Skip to content

Evidence request lists

Security of Critical Infrastructure Act 2018 (SOCI)

Evidence request list. 35 controls, 35 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

CIRMP

AUSOCI-2
Critical Infrastructure Risk Management Program (CIRMP)

Per SOCI Section 30AC: CIRMP. Requirements include (a) Critical Infrastructure Risk Management Program (CIRMP) covering cyber + personnel + physical + natural hazards + (b) Annual CIRMP Report to Board + Department + (c) board responsibility + senior management oversight + (d) cyber hazard responsibility per CIRMP Rules + (e) align to ISO 31000 + AS/NZS standards.

Artefacts an auditor will ask for
  • SOCI evidence for AUSOCI-2
Where this commonly fails
  • CIRMP + 12-hr reporting + enhanced SoNS partial

Enhanced Obligations

AUSOCI-5
Enhanced Cyber Security Obligations and Continuous Improvement

Per SOCI Part 2C: Systems of National Significance (SoNS). Requirements include (a) Enhanced Cyber Security Obligations for SoNS including incident response planning + cyber exercises + vulnerability assessments + system information sharing + (b) Continuous Improvement and Review + (c) board engagement + (d) maintain documented programme.

Artefacts an auditor will ask for
  • SOCI evidence for AUSOCI-5
Where this commonly fails
  • CIRMP + 12-hr reporting + enhanced SoNS partial

Government Powers

AUSOCI-4
Government Assistance Powers and Direction Authority

Per SOCI Part 3A: government assistance + direction. Requirements include (a) Government Assistance Measures including information gathering directions + action directions + intervention requests + (b) Authorised Intelligence Officers + (c) ASD response capability + (d) cooperate with government powers including step-in + (e) maintain documentation.

Artefacts an auditor will ask for
  • SOCI evidence for AUSOCI-4
Where this commonly fails
  • CIRMP + 12-hr reporting + enhanced SoNS partial

Incident Reporting

AUSOCI-3
Cyber Incident Reporting (12/72 hours)

Per SOCI Sections 30BC + 30BD: cyber incident reporting. Requirements include (a) Critical Cyber Security Incident reporting within 12 hours of becoming aware to ASD ACSC + (b) Other Cyber Security Incident reporting within 72 hours + (c) maintain incident response capability + (d) cooperate with ASD on response + (e) maintain breach log + tabletops.

Artefacts an auditor will ask for
  • SOCI evidence for AUSOCI-3
Where this commonly fails
  • CIRMP + 12-hr reporting + enhanced SoNS partial

Register

AUSOCI-1
Register and Sector Coverage

Per Australian Security of Critical Infrastructure Act 2018 (SOCI) + 2022 + 2024 amendments: register + coverage. Requirements include (a) Register of Critical Infrastructure Assets per SOCI Section 18 + (b) Sector Coverage Determination across 11 critical infrastructure sectors + (c) Responsible Entity + Direct Interest Holder identification + (d) maintain registration + updates + (e) cooperate with CISC (Cyber and Infrastructure Security Centre).

Artefacts an auditor will ask for
  • SOCI evidence for AUSOCI-1
Where this commonly fails
  • CIRMP + 12-hr reporting + enhanced SoNS partial

SOCI Act: Critical Infrastructure Risk Management Program

SOCI-CIRMP-CYBER
CIRMP hazard vector: Cyber and information security

The CIRMP must address cyber and information security hazards by adopting one of five approved frameworks: AS ISO/IEC 27001, ASD Essential Eight (ML1+), NIST CSF, C2M2 (MIL1+), or AESCSF (SP1+).

Artefacts an auditor will ask for
  • CIRMP cyber annex
  • Essential Eight maturity assessment
  • cyber controls register
  • annual review records
Where this commonly fails
  • no Essential Eight mapping
  • weak cyber controls
  • no annual review
SOCI-CIRMP-PERSONNEL
CIRMP hazard vector: Personnel

The CIRMP must address personnel hazards including identifying critical workers, ensuring background checks and vetting, minimising risks from malicious or negligent insiders, and proper offboarding procedures.

Artefacts an auditor will ask for
  • personnel screening records
  • background check policy
  • insider threat program
  • training records
Where this commonly fails
  • weak screening for privileged roles
  • no insider threat program
  • missing training
SOCI-CIRMP-PHYSICAL
CIRMP hazard vector: Physical security and natural hazards

The CIRMP must address physical security and natural hazards including identifying physical critical assets, restricting physical access, incident response plans for unauthorised access, and mitigating natural disaster impacts.

Artefacts an auditor will ask for
  • physical security plan
  • natural hazards risk assessment
  • site security audits
  • BCP documentation
Where this commonly fails
  • no natural hazards analysis
  • weak site security
  • missing BCP integration
SOCI-CIRMP-SUPPLY
CIRMP hazard vector: Supply chain

The CIRMP must address supply chain hazards including minimising unauthorised access via supply chain, misuse of privileged access by suppliers, disruption of supply chain assets, and over-reliance on specific suppliers.

