SOCI ActSecurityAustraliaCritical Infrastructure

Australia Security of Critical Infrastructure Act 2018

Australian law protecting critical infrastructure assets. Requires mandatory incident reporting within 72 hours and comprehensive risk management programs.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

SOCI ActPart 2AA record of access

Critical Infrastructure Risk Management

Responsible entities MUST adopt and maintain a critical infrastructure risk management program.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

SOCI ActSection 30BCDetecting it in time to notify

Cyber Security Incidents

Critical cyber security incidents MUST be reported to the Australian Signals Directorate within 72 hours.

Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.

SOCI ActPart 3A record of access

System of Records

Entities MUST maintain records of access to critical infrastructure systems for forensic investigation.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

SOCI ActSection 30BFDetecting it in time to notify

Ransomware Reporting

Ransomware payments MUST be reported within 72 hours of making or becoming aware of the payment.

Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.

What SOCI Act covers

Security of Critical Infrastructure Act 2018, s. 5 — business critical data

Data that, if compromised, would prejudice the socio-economic stability, defence or national security of Australia — defined partly by a headcount threshold.

In scope

  • Personal information about at least 20,000 individuals
  • Information about research and development in relation to a critical infrastructure asset
  • Information about systems needed to operate a critical infrastructure asset
  • Risk management and systems information for the asset

The 20,000-individual threshold is a rare instance of a data definition turning on volume rather than on kind, which means a dataset can enter scope through growth alone.

Security of Critical Infrastructure Act 2018 · as at 2026-08

How SOCI Act is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Cyber and Infrastructure Security Centre, within the Department of Home Affairs.

Published maximumChargedAs at
200 penalty unitsfor failing to adopt and maintain a critical infrastructure risk management programme2026-08
750 penalty unitsper day of contravention for a company missing the annual report. A court may order up to five times the maximum against a body corporate2026-08

The Act prices each obligation separately rather than setting one ceiling. Failing to adopt and maintain a critical infrastructure risk management programme attracts up to 200 penalty units; missing the annual report attracts 750 units per day of contravention for a company. Where the contravener is a body corporate a court may order up to five times the maximum.

The value of a penalty unit is indexed periodically, so the dollar equivalent of each figure moves.

Uncapped exposure that sits outside this instrument

These come from company law rather than from SOCI Act, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for SOCI Act,
not configured for it afterwards

Policy Template

Critical Infrastructure Monitoring

Comprehensive logging for Australian critical infrastructure databases

Report

SOCI Incident Report

72-hour compliant incident documentation for ASD reporting

Classification

Critical Asset Data

Identify data supporting critical infrastructure operations

Alert

Cyber Incident Detection

Real-time detection for 72-hour reporting compliance

Walk into the SOCI Act audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment