Australia government accepts six recommendations from Jill Slay SOCI Act review; Tranche 1 reforms take effect June 2026
Review of the SOCI Act | White & Case LLP
Review of the SOCI Act
Review of the Security of Critical Infrastructure Act 2018 Update
The Security of Critical Infrastructure Act 2018 (Cth) (the " SOCI Act “) was introduced to protect essential services and critical infrastructure from interference and has since been expanded through several rounds of reform to cover a wider range of services, infrastructure, hazards and threats, including cyber incidents.
The primary objective of the SOCI Act is to protect Australia’s critical infrastructure assets from threats that could disrupt essential services or pose risks to national security.
Importantly, the SOCI Act is not simply a cyber law: it is a multilayered, national resilience framework which imposes obligations on asset owners, operators and investors and gives the Commonwealth significant intervention powers. It creates compliance obligations running through the life of an asset, from ownership and structuring to day-to-day operations and incident response.
An independent review by Dr Jill Slay concluded that the SOCI Act requires major legislative changes to:
Remove duplication with other regulatory frameworks (e.g. APRA’s CPS 230
234 and the Privacy Act);
Move to a penalty-based enforcement model;
Expand scope to cover AI, hyperscale cloud, CDNs, space assets and drone-related assets;
Mandate cyber threat intelligence sharing; and
Expand incident reporting to an all-hazards model.
The Government accepted all six recommendations and is running a legislative reform program with the Tranche 1 reforms taking effect in June 2026, and the consultation period for Tranche 2 open until 31 July 2026.
Enhanced Critical Infrastructure Risk Management Program Rules
Tranche 1 advances two pieces of legislative reform addressing immediate risk management, prevention and intervention settings under the SOCI Act.
The Critical Infrastructure Risk Management Program (” CIRMP “) rules require responsible entities to manage material risks across all hazards (cyber, physical, personnel and supply chain) and minimise or eliminate them so far as reasonably practicable. The enhanced rules commenced on 10 June 2026, with 12 or 24 months to implement, depending on the requirement.
The enhanced CIRMP rules apply to critical:
Responsible entities for the above assets must comply with both baseline and enhanced CIRMP requirements, which include:
Requirements to address additional material risks, including: Impairment prejudicing Australia’s social stability, economic stability, national security or defence; Compromise or impairment connected to foreign ownership, control or influence; Offshore or remote access to critical components; and Offshore or remote access to business-critical data.
Impairment prejudicing Australia’s social stability, economic stability, national security or defence;
Compromise or impairment connected to foreign ownership, control or influence;
Offshore or remote access to critical components; and
Offshore or remote access to business-critical data.
Incorporating additional information in a CIRMP for specific hazards, including: Cyber and information security, including patch
update management, legacy system replacement and new technology risks; A personnel security plan addressing unauthorised access, credential misuse, non-worker access and worker onboarding
offboarding; Supply chain risks affecting availability, integrity, reliability or confidentiality of critical components or data; and Physical security and natural hazards, including access controls and security measures for workers, visitors and the public.
Cyber and information security, including patch
update management, legacy system replacement and new technology risks;
A personnel security plan addressing unauthorised access, credential misuse, non-worker access and worker onboarding
Supply chain risks affecting availability, integrity, reliability or confidentiality of critical components or data; and
Physical security and natural hazards, including access controls and security measures for workers, visitors and the public.
Implementing processes to ensure critical workers are suitable, including AusCheck background checks on pre-employment and every five years thereafter.
Implementing a system for assessing existing or proposed major suppliers, including legislative risks (particularly foreign government exposure) and their access, influence and control over the asset.
Proposed Amendments to the Ministerial Directions Powers in Part 3 of the SOCI Act
Under Part 3 of the SOCI Act, the Minister for Home Affairs may direct a responsible entity to do or refrain from doing a specified thing when satisfied there is a risk of an act or omission prejudicial to security and the threshold criteria are met, subject to consultation with the responsible entity.
Proposed Tranche 1 amendments to the Ministerial directions powers include:
Amendments to the Existing Directions Power in Section 32 of the SOCI Act
Removes the requirement for an Adverse Security Assessment from ASIO in favour of ASIO advice, to reduce delays in time-sensitive cases.
Introduction of a Conditions Power
Introduces a new conditions power to allow the Minister to impose targeted conditions (e.g. cyber-security baseline controls, minimum Australian director requirements) where ownership, control or governance arrangements create a material national security risk. Conditions would be reviewed within 12 months to assess their ongoing necessity.
Non-compliance would be enforced under the SOCI Act, including through civil penalty orders.
Given the potential for interplay with Foreign Investment Review Board conditions, it remains to be seen how these regimes will operate together in practice.