Artefacts an auditor will ask for
  • supplier risk register
  • supply chain mapping
  • critical supplier assessments
  • contract clauses
Where this commonly fails
  • incomplete supply chain map
  • no critical supplier identification
  • weak contractual controls
SOCI-S30AC
Obligation to adopt a CIRMP

A responsible entity for a critical infrastructure asset must adopt a written critical infrastructure risk management program that complies with the CIRMP Rules.

Artefacts an auditor will ask for
  • CIRMP document
  • board adoption minutes
  • implementation plan
  • adoption timeline records
Where this commonly fails
  • no CIRMP
  • weak board oversight
  • missed adoption timeline
SOCI-S30AD
Compliance with CIRMP

A responsible entity must comply with its critical infrastructure risk management program.

Artefacts an auditor will ask for
  • control implementation evidence
  • compliance dashboards
  • internal audit reports
  • remediation plans
Where this commonly fails
  • controls not implemented
  • no compliance evidence
  • weak audit
SOCI-S30AE
Annual review of CIRMP

A responsible entity must review its critical infrastructure risk management program at least once every 12 months and update it as necessary.

Artefacts an auditor will ask for
  • annual review document
  • board approval minutes
  • annual report submission to CISC
  • review findings register
Where this commonly fails
  • no annual review
  • no board sign-off
  • missed CISC submission

SOCI Act: Cyber Security Incident Reporting

SOCI-S30BC
Notification of critical cyber security incidents (12 hours)

A responsible entity must report a critical cyber security incident (with significant impact on availability) to the ACSC within 12 hours of becoming aware of the incident.

Artefacts an auditor will ask for
  • incident detection records
  • ASD ACSC notification log
  • 12-hour timer evidence
  • incident triage procedure
Where this commonly fails
  • missed 12-hour window
  • weak triage
  • no notification template
SOCI-S30BD
Notification of other cyber security incidents (72 hours)

A responsible entity must report other cyber security incidents (with relevant impact on availability, integrity, or reliability) to the ACSC within 72 hours of becoming aware of the incident.

Artefacts an auditor will ask for
  • incident classification records
  • 72-hour notification log
  • ASD ACSC correspondence
  • post-incident reports
Where this commonly fails
  • misclassified incidents
  • missed 72-hour window
  • incomplete reporting

SOCI Act: Enhanced Cyber Security Obligations

SOCI-S30CB
Statutory incident response planning

The responsible entity for a system of national significance must prepare, adopt, and maintain a written cyber security incident response plan and provide a copy to the Secretary.

Artefacts an auditor will ask for
  • statutory IR plan
  • plan testing records
  • plan submission to Home Affairs
  • annual review documentation
Where this commonly fails
  • no statutory plan
  • untested plan
  • missed submission
SOCI-S30CM
Cyber security exercises

The responsible entity must undertake cyber security exercises to test preparedness and submit an evaluation report within 30 days of completing the exercise.

Artefacts an auditor will ask for
  • exercise plans
  • exercise reports
  • after-action reviews
  • participation evidence
Where this commonly fails
  • no exercises
  • weak after-action review
  • no government participation
SOCI-S30CU
Vulnerability assessments

The responsible entity must undertake vulnerability assessments of the system to identify vulnerabilities for remediation.

Artefacts an auditor will ask for
  • vulnerability assessment reports
  • assessment scope documentation
  • remediation tracking
  • submission to Home Affairs
Where this commonly fails
  • narrow scope
  • no remediation tracking
  • missed submission
SOCI-S30DB
System information access

The responsible entity may be required to provide system information to the government to enable development of a near-real-time threat picture.

Artefacts an auditor will ask for
  • system information access procedure
  • data sharing agreements
  • access logs
  • compliance attestation
Where this commonly fails
  • no procedure
  • weak access logging
  • incomplete data sharing

SOCI Act: Government Assistance Powers

SOCI-S35AB
Ministerial authorisation for government assistance

The Minister may authorise government assistance in response to a cyber security incident that has seriously prejudiced or is likely to seriously prejudice the social or economic stability, defence, or national security of Australia.

Artefacts an auditor will ask for
  • ministerial authorisation records
  • request documentation
  • response procedures
  • communication protocols
Where this commonly fails
  • no preparedness procedure
  • weak communication
  • missing legal review
SOCI-S35AK
Information gathering directions

Following Ministerial authorisation, the Secretary may direct a responsible entity to provide information relevant to responding to the incident.

Artefacts an auditor will ask for
  • information gathering response procedure
  • direction tracking log
  • compliance records
  • legal review documentation
Where this commonly fails
  • no response procedure
  • delayed compliance
  • missing documentation
SOCI-S35AQ
Action directions

Following Ministerial authorisation, the Secretary may direct a responsible entity to take specified actions to respond to the incident.

Artefacts an auditor will ask for
  • action direction response procedure
  • implementation records
  • compliance evidence
  • lessons learned reports
Where this commonly fails
  • no response procedure
  • weak implementation
  • no documentation

SOCI Act: Register and Information Obligations

SOCI-S19
Register of Critical Infrastructure Assets

The Secretary must keep a Register of Critical Infrastructure Assets containing operational and ownership information provided by responsible entities.

