Business Insight

Streamline and Modernise: An Overview of the SOCI Act 'Tranche 2' Reforms 

Infrastructure_8_Insight_960x677

    What you need to know

    • The Department of Home Affairs has recently closed its public consultation on proposed 'Tranche 2' reforms to the Security of Critical Infrastructure Act 2018, comprising 21 measures aimed at streamlining, refining and modernising the Act's underlying architecture.
    • The reforms follow an independent review in January 2026, which found that while the Act had laid a strong foundation for safeguarding critical assets, it would benefit from modernisation, reduced complexity and clearer expectations to address an evolving threat environment.
    • The 21 measures span three key objectives: reducing complexity, duplication and uncertainty; modernising sector and asset coverage; and strengthening governance, assurance and accountability.

    What you need to do

    • Familiarise yourself with the consultation paper and consider potential implications, exposures and increased compliance obligations that may apply to your organisation, particularly if you have existing SOCI obligations.
    • Assess whether the proposed new or expanded asset classes could bring your operations within scope of the SOCI Act for the first time.

    Background

    On 31 July 2026 the Department of Home Affairs closed its public consultation on proposed amendments to the Security of Critical Infrastructure Act 2018 (SOCI Act).

    These proposed reforms are a result of the independent review of the SOCI Act delivered by Dr Jill Slay AM in January 2026. Dr Slay's review found that while the SOCI Act had laid a strong foundation for safeguarding Australia's most critical assets, it would benefit from modernisation, reduced complexity, clearer expectations and ongoing legislative refinement to address an evolving threat environment.

    In response, the Department published its consultation paper accepting the six overarching recommendations made in Dr Slay's review, and proposed to implement reforms in two key tranches.

    Tranche 1, addressing immediate risk and intervention powers, is progressing through the introduction of enhancements to the Critical Infrastructure Risk Management Program Rules (Enhanced CIRMP Rules) and consultation on the Ministerial Directions framework in Part 3 of the SOCI Act.

    Tranche 2, the key focus of the consultation paper, comprises 21 measures aimed at streamlining, refining and modernising the SOCI Act’s underlying architecture.

    Key Objectives

    The Tranche 2 reforms are structured around the following key objectives:

    A) reducing complexity, duplication and uncertainty;

    B) modernising and refining sector and asset coverage; and

    C) governance, assurance and accountability.

    The table below outlines each measure, its key objectives, and intended impacts:

    Part A – Reducing Complexity, Duplication and Uncertainty

    Measure Key ObjectivesAim
    Measure 1 – Exemptions Framework
    • Clearer exemptions framework.
    • Providing targeted relief where an equivalent law or framework exists.
    Reducing duplication of obligations or requirements from equivalent frameworks.  
    Measure 2 – Register of Critical Infrastructure Assets  
    • Restructuring of Part 2 of the SOCI Act
    • Intent to capture broad categories of registrable information.
    • Detailed information items to be left to be prescribed in the SOCI Rules.
    Simplifying administration, reporting and notification.
    Measure 3 – CIRMP Annual Reporting Simplification
    • Replacement of current annual reporting framework with simpler obligation of submitting an annual compliance report in approved form.
    • Tailored by entity, asset or obligation.
    Measure 4 – Notification clarification for enhanced requirements for critical telco assets

    Clarification that:

    • the Secretary's notice under Part 2D – Enhanced security regulation for critical telecommunications assets is a point-in-time assessment; and
    • that later material changes may require further notification.
    Measure 5 – Cyber Security Incident Definition: Automated Systems, Software Agents and AI
    • Refined definition of "cyber security incident" to clearly operate where automation, software agents or AI-enabled tools affect mechanism, attribution or operation of a cyber incident.
    • Preserve thresholds under Part 2B – Notification of cyber security incidents.
    Measure 6 – Systems of National Significance
    • Several measures to simplify Systems of National Significance framework so designation has clearer, asset-specific requirements, and practical consequences for the declared asset.
    Simplifying to focus enhanced-obligations on preparedness, continuity, recovery and restoration.
    Measure 7 – Subsea Telecommunications Cables and Associated Infrastructure
    • Refine asset framework for nationally significant submarine cable systems.
    Clarifying uncertain asset boundaries.
    Measure 8 – Data Storage or Processing
    • Replace customer-driven capture model with operator-facing pathways.
    • Intended to cover significant data-centre facilities, larger service-layer providers, certified hosting providers and some exceptional government-dependent cases.

    Part B – Modernising and Refining Sector and Asset Coverage

    MeasureKey ObjectivesAim
    Measure 9 – Space Technology
    • Establish four key asset classes.
    • Operative thresholds, specified assets, requirements and exclusions to be developed later through SOCI Rules consultation.
    Giving effect to the sector, which currently has no operative asset classes.
    Measure 10 – Health Care and Medical Sector
    • Apply risk-management obligations more consistently to critical hospitals.
    • New asset classes for concentrated and systemically significant blood supply, pathology, and high-containment or specialised laboratory functions.
    Increasing concentrated focus on systemically significant functions.
    Measure 11 – Distributed Energy Resources
    • Update electricity framework to cover storage, DER portfolios, controllable demand, aggregation, orchestration and dispatch arrangements.
    • Thresholds for these assets to be captured in SOCI Rules.
    Clarifying requirements beyond traditional electricity assets.
    Measure 12 – Offshore Electricity Assets
    • Disapply geographic limitation for critical electricity assets in Commonwealth offshore areas.
    • Offshore assets will still need to meet critical electricity asset definition and SOCI Rules thresholds before SOCI obligations apply.
    Preventing exclusion of offshore electricity infrastructure from location settings.
    Measure 13 – Critical Freight
    • Broaden freight framework to cover nationally significant nodes, interfaces, logistics platforms, and discrete chokepoints.
    • Clarify existing obligations.
    Broadening and clarifying critical freight framework.
    Measure 14 – Higher Education and Research
    • Replace critical education asset class with critical research asset class focused on organised research functions.
    Refining and clarifying definition, which is currently limited in scope.  

