight infrastructure and services assets, critical public transport assets, and critical aviation assets.
- transport asset register
- sector controls documentation
- regulator engagement log
- incident reporting procedures
- weak sector controls
- no regulator engagement
- incomplete asset register
Covers critical water assets.
- water asset register
- WSAA WSF engagement records
- sector controls
- OT security documentation
- weak OT controls
- no WSAA engagement
- incomplete asset register
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Security of Critical Infrastructure Act 2018 (SOCI) framework page.