24 July 2026
SOCI Act & CIRMP: A Compliance Guide for Responsible Entities
A practical guide for Australian responsible entities on the Security of Critical Infrastructure (SOCI) Act 2018 and Critical Infrastructure Risk Management Program (CIRMP) obligations — scope, hazards, reporting timelines and how to align with ACSC ISM and Essential Eight.
The Security of Critical Infrastructure Act 2018 (SOCI Act) has evolved from a narrow reporting regime into one of the most consequential cyber and operational-resilience laws in Australia. If you are a responsible entity for a critical infrastructure asset, the Critical Infrastructure Risk Management Program (CIRMP) obligations are no longer optional — they are enforceable, auditable, and increasingly under Home Affairs scrutiny.
Who is a "Responsible Entity"?
The SOCI Act applies to 11 critical infrastructure sectors — communications, financial services and markets, data storage or processing, defence, higher education and research, energy, food and grocery, health care and medical, space technology, transport, and water and sewerage. If your organisation owns or operates an asset within these sectors, you are likely a responsible entity and CIRMP applies.
What CIRMP Requires
The CIRMP rules (in force since August 2023) require responsible entities to establish, maintain and comply with a written risk management program that addresses four hazard categories:
- Cyber and information security hazards — aligned to an approved cyber framework such as ACSC Essential Eight ML1, ISO/IEC 27001, NIST CSF, or AESCSF.
- Personnel hazards — insider threat, screening, and access management.
- Supply chain hazards — third-party risk, foreign ownership, and vendor concentration.
- Physical and natural hazards — site security, environmental resilience and business continuity.
Reporting Timelines You Cannot Miss
- Critical cyber incidents: notify ASD within 12 hours.
- Other cyber incidents: notify ASD within 72 hours.
- Annual CIRMP report: board-approved and submitted to the Cyber and Infrastructure Security Centre (CISC) within 90 days of the financial-year end.
How to Align CIRMP with ISM and Essential Eight
The cyber hazard section is where most responsible entities focus first — and where CIRMP overlaps significantly with the ACSC ISM and Essential Eight. A pragmatic path is:
- Adopt Essential Eight ML1 (or higher) as the base cyber framework declared in CIRMP.
- Map ISM controls to the CIRMP hazard categories to avoid duplicate uplift.
- Automate evidence collection so annual attestation is a byproduct of daily operations, not a Q4 fire drill.
- Bring the board into the loop early — CIRMP requires board approval, not just IT sign-off.
Enhanced Cyber Security Obligations (ECSO)
For Systems of National Significance (SoNS), the Minister can impose additional obligations — vulnerability assessments, incident-response planning, cyber-security exercises, and system-information reporting. If your organisation has been designated a SoNS, ECSO obligations layer on top of CIRMP.
What Good Looks Like
Responsible entities that treat CIRMP as a governance program — rather than a paperwork exercise — end up with three durable outcomes: a defensible risk register mapped to CISC's hazard taxonomy, a live evidence pipeline that shortens audit prep from weeks to days, and a board that understands cyber risk in the same language as financial and operational risk.
Where to Start
If you are new to CIRMP, the fastest way in is a gap assessment against the four hazard categories, using your existing ISM or ISO 27001 controls as the starting point. That gives you a defensible baseline, a prioritised uplift plan, and enough evidence to prepare the annual report with confidence.
Need help scoping a CIRMP program or preparing the annual attestation? Book a scoping call.