SOCI gap assessment
A first review of where you stand against the Act and the Rules, with a clear list of gaps.
Gap assessments, risk management program reviews and security testing for critical infrastructure entities under the SOCI Act.
The SOCI Act places a different mix of duties on each class of critical infrastructure asset. Vectra helps responsible entities work out which duties apply, check their risk management program against the Rules and close the gaps. We cover the cyber and information security side, from framework uplift to SCADA security reviews and penetration testing, and we help you build the evidence your board needs to approve the annual report. Our team holds the specialist certifications this work needs.
In June 2026 the Minister for Home Affairs made new rules that add enhanced requirements to the risk management program. They apply to critical electricity, energy market operator, gas, liquid fuel, water, broadcasting, domain name system, freight infrastructure and freight services assets.
These entities must meet both the baseline and the enhanced rules. We assess where you stand and plan the work to fit the grace periods.
Comply with a named framework at a higher level, such as the Essential Eight at Maturity Level Two, AESCSF Security Profile 2, AS ISO/IEC 27001:2023 or NIST CSF 2.0.
Where your framework does not require it, use phishing-resistant multi-factor authentication for critical systems and remote access, and log every attempt.
Keep an inventory of critical systems and their links, and segregate them so they can keep running for at least three months while other systems are restored.
Manage the risk of late patching, unsupported technology and the use of new and emerging technology.
Map major suppliers and critical components, set a maximum acceptable outage, and check critical workers through AusCheck or a security clearance.
Your board signs off the program each year.
Responsible entities must report on their risk management program within 90 days after the end of each financial year, with the approval of their board, council or other governing body. We give directors independent evidence to support that approval.
Work out which of your assets are critical infrastructure assets, and which duties apply to each: the register, incident reporting, the risk management program and any enhanced rules.
Check your program and controls against the Rules across all four hazard types: cyber, personnel, supply chain, and physical and natural.
Review your infrastructure, SCADA systems and application code, and run penetration tests to show how well controls work.
Rank the gaps by risk and by the grace periods that apply, and agree who fixes what.
Help you put the right technical and organisational measures in place, including data protection policies.
Monitor your controls and review the program before each annual report.
A first review of where you stand against the Act and the Rules, with a clear list of gaps.
A check that your program identifies material risks across every hazard type and has steps to reduce them.
Help to meet the framework your program relies on, such as the AESCSF for energy entities or the Essential Eight.
A review of the control systems that run your physical operations, and how they connect to other systems.
Tests of your networks, infrastructure and applications, to find weak points before an attacker does.
Regular checks so your controls and program keep pace with your assets and the threats.
A clear map of the SOCI duties that apply to each asset.
A ranked list of gaps across all four hazard types.
A plan to meet any enhanced rules within their grace periods.
Evidence to support your board's approval of the annual report.
Tested controls across your IT, OT and SCADA systems.
The Act covers 11 sectors, but the duties depend on the class of asset you own or run. Each class carries a different mix of duties, such as registering the asset, reporting cyber incidents and keeping a risk management program. We help you confirm where you stand.
It covers all hazards, not only cyber. The Rules name four types: cyber and information security, personnel, supply chain, and physical and natural hazards. You must identify material risks and, as far as reasonably practicable, reduce or remove them.
The rules took effect in June 2026. Some requirements apply after a 12-month grace period and most after 24 months. For assets that become critical infrastructure later, the periods run from that date.
Incidents with a significant impact must be reported to ASD's ACSC within 12 hours of becoming aware of them. Incidents with a relevant impact must be reported within 72 hours. We can check that your team can detect incidents and report them in time.
Speak to us about your cyber governance and compliance requirements.