Streamline and Modernise: An Overview of the SOCI Act 'Tranche 2' Reforms
On 31 July 2026 the Department of Home Affairs closed its public consultation on proposed amendments to the Security of Critical Infrastructure Act 2018 (SOCI Act).
These proposed reforms are a result of the independent review of the SOCI Act delivered by Dr Jill Slay AM in January 2026. Dr Slay's review found that while the SOCI Act had laid a strong foundation for safeguarding Australia's most critical assets, it would benefit from modernisation, reduced complexity, clearer expectations and ongoing legislative refinement to address an evolving threat environment.
In response, the Department published its consultation paper accepting the six overarching recommendations made in Dr Slay's review, and proposed to implement reforms in two key tranches.
Tranche 1, addressing immediate risk and intervention powers, is progressing through the introduction of enhancements to the Critical Infrastructure Risk Management Program Rules (Enhanced CIRMP Rules) and consultation on the Ministerial Directions framework in Part 3 of the SOCI Act.
Tranche 2, the key focus of the consultation paper, comprises 21 measures aimed at streamlining, refining and modernising the SOCI Act’s underlying architecture.
The Tranche 2 reforms are structured around the following key objectives:
A) reducing complexity, duplication and uncertainty;
B) modernising and refining sector and asset coverage; and
C) governance, assurance and accountability.
The table below outlines each measure, its key objectives, and intended impacts:
| Measure | Key Objectives | Aim |
|---|---|---|
| Measure 1 – Exemptions Framework |
| Reducing duplication of obligations or requirements from equivalent frameworks. |
| Measure 2 – Register of Critical Infrastructure Assets |
| Simplifying administration, reporting and notification. |
| Measure 3 – CIRMP Annual Reporting Simplification |
| |
| Measure 4 – Notification clarification for enhanced requirements for critical telco assets | Clarification that:
| |
| Measure 5 – Cyber Security Incident Definition: Automated Systems, Software Agents and AI |
| |
| Measure 6 – Systems of National Significance |
| Simplifying to focus enhanced-obligations on preparedness, continuity, recovery and restoration. |
| Measure 7 – Subsea Telecommunications Cables and Associated Infrastructure |
| Clarifying uncertain asset boundaries. |
| Measure 8 – Data Storage or Processing |
|
| Measure | Key Objectives | Aim |
|---|---|---|
| Measure 9 – Space Technology |
| Giving effect to the sector, which currently has no operative asset classes. |
| Measure 10 – Health Care and Medical Sector |
| Increasing concentrated focus on systemically significant functions. |
| Measure 11 – Distributed Energy Resources |
| Clarifying requirements beyond traditional electricity assets. |
| Measure 12 – Offshore Electricity Assets |
| Preventing exclusion of offshore electricity infrastructure from location settings. |
| Measure 13 – Critical Freight |
| Broadening and clarifying critical freight framework. |
| Measure 14 – Higher Education and Research |
| Refining and clarifying definition, which is currently limited in scope. |
| Measure | Key Objectives | Aim |
|---|---|---|
| Measure 15 – CIRMP Governance and Assurance |
| Clarifying obligations and evidence requirements for CIRMPs. |
| Measure 16 – Graduated Civil Penalty Settings |
| Improve deterrence and preserve graduated penalty structure. |
| Measure 17 – Operations and Maintenance Managed Service Providers |
| Preserve responsible entity model and address risks that sit outside current ownership and direct-interest concepts. |
| Measure 18 – Corporate Group Cooperation |
| Encourage and facilitate compliance for responsible entities within corporate groups. |
| Measure 19 – Supply Chain Cyber Security Assurance |
| Assist responsible entities with assessing and managing cyber risks. |
| Measure 20 – Specified Risk Information |
| Clearer documented consideration of CIRMP obligations. |
| Measure 21 – Critical Workers and Critical Components |
| Clarify application of definition and broader framework. |
The Department is currently considering submissions that were made during the consultation period, after which it is likely that a legislative exposure draft or draft Bill will follow.
The timeline for the enactment of the Enhanced CIRMP Rules as part of Tranche 1 was relatively short: an initial draft consultation paper was published in late 2025, an exposure draft consultation followed in early 2026, and the Enhanced CIRMP Rules were finalised and came into force by June 2026.
If this timeline is indicative, Tranche 2 reforms may become formal legislation in as soon as six months' time.
We will release further publications exploring these reforms in greater depth, including issues we have identified as likely to present imminent compliance challenges or uplift obligations.
In the meantime, we recommend that entities with existing SOCI obligations familiarise themselves with the measures outlined above and consider the potential implications, exposures and increased compliance obligations that may apply to them.
Authors: Clare Doneley, Partner; John Moore, Director, Risk Advisory; Sanjam Bajwa, Lawyer; Georgina Whittle, Graduate.
This publication is a joint publication from Ashurst Perkins Coie Australia and Ashurst Perkins Coie Risk Advisory Pty Ltd, which are part of the Ashurst Perkins Coie Group.
Ashurst Perkins Coie Australia (ABN 75 304 286 095) is a general partnership constituted under the laws of the Australian Capital Territory.
Ashurst Perkins Coie Risk Advisory Pty Ltd is a proprietary company registered in Australia and trading under ABN 74 996 309 133.
The Ashurst Perkins Coie Group comprises Ashurst Perkins Coie UK LLP, Ashurst Perkins Coie US LLP, Ashurst Perkins Coie Australia and their respective affiliates (including independent local partnerships, companies or other entities) which are authorised to use the name "Ashurst Perkins Coie" or describe themselves as being affiliated with Ashurst Perkins Coie. Some members of the Ashurst Perkins Coie Group are limited liability entities. Some members of the Ashurst Perkins Coie Group provide legal services and some provide non-legal services. Different legal entities in the group may operate in the same jurisdictions. Information about which Ashurst Perkins Coie Group entity operates in any country can be found on our website at www.ashurstperkinscoie.com.
The services provided by Ashurst Perkins Coie Risk Advisory Pty Ltd do not constitute legal services or legal advice, and are not provided by qualified legal practitioners acting in that capacity. The laws and regulations which govern the provision of legal services in the relevant jurisdiction do not apply to the provision of non-legal services.
This material is current as at 21 September 2026 but does not take into account any developments after that date. It is not intended to be a comprehensive review of all developments in the law or in practice, or to cover all aspects of those referred to, and does not constitute professional advice. The information provided is general in nature, and does not take into account and is not intended to apply to any specific issues or circumstances. Readers should take independent advice. No part of this publication may be reproduced by any process without prior written permission from Ashurst Perkins Coie. We accept no liability for use of these materials and reliance upon it by any person.