By its Consultation Paper, the Department of Home Affairs is seeking industry feedback on 21 proposed measures aimed at streamlining and modernising the Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act). The proposed reforms follow an Independent Review by Dr Jill Slay AM. The Government accepted all six recommendations of the Independent Review in principle and is progressing the SOCI Act reform program in two tranches. Submissions on tranche 2, which is the focus of the Consultation Paper remain open until 31 July 2026.
The Review's overarching conclusion was that the SOCI Act requires legislative change to reduce complexity, simplify its operation, and move toward a more outcome-driven model focused on measurable improvements in security risk management.
In response, the Government has organised its proposed reforms under three categories:
- modernising and refining sector and asset coverage
- reducing complexity, duplication and uncertainty
- enhancing governance, assurance and accountability.
In this article we touch on some of these measures.
What are some key changes in sector and asset coverage?
Several proposals would bring new assets into scope, or significantly expand existing obligations:
- Space technology - four new asset classes (ground segment, PNT support, earth observation data, space situational awareness) would operationalise the space sector. Thresholds and exclusions would be developed through separate Rules consultation.
- Health care – Critical Infrastructure Risk Management Program (CIRMP) obligations would be applied more consistently to critical hospitals, and new asset classes would be created for significant blood supply, pathology, and nationally significant high-containment/specialised laboratories.
- Electricity - coverage would extend to battery storage, virtual power plants, and DER aggregation and orchestration platforms. The current geographic limitation would also be removed so that critical electricity assets in Commonwealth offshore areas could be captured.
- Freight - coverage would extend to nationally significant freight nodes, logistics platforms, cold chain facilities, chokepoints, and operational technology systems. The asset boundary for critical freight service business would be clarified so that the regulated asset is the entity's own systems, facilities, and operational capabilities rather than public infrastructure it merely uses. The Department is also considering extension to large-scale connected transport systems.
- Research - the 'critical education asset' class would be repealed and replaced with a 'critical research asset' class focused on organised research functions. This class would apply to sensitive research conducted in or outside universities.
In addition:
- Data storage or processing – asset classification would shift from considering customer data being stored or processed as notified by a customer to clearer criteria concerning the provider, in particular:
- data centre facility-based capture, including data centres measured by rated IT load, with 1 MW as a starting point for consultation;
- service-based capture (eg larger cloud, hosted infrastructure, managed hosting, back-up) for larger service-layer providers whose scale and role makes them systemically significant;
- certification-based capture (eg certification under the Commonwealth Hosting Certification Framework); and
- a narrow reserve Ministerial designation for exceptional government dependency.
- Subsea telecommunications cable - the framework for critical telecommunications assets would also be refined to address nationally significant submarine cable systems. The reform would clarify asset boundaries, identify responsible entities by reference to ownership or operation of relevant components rather than carrier status alone, and update the treatment of material cable interests.
What are some of the simplification measures?
Consolidated exemptions framework
The Government proposes a clearer exemptions framework to provide targeted relief from specified SOCI obligations where another law or recognised framework delivers substantially equivalent or stronger outcomes. Relief could be full, partial, conditional, time-limited or subject to review. This replaces the current fragmented, approach and addresses longstanding regulatory-overlap concerns (including with CPS 230 and the Privacy Act).
Register reforms
It is proposed that Part 2 would be restructured so the SOCI Act sets broad categories of registrable information and the Rules prescribe the detailed information items within those categories, supported by a simpler change-notification model. The current Register framework requires responsible entities to provide 'operational information' and direct interest holders to provide 'interest and control information', with updates triggered by an assessment of whether previously submitted information has become incorrect or incomplete. Under the proposed model, the change-notification trigger would be replaced with a clearer obligation to notify changes of a kind prescribed in the Rules. The reformed framework would also expressly support a category of disclosable information for key systems, key suppliers, and material dependencies relevant to the operation, control or continued functioning of the asset.
AI and automation
The definition of 'cyber security incident' in section 12M would be refined so it clearly captures serious incidents where automated systems, software agents, or AI tools are involved in causing or facilitating an incident. Existing Part 2B incident notification thresholds and safeguards (12 hours for critical incidents and 72 hours for other reportable incidents) would be preserved.
Systems of National Significance (SoNS)
The SoNS framework would be simplified so designation has clearer practical consequences for the declared asset.
The proposed changes would mean that:
- incident response planning would be replaced with asset-specific 'resilience planning', with cyber security exercises retained;
- vulnerability assessments would become discretionary and all-hazards;
- the System Information Enhanced Cyber Security Obligation would be repealed; and
- equivalent arrangements would be recognised where they deliver substantially the same outcome.
More streamlined annual reporting
Entities would be required to submit an annual compliance report in an approved form, with questions published in advance and capable of being tailored by entity, asset class, or obligation type. Questions would be limited to matters relating to SOCI compliance, administration, assurance, or enforcement.