    Part C – Governance, Assurance and Accountability

    MeasureKey ObjectivesAim
    Measure 15 – CIRMP Governance and Assurance
    • Clarify governance/review obligations.
    • Introduce proportionate independent assurance of CIRMP effectiveness.
    Clarifying obligations and evidence requirements for CIRMPs.
    Measure 16 – Graduated Civil Penalty Settings
    • Increase maximum penalty for preventive/assurance obligations from $72,800 to $182,000.
    Improve deterrence and preserve graduated penalty structure.
    Measure 17 – Operations and Maintenance Managed Service Providers
    • Introduce relevant operator concept for entities with material practical control over an asset or critical function.
    • Require targeted registration and limited direct duties to cooperate/notify.
    Preserve responsible entity model and address risks that sit outside current ownership and direct-interest concepts.
    Measure 18 – Corporate Group Cooperation
    • Limited cooperation duty for connected corporate-group entities where responsible entity depends on them for CIRMP compliance.
    Encourage and facilitate compliance for responsible entities within corporate groups.
    Measure 19 – Supply Chain Cyber Security Assurance  
    • Clarify CIRMP expectations for cyber security assurance of major suppliers.
    Assist responsible entities with assessing and managing cyber risks.
    Measure 20 – Specified Risk Information
    • Mechanism for Secretary to specify published risk, hazard, standards or guidance material for CIRMP processes.
    • Responsible entities to consider, assess relevance and document response.  
    Clearer documented consideration of CIRMP obligations.
    Measure 21 – Critical Workers and Critical Components
    • Replace current definition of "critical worker" with access-based/authority-based model.
    • SOCI Rules may create categories of "critical workers" with proportionate requirements.

    Clarify application of definition and broader framework.

    Progress of Legislative Amendments

    The Department is currently considering submissions that were made during the consultation period, after which it is likely that a legislative exposure draft or draft Bill will follow.

    The timeline for the enactment of the Enhanced CIRMP Rules as part of Tranche 1 was relatively short: an initial draft consultation paper was published in late 2025, an exposure draft consultation followed in early 2026, and the Enhanced CIRMP Rules were finalised and came into force by June 2026.

    If this timeline is indicative, Tranche 2 reforms may become formal legislation in as soon as six months' time.

    What now?

    We will release further publications exploring these reforms in greater depth, including issues we have identified as likely to present imminent compliance challenges or uplift obligations.

    In the meantime, we recommend that entities with existing SOCI obligations familiarise themselves with the measures outlined above and consider the potential implications, exposures and increased compliance obligations that may apply to them.

    Authors: Clare Doneley, Partner; John Moore, Director, Risk Advisory; Sanjam Bajwa, Lawyer; Georgina Whittle, Graduate.

    Want to know more?

    This publication is a joint publication from Ashurst Perkins Coie Australia and Ashurst Perkins Coie Risk Advisory Pty Ltd, which are part of the Ashurst Perkins Coie Group.

    Ashurst Perkins Coie Australia (ABN 75 304 286 095) is a general partnership constituted under the laws of the Australian Capital Territory.

    Ashurst Perkins Coie Risk Advisory Pty Ltd is a proprietary company registered in Australia and trading under ABN 74 996 309 133.

    The Ashurst Perkins Coie Group comprises Ashurst Perkins Coie UK LLP, Ashurst Perkins Coie US LLP, Ashurst Perkins Coie Australia and their respective affiliates (including independent local partnerships, companies or other entities) which are authorised to use the name "Ashurst Perkins Coie" or describe themselves as being affiliated with Ashurst Perkins Coie. Some members of the Ashurst Perkins Coie Group are limited liability entities. Some members of the Ashurst Perkins Coie Group provide legal services and some provide non-legal services. Different legal entities in the group may operate in the same jurisdictions. Information about which Ashurst Perkins Coie Group entity operates in any country can be found on our website at www.ashurstperkinscoie.com.

    The services provided by Ashurst Perkins Coie Risk Advisory Pty Ltd do not constitute legal services or legal advice, and are not provided by qualified legal practitioners acting in that capacity. The laws and regulations which govern the provision of legal services in the relevant jurisdiction do not apply to the provision of non-legal services.

    This material is current as at 21 September 2026 but does not take into account any developments after that date. It is not intended to be a comprehensive review of all developments in the law or in practice, or to cover all aspects of those referred to, and does not constitute professional advice. The information provided is general in nature, and does not take into account and is not intended to apply to any specific issues or circumstances. Readers should take independent advice. No part of this publication may be reproduced by any process without prior written permission from Ashurst Perkins Coie. We accept no liability for use of these materials and reliance upon it by any person.