
Short answer: The SOCI Act CIRMP is a written critical infrastructure risk management program that Australian responsible entities for certain asset classes must maintain. It identifies and minimises material risks across cyber, personnel, supply chain and physical hazards, requires an annual board-approved report, and pushes security expectations down to suppliers such as SaaS, health technology and managed service providers.
Related guides:
Key takeaways
- The Security of Critical Infrastructure Act 2018 (SOCI Act) is administered by the Cyber and Infrastructure Security Centre (CISC) within the Department of Home Affairs, and now spans 11 sectors after amendments in 2021 and 2022.
- A CIRMP must address four hazard domains: cyber and information security, personnel, supply chain, and physical security and natural hazards.
- The cyber part of the program must comply with a recognised framework such as ISO/IEC 27001, the Essential Eight at Maturity Level One, NIST CSF, C2M2 at MIL1, AESCSF Security Profile 1, or an equivalent.
- Suppliers are not usually responsible entities themselves, but they are a named hazard in the program, so they should expect contract clauses, questionnaires and evidence requests.
What is the SOCI Act and who does it cover?
The SOCI Act is Australia's main law for protecting critical infrastructure, and it places obligations on the owners and operators of assets whose disruption would seriously affect the economy, security or community.
It started in 2018 with a narrow focus on electricity, gas, water and ports. Amendments in 2021 and 2022 broadened it to 11 sectors:
- Communications
- Data storage or processing
- Defence industry
- Energy
- Financial services and markets
- Food and grocery
- Health care and medical
- Higher education and research
- Space technology
- Transport
- Water and sewerage
The 2021 amendments extended the asset register and mandatory cyber incident reporting obligations across the new sectors, and the 2022 amendments added the risk management program obligation and the enhanced cyber security obligations for Systems of National Significance. The Cyber and Infrastructure Security Centre (CISC), part of the Department of Home Affairs, administers the regime and publishes guidance for each obligation.
Obligations attach to specific asset classes rather than whole sectors. A private clinic is not automatically in scope, but a hospital meeting the critical hospital definition is. The entity legally accountable for an asset is the responsible entity, and the CIRMP obligation lands on it.
In late 2024, the Cyber Security Legislative Package passed Parliament. It introduced a standalone Cyber Security Act and made further changes to the SOCI Act, including clarifications around data storage systems and the government's powers to manage the consequences of incidents. Check CISC guidance for how those reforms apply to your asset class.
What does a CIRMP have to include?
A CIRMP is a written program that identifies hazards with a material risk of affecting the availability, integrity, reliability or confidentiality of the asset, and sets out how the entity minimises or eliminates those risks.
The Security of Critical Infrastructure (Critical infrastructure risk management program) Rules 2023 commenced on 17 February 2023. Entities had until 17 August 2023 to adopt a program, and until 17 August 2024 to comply with a recognised cyber security framework. The rules are principles based rather than a control list. The program must:
- Identify material risks for each hazard domain, including the interdependencies between the asset and other critical infrastructure.
- Minimise or eliminate those risks as far as reasonably practicable, and mitigate the impact if a hazard does occur.
- Name accountable people who are responsible for developing, implementing and reviewing the program.
- Describe a review process so the program stays current, including after significant changes or incidents.
- Support an annual report to CISC confirming whether the program was up to date, approved by the board, council or other governing body.
Board approval gives the CIRMP real weight: directors will want evidence behind their attestation, which is hard to produce from scattered spreadsheets.
The four CIRMP hazard domains: controls and supplier evidence
Each CIRMP must cover four hazard domains, and each one has a natural set of controls and a matching set of evidence you can reasonably ask suppliers to provide.
| Hazard domain | What the program must address | Example controls | Evidence a supplier might be asked for |
|---|---|---|---|
| Cyber and information security | Unauthorised access, interference or compromise of systems and data supporting the asset | Recognised framework compliance, MFA, patching, logging, backups, incident response plan | ISO/IEC 27001 certificate and Statement of Applicability, SOC 2 report, Essential Eight self-assessment, penetration test summary, incident notification terms |
| Personnel | Risks from critical workers who could cause significant harm through negligence or malice | Identifying critical positions, background checks, access reviews, offboarding procedures | Background screening policy, joiner/mover/leaver process, privileged access review records |
| Supply chain | Unauthorised access through suppliers, misuse of privileged access, disruption, and over-reliance on particular suppliers | Supplier tiering, security clauses in contracts, ongoing monitoring, exit and continuity plans | Security questionnaire responses, list of subprocessors and hosting locations, business continuity and disaster recovery test results |
| Physical security and natural hazards | Unauthorised physical access to critical sites and components, plus fire, flood, storms and similar events | Access control for critical areas, environmental protections, site redundancy, emergency response plans | Data centre attestations, hosting region redundancy details, BCP covering natural hazard scenarios |
Much of this evidence already exists if you hold a mainstream security attestation. The gap is usually supply chain specifics such as fourth parties, data location and concentration risk.
Which cyber framework satisfies the CIRMP rules?
The cyber and information security domain requires the responsible entity to comply with one of a set of recognised frameworks, or an equivalent, and the choice usually follows the sector the entity sits in.
The frameworks named in the rules include:
- ISO/IEC 27001, the international standard for an information security management system.
- The Essential Eight from the Australian Signals Directorate, at Maturity Level One.
- NIST Cybersecurity Framework (CSF) from the US National Institute of Standards and Technology.
- Cybersecurity Capability Maturity Model (C2M2) at Maturity Indicator Level 1 (MIL1).
- Australian Energy Sector Cyber Security Framework (AESCSF) at Security Profile 1.