Restrictions on the Use of High-Risk Vendors, Products or Services
Introduces a vendor-risk direction power enabling coordinated removal, remediation or restriction of a vendor’s products, equipment, services or technologies presenting a material national security risk. For example, the Minister could direct responsible entities to cease using a specified product or service by a set date.
The proposal is that this power is subject to guardrails requiring the Minister to weigh economic, social and asset-availability impacts, including where replacements may lack like-for-like functionality.
Exceptions to Continuous Disclosure Requirements for Cyber Incidents
Two options are proposed for delaying disclosure of cyber incidents to prevent broader harm: Using section 111AT of the Corporations Act to delay disclosure in circumstances outlined in published guidance. Adding a new directions power allowing the Minister to direct non-disclosure of a cyber incident for a prescribed period.
Using section 111AT of the Corporations Act to delay disclosure in circumstances outlined in published guidance.
Adding a new directions power allowing the Minister to direct non-disclosure of a cyber incident for a prescribed period.
Increases the maximum civil penalty for non-compliance with a Part 3 direction to 2,000 penalty units.
Streamlining and Modernising the SOCI Act
The Government is also consulting on 21 proposed measures to streamline and modernise the SOCI Act, with the consultation period open until 31 July 2026, addressing broader concerns with the Act’s structure and operation.
Key Measures Targeted at Reducing Complexity, Duplication and Uncertainty
Several measures are being considered to amend and uplift the SOCI Act to reduce complexity, duplication and uncertainty, including:
Exemptions Framework: A clearer exemptions framework providing relief where another law or framework delivers equivalent outcomes, with equivalence criteria and review
Register: A more adaptable Register of Critical Infrastructure Assets, allowing different information and notification requirements by asset class or entity.
Reporting: Limiting reporting to an annual compliance report in an approved, published format, with group reporting for corporate groups under consideration.
Cyber Security Incident: Clarifying the definition so unauthorised access, modification or impairment via AI or automated tools is not excluded, with reporting thresholds unchanged.
SoNS: Simplifying the Systems of National Significance framework, including asset-specific resilience planning and required cyber security exercises.
Submarine Cables: Clarifying that the critical telecommunications asset framework applies to nationally significant submarine cable systems with an Australian landing.
Data Storage or Processing Asset: Replacing the current customer
data-handling-based definition, which has created uncertainty, with provider-facing criteria to capture data centres, large service-layer providers and certain certified hosting providers via three pathways: Facility-based: major shared physical infrastructure, with a threshold referencing 1 MW-rated IT load; Service-based: large cloud, hosted infrastructure, managed hosting and disaster recovery providers, with thresholds by revenue, customers, data volume or headcount; and Certification-based: providers certified under the Hosting Certification Framework as suitable for sensitive government information.
Facility-based: major shared physical infrastructure, with a threshold referencing 1 MW-rated IT load;
Service-based: large cloud, hosted infrastructure, managed hosting and disaster recovery providers, with thresholds by revenue, customers, data volume or headcount; and
Certification-based: providers certified under the Hosting Certification Framework as suitable for sensitive government information.
Key Measures for Modernising and Refining Sector and Asset Coverage
The Government also proposes to clarify or introduce new asset classes across several sectors, including:
Space Technologies: New asset classes for: Ground segment infrastructure (command, telemetry, tracking, uplink
downlink and mission operations for satellites); Positioning, navigation and timing support infrastructure; Earth observation data infrastructure; and Space situational awareness infrastructure.
Ground segment infrastructure (command, telemetry, tracking, uplink
downlink and mission operations for satellites);
Positioning, navigation and timing support infrastructure;
Earth observation data infrastructure; and
Thresholds for each class would be developed through further consultation.
Health Care and Medical: More consistent CIRMP obligations for critical hospitals, plus new classes for: Critical blood supply operations; Critical pathology systems operating at significant scale; and High-containment or specialised laboratory functions with material public health, biosecurity, national security or economic consequences if disrupted.
Critical pathology systems operating at significant scale; and
High-containment or specialised laboratory functions with material public health, biosecurity, national security or economic consequences if disrupted.
Distributed Energy Resources: Updating the electricity framework for distributed generation, storage, demand-response and aggregation
Offshore Electricity Assets: Removing the geographic limitation so offshore assets are captured.
Critical Freight: Broadening coverage to nationally significant freight nodes, interfaces and logistics platforms.
Higher Education and Research: Replacing the critical education class with a narrower class focused on nationally significant sensitive research (not limited to universities).
Amendments have also been proposed to governance, assurance and accountability, particularly around the CIRMP framework:
CIRMP Governance and Assurance: Reforming the CIRMP regime to: Allow annual compliance reports to be relied on in civil penalty proceedings; Require governing body approval and oversight of a responsible entity’s CIRMP, which must be reviewed at least every 24 m