The Security of Critical Infrastructure Act 2018, as substantially amended in 2022, represents the most significant expansion of Australian cyber security regulation since the Privacy Act amendments of 2012. The SOCI Act 2022 extended mandatory obligations from four sectors (electricity, gas, water, ports) to eleven critical infrastructure sectors, introduced mandatory Critical Infrastructure Risk Management Programmes (CIRMPs), created government intervention powers for cyber incidents, and established enhanced cyber security obligations — including mandatory cyber security incident reporting within 12 hours and government assistance powers in the event of a significant cyber attack. For organisations operating in affected sectors, the SOCI Act 2022 is not a compliance framework to file and forget — it creates ongoing operational obligations, including explicit requirements for testing the effectiveness of cyber security controls.
What Is the SOCI Act and Which Sectors Does It Cover?
The Security of Critical Infrastructure Act 2022 covers eleven critical infrastructure sectors in Australia — defined as assets whose disruption would have severe consequences for Australia's economy, security, or sovereignty:
Communications — telecommunications networks, internet infrastructure, broadcasting
Data storage and processing — government data hosting, commercial cloud infrastructure processing sensitive government data
Defence industry — defence contractors and suppliers
Education and research — universities with critical research functions
Energy — electricity generation and distribution, gas, liquid fuels
Food and grocery — major supermarket supply chain operators
Health — hospitals, pathology, pharmaceutical supply chain
Space technology — satellite operations and ground infrastructure
Transport — airports, ports, rail, road, freight
Water and sewerage — drinking water systems, wastewater treatment
Responsible entities in these sectors must register their critical infrastructure assets with the Department of Home Affairs and comply with obligations proportionate to their risk classification.
What Cyber Security Testing Does the SOCI Act Require?
Risk management programme testing — SOCI Act requires a Critical Infrastructure Risk Management Programme (CIRMP) that identifies and manages risks to critical infrastructure. The CIRMP must include testing of controls implemented to manage those risks — particularly cyber security controls — and must be reviewed annually
Incident detection capability testing — verifying that the organisation's monitoring and detection systems can identify and alert on intrusion attempts, malware, lateral movement, and data exfiltration within operationally relevant timeframes
Incident response exercise testing — tabletop and technical exercises that test the organisation's ability to respond to a cyber incident, including escalation, containment, and notification to the Australian Cyber Security Centre (ACSC) within the 12-hour mandatory reporting window
Backup and recovery testing — demonstrating that critical systems can be restored from backup within documented recovery time objectives (RTOs) following a ransomware or destructive attack
Supply chain and third-party testing — verifying that third-party suppliers and managed service providers with access to critical infrastructure systems meet equivalent cyber security standards
Penetration testing of operational technology (OT) — testing the cyber security of industrial control systems (ICS), SCADA systems, and operational technology networks, which have unique characteristics and vulnerabilities distinct from IT environments
Enhanced obligation compliance testing — for systems identified as Systems of National Significance (SoNS), additional testing obligations apply, including government-directed vulnerability assessments and mandatory participation in cyber security exercises
SOCI Act security testing must cover both IT and operational technology (OT) environments — SCADA systems, industrial control networks, and critical physical infrastructure that have fundamentally different security characteristics from standard enterprise IT.
SOCI Act Risk Management Programme: What Must the CIRMP Include?
The Critical Infrastructure Risk Management Programme (CIRMP) is the centrepiece of SOCI Act compliance. It must be a written programme identifying all hazards — cyber, physical, personnel, supply chain, and natural — and documenting the controls implemented to manage each risk. For cyber security, the CIRMP must specifically include:
Identification of critical systems, data, and networks that support the infrastructure asset
Risk assessment of cyber threats that could disrupt the asset
Documentation of cyber security controls implemented for each identified risk
Testing and review processes to verify control effectiveness
Annual board or governance body review and attestation
Annual compliance report submitted to the Department of Home Affairs within 90 days of financial year end
The annual board review requirement means cyber security testing results — penetration test findings, Essential 8 scores, backup restoration evidence — must be documented in a form that executives and board members can review and formally attest to.
“
Our SOCI Act compliance programme was in its infancy when we engaged KiwiQA. They helped us map our critical infrastructure assets to the CIRMP obligations, identify the specific cyber security controls we needed to test, and design a testing programme that would produce board-ready evidence for our annual compliance report. Their OT security testing capability was particularly valuable — most security firms we spoke to understood IT but had limited experience with SCADA and ICS environments. KiwiQA's team worked effectively with our operations engineers and understood the operational constraints around testing live infrastructure.