An equivalent framework is acceptable if the entity can justify the equivalence. Energy operators often choose AESCSF or C2M2, which were built around operational technology, while health services often use the Essential Eight or ISO/IEC 27001. If you are working towards the Essential Eight, our Essential 8 maturity guide explains what Maturity Level One looks like in practice.
For suppliers, the practical question is which framework your customer chose. An Essential Eight customer will ask about application control, patching and MFA; an ISO/IEC 27001 customer will look for Annex A alignment. Mapping your controls to several frameworks avoids rebuilding answers for each customer.
What other SOCI Act obligations sit alongside the CIRMP?
The CIRMP is one of several positive security obligations, and responsible entities typically manage them together.
Register of Critical Infrastructure Assets. Responsible entities and direct interest holders must give CISC operational and ownership information about their assets, and keep it current when things change. This includes details that often involve suppliers, such as who operates or maintains parts of the asset.
Mandatory cyber incident reporting. Entities must report cyber security incidents affecting their assets to the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC):
- Within 12 hours of becoming aware of a critical cyber security incident that has had, or is having, a significant impact on the availability of the asset. This report can be made orally, but an oral report must be followed by a written report within 84 hours.
- Within 72 hours of becoming aware of any other cyber security incident that has had, is having, or is likely to have a relevant impact on the asset. An oral report must be followed by a written report within 48 hours.
Those clocks only work if suppliers notify the entity quickly, so notification terms in supplier contracts matter.
Enhanced cyber security obligations. A smaller group of assets can be declared Systems of National Significance. These can be required to take on additional obligations, such as maintaining cyber incident response plans, running cyber security exercises, undergoing vulnerability assessments and providing system information to the government.
Why suppliers to critical infrastructure are pulled into scope
Suppliers are rarely responsible entities in their own right, but the supply chain hazard domain means responsible entities must understand and manage the risk that each material supplier introduces.
This matters in health care. Hospitals are a critical infrastructure asset class, and each depends on vendors such as electronic medical record platforms, imaging and pathology systems, patient apps, cloud hosting and outsourced IT. Any of them can become a pathway into the hospital or a single point of failure.
Responsible entities usually respond in three ways:
- Tiering suppliers by how critical they are to the asset, so the deepest scrutiny goes to vendors with privileged access or operational dependency. A structured vendor tiering model makes that defensible to the board.
- Updating contracts with security requirements, incident notification timeframes that support the 12 and 72 hour reporting windows, rights to request evidence, and data location commitments.
- Monitoring over time, rather than relying on a single onboarding questionnaire. Our guide to TPRM supply chain security covers ongoing monitoring approaches.
For SaaS and health technology companies, answering a CIRMP-driven review quickly with credible evidence also shortens procurement cycles.
Supplier checklist: getting ready for a CIRMP review
Assume your customer will ask about all four hazard domains, and have evidence ready before the questionnaire arrives.
Cyber and information security
- Identify which recognised framework your key customers use and map your controls to it.
- Keep a current attestation or certificate, such as ISO/IEC 27001 or a SOC 2 report, plus a summary of your latest penetration test.
- Document MFA coverage, patching timelines and backup testing.
- Maintain an incident response plan with a customer notification step fast enough to support a 12 hour reporting window.
Personnel
- Define which roles have privileged or production access and apply screening to them.
- Run periodic access reviews and keep the records.
- Show that offboarding removes access promptly.
Supply chain
- Publish or be ready to share your subprocessor list, including hosting providers and data locations.
- Explain how you assess your own critical vendors, since your fourth parties are your customer's risk too.
- Describe dependencies that could create concentration risk, and your fallback options.
Physical security and natural hazards
- Collect attestations from your data centre or cloud providers.
- Document redundancy across regions or availability zones.
- Test your business continuity and disaster recovery plans and keep the results.
How SecureSlate helps
SecureSlate gives responsible entities and their suppliers one place to manage the work behind a CIRMP. A single control library lets you map controls across frameworks such as ISO/IEC 27001 and the Essential Eight, while automated evidence collection from your cloud and SaaS stack keeps proof current instead of rebuilt each year. The risk register helps you record hazards and treatments by domain, and policy templates cover areas such as access control, incident response and supplier management.
For supply chain risk, vendor risk management lets you tier suppliers, send questionnaires and track remediation. Suppliers can answer customer reviews with audit-ready exports and a trust center. SecureSlate helps you map and track your controls and evidence; your CIRMP and board attestation remain your organisation's responsibility.
Start your free SecureSlate trial
FAQ
Does the SOCI Act CIRMP apply to my SaaS company?
Usually not directly, unless your company is itself the responsible entity for a critical infrastructure asset, such as certain data storage or processing assets. More commonly, the obligation applies to your customers, who must manage supply chain risk and will ask you for evidence through contracts and security reviews.
Who approves the annual CIRMP report?
The annual report must be approved by the responsible entity's board, council or other governing body. That approval is an attestation about whether the program was up to date, so directors will expect supporting evidence rather than a summary slide.
Is the Essential Eight enough for CIRMP cyber compliance?
The Essential Eight at Maturity Level One is one of the recognised frameworks in the CIRMP rules, so it can satisfy the cyber and information security requirement. The program still needs to address personnel, supply chain and physical hazards separately, since the framework only covers the cyber domain.
How fast must cyber incidents be reported under the SOCI Act?
Critical cyber security incidents with a significant impact on the asset must be reported to ASD's ACSC within 12 hours of becoming aware. Other incidents with a relevant impact must be reported within 72 hours. If either report is made orally, a written report must follow within 84 hours or 48 hours respectively. Suppliers should agree notification timeframes with customers that make those windows achievable.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds
