Advisory

SOCI Act Compliance

Gap assessments, risk management program reviews and security testing for critical infrastructure entities under the SOCI Act.

Know your duties. Close the gaps.

The SOCI Act places a different mix of duties on each class of critical infrastructure asset. Vectra helps responsible entities work out which duties apply, check their risk management program against the Rules and close the gaps. We cover the cyber and information security side, from framework uplift to SCADA security reviews and penetration testing, and we help you build the evidence your board needs to approve the annual report. Our team holds the specialist certifications this work needs.

SOCI Act Compliance

New enhanced rules for nine asset classes.

In June 2026 the Minister for Home Affairs made new rules that add enhanced requirements to the risk management program. They apply to critical electricity, energy market operator, gas, liquid fuel, water, broadcasting, domain name system, freight infrastructure and freight services assets.

These entities must meet both the baseline and the enhanced rules. We assess where you stand and plan the work to fit the grace periods.

  • A higher framework level

    Comply with a named framework at a higher level, such as the Essential Eight at Maturity Level Two, AESCSF Security Profile 2, AS ISO/IEC 27001:2023 or NIST CSF 2.0.

  • Phishing-resistant MFA

    Where your framework does not require it, use phishing-resistant multi-factor authentication for critical systems and remote access, and log every attempt.

  • Segregated critical systems

    Keep an inventory of critical systems and their links, and segregate them so they can keep running for at least three months while other systems are restored.

  • Patching and legacy systems

    Manage the risk of late patching, unsupported technology and the use of new and emerging technology.

  • Supply chain and people

    Map major suppliers and critical components, set a maximum acceptable outage, and check critical workers through AusCheck or a security clearance.

Your board signs off the program each year.

Responsible entities must report on their risk management program within 90 days after the end of each financial year, with the approval of their board, council or other governing body. We give directors independent evidence to support that approval.

From first review to ongoing assurance.

  1. Step 1: Confirm your duties

    Work out which of your assets are critical infrastructure assets, and which duties apply to each: the register, incident reporting, the risk management program and any enhanced rules.

  2. Step 2: Gap assessment

    Check your program and controls against the Rules across all four hazard types: cyber, personnel, supply chain, and physical and natural.

  3. Step 3: Test

    Review your infrastructure, SCADA systems and application code, and run penetration tests to show how well controls work.

  4. Step 4: Plan

    Rank the gaps by risk and by the grace periods that apply, and agree who fixes what.

  5. Step 5: Put controls in place

    Help you put the right technical and organisational measures in place, including data protection policies.

  6. Step 6: Assure

    Monitor your controls and review the program before each annual report.

SOCI work we run.

SOCI gap assessment

A first review of where you stand against the Act and the Rules, with a clear list of gaps.

Risk management program review

A check that your program identifies material risks across every hazard type and has steps to reduce them.

Cyber framework uplift

Help to meet the framework your program relies on, such as the AESCSF for energy entities or the Essential Eight.

SCADA security review

A review of the control systems that run your physical operations, and how they connect to other systems.

Penetration testing and code review

Tests of your networks, infrastructure and applications, to find weak points before an attacker does.

Ongoing monitoring and assurance

Regular checks so your controls and program keep pace with your assets and the threats.

What you have at the end.

  • A clear map of the SOCI duties that apply to each asset.

  • A ranked list of gaps across all four hazard types.

  • A plan to meet any enhanced rules within their grace periods.

  • Evidence to support your board's approval of the annual report.

  • Tested controls across your IT, OT and SCADA systems.

SOCI Act questions, answered.

Does the SOCI Act apply to us?

The Act covers 11 sectors, but the duties depend on the class of asset you own or run. Each class carries a different mix of duties, such as registering the asset, reporting cyber incidents and keeping a risk management program. We help you confirm where you stand.

What does the risk management program cover?

It covers all hazards, not only cyber. The Rules name four types: cyber and information security, personnel, supply chain, and physical and natural hazards. You must identify material risks and, as far as reasonably practicable, reduce or remove them.

When do the 2026 enhanced rules apply?

The rules took effect in June 2026. Some requirements apply after a 12-month grace period and most after 24 months. For assets that become critical infrastructure later, the periods run from that date.

How do cyber incidents need to be reported?

Incidents with a significant impact must be reported to ASD's ACSC within 12 hours of becoming aware of them. Incidents with a relevant impact must be reported within 72 hours. We can check that your team can detect incidents and report them in time.

Start with a conversation.

Speak to us about your cyber governance and compliance requirements.