Artefacts an auditor will ask for
  • register entries
  • asset descriptions
  • interest holder records
  • submission confirmations
Where this commonly fails
  • incomplete asset detail
  • stale interest holder data
  • missed submission
SOCI-S23
Initial obligation to give information

A responsible entity for a critical infrastructure asset must provide prescribed information to the Secretary for inclusion in the Register within prescribed timeframes.

Artefacts an auditor will ask for
  • initial information submission
  • asset characterization records
  • ownership documentation
  • submission timeline log
Where this commonly fails
  • missed initial deadline
  • incomplete characterization
  • no documentation
SOCI-S24
Ongoing obligation to update information

A responsible entity must notify the Secretary of changes to information in the Register within prescribed timeframes.

Artefacts an auditor will ask for
  • change tracking log
  • 30-day notification records
  • amended register entries
  • submission confirmations
Where this commonly fails
  • delayed change notification
  • missed material changes
  • no tracking

SOCI Act: Sector Coverage

SOCI-SECTOR-COMMS
Communications sector

Covers critical telecommunications assets, critical broadcasting assets, and critical domain name system assets.

Artefacts an auditor will ask for
  • asset identification records
  • sector-specific risk assessments
  • regulator engagement log
  • compliance attestations
Where this commonly fails
  • unclear asset scope
  • weak sector risk view
  • no regulator engagement
SOCI-SECTOR-DATA
Data storage or processing sector

Covers critical data storage or processing assets.

Artefacts an auditor will ask for
  • data storage asset register
  • business critical data identification
  • sector-specific controls
  • regulator correspondence
Where this commonly fails
  • no business critical data identification
  • weak controls
  • no regulator engagement
SOCI-SECTOR-DEFENCE
Defence industry sector

Covers critical defence industry assets.

Artefacts an auditor will ask for
  • defence asset register
  • DISP membership records
  • sector controls documentation
  • Defence engagement log
Where this commonly fails
  • no DISP membership
  • weak sector controls
  • missing Defence engagement
SOCI-SECTOR-EDU
Higher education and research sector

Covers critical education assets.

Artefacts an auditor will ask for
  • research asset register
  • foreign interference controls
  • UFIT guidelines compliance
  • sector engagement records
Where this commonly fails
  • no foreign interference framework
  • weak research data controls
  • no sector engagement
SOCI-SECTOR-ENERGY
Energy sector

Covers critical electricity assets, critical gas assets, critical energy market operator assets, and critical liquid fuel assets.

Artefacts an auditor will ask for
  • energy asset register
  • AEMO compliance records
  • AESCSF maturity assessment
  • sector controls
Where this commonly fails
  • no AESCSF assessment
  • weak AEMO engagement
  • incomplete asset register
SOCI-SECTOR-FINANCE
Financial services and markets sector

Covers critical banking assets, critical superannuation assets, critical insurance assets, and critical financial market infrastructure assets.

Artefacts an auditor will ask for
  • financial services asset register
  • APRA CPS 234 compliance records
  • sector controls
  • regulator correspondence
Where this commonly fails
  • weak CPS 234 alignment
  • incomplete asset register
  • no regulator engagement
SOCI-SECTOR-FOOD
Food and grocery sector

Covers critical food and grocery assets.

Artefacts an auditor will ask for
  • food sector asset register
  • supply chain risk records
  • sector controls documentation
  • regulator engagement log
Where this commonly fails
  • weak supply chain mapping
  • no sector engagement
  • incomplete asset register
SOCI-SECTOR-HEALTH
Healthcare and medical sector

Covers critical hospitals.

Artefacts an auditor will ask for
  • healthcare asset register
  • Privacy Act compliance records
  • sector controls
  • patient safety integration
Where this commonly fails
  • no patient safety integration
  • weak privacy controls
  • incomplete asset register
SOCI-SECTOR-SPACE
Space technology sector

Covers critical space technology assets.

Artefacts an auditor will ask for
  • space asset register
  • Australian Space Agency engagement
  • sector controls
  • supply chain mapping
Where this commonly fails
  • weak agency engagement
  • no sector controls
  • incomplete asset register
SOCI-SECTOR-TRANSPORT
Transport sector

Covers critical port assets, critical freight infrastructure and services assets, critical public transport assets, and critical aviation assets.

Artefacts an auditor will ask for
  • transport asset register
  • sector controls documentation
  • regulator engagement log
  • incident reporting procedures
Where this commonly fails
  • weak sector controls
  • no regulator engagement
  • incomplete asset register
SOCI-SECTOR-WATER
Water and sewerage sector

Covers critical water assets.

Artefacts an auditor will ask for
  • water asset register
  • WSAA WSF engagement records
  • sector controls
  • OT security documentation
Where this commonly fails
  • weak OT controls
  • no WSAA engagement
  • incomplete asset register
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Security of Critical Infrastructure Act 2018 (SOCI) framework page.