E
Head of Cyber Security
Energy & Utilities Organisation, Victoria
SOCI Act vs Essential 8 vs ISO 27001: How the Frameworks Fit Together
The three frameworks are complementary, not competing. Understanding how they interrelate is key to an efficient compliance testing programme:
SOCI Act — the legislation. Creates mandatory CIRMP, incident reporting, and (for Systems of National Significance) enhanced cyber security obligations. Outcome-focused: it does not prescribe specific technical controls, but requires demonstrated risk management
ACSC Essential 8 — the technical control baseline. Strongly recommended for all SOCI Act entities as the minimum cyber security standard. Regulators and government stakeholders expect to see Essential 8 evidence as part of SOCI compliance. For Systems of National Significance, government can direct Essential 8 implementation
ISO 27001 — the governance framework. An ISMS structured around ISO 27001 provides the management architecture within which SOCI Act risk programmes and Essential 8 controls sit. ISO 27001 certification signals systematic security management capability to regulators, clients, and insurers
In practice, most large critical infrastructure operators use ISO 27001 as their governance foundation, Essential 8 testing as their primary control assurance evidence, and SOCI Act CIRMP documentation as their regulatory reporting layer — three frameworks, one cohesive programme.
KiwiQA SOCI Act Security Testing: KiwiQA provides cyber security testing for Australian critical infrastructure operators across energy, water, transport, and telecommunications sectors. Our team has experience with both IT and OT security testing, Essential 8 assessments, penetration testing, and CIRMP control effectiveness testing — producing board-ready reports that satisfy SOCI Act annual compliance obligations. Explore KiwiQA Security Testing →
Building a SOCI-Compliant Cyber Security Testing Programme: Key Steps
Step 1 — Asset and system identification: Map all systems, data stores, networks, and third-party connections that support your critical infrastructure asset. This asset register forms the foundation of your CIRMP.
Step 2 — Risk and threat assessment: Identify relevant cyber threats (ransomware, nation-state intrusion, insider threat, supply chain compromise) and assess their likelihood and consequence for each critical system.
Step 3 — Control implementation and documentation: Document the cyber security controls implemented for each identified risk, including detection, prevention, and response controls across IT and OT environments.
Step 4 — Control effectiveness testing: Conduct structured testing to verify that each documented control actually works as intended — penetration testing, Essential 8 assessment, backup restoration testing, detection capability testing.
Step 5 — Incident response exercise: Conduct at least one tabletop exercise and one technical exercise annually that tests your organisation's ability to detect, respond to, and report a cyber incident — including the 12-hour ACSC notification timeline.
Step 6 — Annual CIRMP review and board reporting: Present testing results, control effectiveness evidence, and risk posture assessment to the board or equivalent governance body for annual attestation.
Step 7 — Home Affairs compliance report: Submit the annual compliance report to the Department of Home Affairs within 90 days of financial year end, including attestation that the CIRMP has been reviewed and implemented.
KiwiQA works with Australian critical infrastructure operators across energy, water, transport, and communications sectors to build and execute cyber security testing programmes that meet SOCI Act CIRMP obligations. Our security engineers understand both the regulatory requirements of the SOCI Act and the technical complexities of testing in OT and ICS environments where downtime and disruption risk must be carefully managed. Explore KiwiQA's security testing capability at kiwiqa.ai/security, or speak with our team about your SOCI Act compliance testing requirements.
Need board-ready evidence for your SOCI Act annual compliance report? KiwiQA's critical infrastructure security team delivers penetration testing, Essential 8 assessments, OT security testing, and CIRMP control effectiveness testing — producing the documented evidence that boards, executives, and the Department of Home Affairs need to see. Talk to KiwiQA about SOCI Act testing →
Frequently Asked Questions
Enjoyed this? Explore more below.
In this article
What Is the SOCI Act and Which Sectors Does It Cover?
What Cyber Security Testing Does the SOCI Act Require?
SOCI Act Risk Management Programme: What Must the CIRMP Include?
SOCI Act vs Essential 8 vs ISO 27001: How the Frameworks Fit Together
Building a SOCI-Compliant Cyber Security Testing Programme: Key Steps