Clarified telecommunications change notifications
For critical telecommunications assets, section 30ED notices would be clarified as point-in-time assessments based on the information then available, rather than ongoing 'approvals' for later stages. The reform would also make clear that later or materially different arrangements may require further notification, providing responsible entities with clearer guidance on the continuing notification obligation.
What are some of the additional governance and enforcement measures?
CIRMP governance
In relation to CIRMPs, the Consultation Paper proposes:
- Specified risk information - allowing the Home Affairs Secretary to specify published risk, hazard, standards or guidance material that responsible entities must formally consider through their CIRMP processes. Entities would be required to assess relevance, document their response, and determine whether any update to their CIRMP or controls is needed.
- Review - a review cycle on CIRMPs of no more than 24 months, or more frequently based on event triggers.
- Critical workers – would be re-defined by reference to security-sensitive access, operational authority, access to a critical component (which definition would also be revised), or prescribed roles, and would extend to personnel of relevant operators, managed service providers, and contractors where their role or access meets the statutory criteria.
- Supplier cyber assurances - responsible entities would be expected to assess and manage cyber risks from major suppliers through their CIRMP processes. This would include an assessment of supplier practices, contractual or equivalent measures at appropriate commercial touchpoints, and reliance on recognised certifications where current and relevant. Suppliers would not become directly regulated, but procurement and vendor management frameworks will need to reflect these expectations.
Independent assurance
Responsible entities would be required to obtain proportionate independent assurance of CIRMP design, implementation, and effectiveness on a base cycle of at least every three years. Assurance reports would be provided to both the governing body and the Critical Infrastructure Security Centre (CISC), with remediation plans required where material deficiencies were identified.
Admissibility restrictions removed
Annual compliance reports would be able to be relied on in civil penalty proceedings. Voluntary disclosure, cooperation and timely remediation would remain relevant to compliance and enforcement decision-making, but responsible entities should be aware that statements in annual reports may be used as evidence where relevant to serious or repeated non-compliance, or where a report is materially false, misleading or incomplete.
Higher penalties
Maximum penalties for selected core preventive and assurance duties (eg CIRMP obligations and related compliance) would increase from 200 to 500 penalty units, while lower-tier administrative and visibility obligations, and top-tier penalties, remain unchanged.
Connected entities would have new statutory duties
The Consultation Paper proposes:
- New 'relevant operator' concept - Where third parties exercise material practical control over a critical infrastructure asset or critical function, a new 'relevant operator' category would impose direct statutory obligations. These would consist of registration, cooperation duties, and a prohibition on materially compromising the asset. The responsible entity would remain responsible for is broader SOCI obligations including CIRMP and maintaining arrangements with operators where it depends on them for critical functions. A limited safe harbour is being considered for responsible entities that take reasonable steps to secure appropriate arrangements with a relevant operator but cannot secure them.
- Corporate group cooperation duty - Where a responsible entity materially depends on a connected corporate group entity for CIRMP-critical functions, a statutory cooperation duty would be imposed on the connected entity. Breach would attract a civil penalty, subject to a reasonableness test for foreign law constraints and confidentiality.
Key takeaways from the proposed changes
- New sectors and expanded coverage will bring more entities into scope: Operative asset classes are proposed for space technology, blood supply, pathology, high-containment laboratories, DER aggregation and orchestration platforms, offshore electricity, nationally significant freight nodes, and data centres. A new 'critical research asset' class would replace the current education model.
- Third-party providers face direct statutory obligations for the first time: A new 'relevant operator' concept would impose registration, cooperation, notification, and non-compromise duties directly on third parties exercising material practical control over critical infrastructure assets, alongside a corporate group cooperation duty for connected entities providing CIRMP-critical functions.
- The SOCI Act is shifting to independent assurance and strengthening enforcement powers: The proposed reforms introduce mandatory independent assurance of CIRMPs, board-level approval of CIRMP establishment and review, and the removal of admissibility restrictions so that annual compliance reports can be used in civil penalty proceedings.
What's next?
Submissions close on 31 July 2026 and the Government has indicated it will consider all submissions before finalising legislation. This is the primary opportunity to shape thresholds, boundary definitions, exemption settings, and assurance calibration. A legislative exposure draft or Bill is expected to follow once the consultation is finalised.
While detailed Rules-level thresholds will be subject to later consultation (and the magic will lie in the detail there once known), it's important for entities to consider now the potential impact of the Government's current policy direction and how engagement in this consultation could help shape the ultimate policy settings.
How can we help?
The SOCI Act is maturing into a comprehensive, outcome-focused national security governance framework. The combination of proposed reforms imposing higher penalties, mandatory assurance, and direct obligations creates a more demanding compliance environment. It is important that entities begin to understand their exposure and prepare for ongoing compliance requirements.
MinterEllison provides full-service legal and consultancy services with extensive experience in SOCI compliance, risk governance, privacy and cyber. Please contact us if you would like assistance preparing a submission, understanding your exposure under the proposed reforms, or navigating the new evolving compliance environment.