Home Insights Security of Critical Infrastructure: Tranche 2 reforms
Share

Security of Critical Infrastructure: Tranche 2 reforms

The Department of Home Affairs (the Department) has released a detailed consultation paper on the second tranche of proposed amendments to the Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act). The Tranche 2 reforms represent the most significant proposed structural reform to Australia's critical infrastructure regulatory framework since the SOCI Act was substantially amended in 2021–2022. 

The period for making submissions in response to the consultation paper closed on 31 July 2026 and the Department is currently considering submissions. This follows the commencement of the enhanced Critical Infrastructure Risk Management Program (CIRMP) Rules on 10 June 2026.

Entities across all potentially affected sectors should:

  • review the consultation paper to assess the potential impact of the proposed reforms on their operations;
     
  • where already subject to the SOCI Act, prepare for potential enhanced governance, assurance and penalty settings; and
     
  • where not currently subject to the SOCI Act, monitor developments closely if operating in sectors which are proposed to be newly covered or if acting as a managed service or outsourced provider exercising material operational control over critical infrastructure assets of customers.

This article provides a summary of the key proposed amendments to the SOCI Act under consideration.

Background to SOCI’s Tranche 2 reforms

The Tranche 2 reforms represent the next stage of the federal government's response to the Independent Review of the SOCI Act, which was conducted by Dr Jill Slay AM between November 2025 and January 2026 (the Review). The Review found that while the SOCI Act had made an important contribution to Australia's critical infrastructure security framework, the Act's complexity, regulatory duplication and operational difficulty were barriers to the framework working effectively in practice. The government accepted all six of the Review's recommendations in principle.

While Tranche 1 addressed immediate risk management and intervention settings through the enhanced CIRMP Rules and proposed reforms to Part 3 Ministerial direction powers, Tranche 2 proposes broader structural and operational reforms to the SOCI framework itself.

What this means for responsible entities and other stakeholders

These reforms would significantly reshape Australia's critical infrastructure regulatory framework. 

For existing responsible entities, the reforms would:

  • change how compliance is assessed and assured;
     
  • introduce new and significantly increased penalties for non-compliance to preventative and assurance duties such as establishing a CIRMP and reporting; and 
     
  • potentially expand obligations to other entities within their corporate group and supply chains, including outsourcers and managed service providers.

The proposed reforms also seek to cover new or expanded industry sectors and operators not presently within the scope of the critical sectors covered by the SOCI Act. This would include:

  • space technology;
     
  • distributed energy resources; 
     
  • offshore electricity; 
     
  • expanded health and medical functions;
     
  • a redefined higher education and research sector; 
     
  • data centres and cloud providers;
     
  • freight operators; and 
     
  • managed service providers and outsourcers exercising material operational control over critical assets.

Importantly, the detailed thresholds and boundaries for many of these measures are only proposed to be developed through subsequent Rules consultation. They are not settled in this paper. The consultation paper expressly notes that the key question for this round of consultation is whether the proposed Act-level framework reforms properly respond to the identified risks and regulatory gaps from the Review.

The Tranche 2 reforms, together with the Tranche 1 enhanced CIRMP Rules already in force and the proposed Part 3 Ministerial directions reforms, represent a comprehensive program of reform that will substantially reshape Australia's critical infrastructure regulatory landscape over the coming years.

Scope and objectives of the Tranche 2 reforms

The consultation paper identifies three linked objectives for the proposed reforms:

  • reducing unnecessary complexity, duplication and uncertainty in the current framework;
     
  • modernising and refining sector and asset coverage, so the framework continues to address nationally significant risks; and
     
  • strengthening governance, assurance and accountability mechanisms to assess whether security and resilience outcomes are actually being achieved.

The proposals are organised into three parts, comprising 21 distinct reform measures. For the remainder of this article, we summarise each of the three parts and each proposed measure.

Part A: Reducing complexity, duplication and uncertainty

Exemptions framework (Measure 1)

The consultation paper proposes a single, consolidated exemptions framework to replace the current patchwork of obligation-specific exemption mechanisms. Exemptions would be available where another Commonwealth, State or Territory law, or another recognised enforceable framework, delivers substantially equivalent or stronger outcomes for the same asset, entity, function or risk. Exemptions would, however, be limited, conditional and subject to review, allowing SOCI requirements to continue where still needed for visibility, notification, assurance or national security risk management. Exemptions need to be granted by the Secretary and may be individual on application or class based at the discretion of the Secretary.

Simplifying administration, reporting and incident notification (Measures 2–5)

The proposed reforms would restructure the Register of Critical Infrastructure Assets so that the Act sets broad categories of registrable information. The Rules would prescribe detailed information items within those categories. This would move from prescriptive, Act-level data fields to a more adaptable framework. Annual CIRMP reporting would be simplified by replacing hard-coded report content with a simpler obligation to lodge a compliance report in an approved form. Reporting questions would be published in advance and tailored by entity, asset class or obligation type. The Act-wide definition of ‘cyber security incident’ would be refined to also deal with incidents involving automated systems, software agents and AI-enabled tools, while preserving the existing Part 2B reporting thresholds and the cyber security character of the definition. The reform does not propose to create a separate AI incident reporting regime.

Systems of National Significance (Measure 6)

The SoNS framework would be simplified so designation has clearer practical consequences. This would replace the current incident response planning obligation with an asset-specific resilience planning obligation focused on continuity, recovery and restoration. Vulnerability assessments would no longer be required automatically on SoNS declaration, but would be required by reference to specific vulnerabilities or threat advice from an intelligence agency. All-hazards (including cyber security, physical security, personnel security, supply chain security and natural hazards) would be within scope, and the System Information Enhanced Cyber Security Obligation (ECSO) would be repealed.

Clarifying asset boundaries (Measures 7–8)

The framework for critical telecommunications assets would be refined to deal with nationally significant submarine cable systems, including shore-end infrastructure, landing stations and material cable interests such as indefeasible rights of use (IRUs). The current, customer-driven capture model for critical data storage or processing assets would be replaced with clearer operator-facing pathways. This would include facility-based capture (potentially based on a rated IT load threshold of 1 MW), service-based capture for larger cloud and hosting providers, certification-based capture through the Hosting Certification Framework, and a limited reserved Ministerial designation pathway.

Part B: Modernising and refining sector and asset coverage

Space technology (Measure 9)

The existing space technology sector, which currently has no operative critical asset classes, would receive four new asset classes: ground segment infrastructure, positioning, navigation and timing (PNT) support infrastructure, earth observation data infrastructure, and space situational awareness infrastructure. These would focus on ground-based and terrestrial systems physically located in Australia, with operative thresholds to be developed through subsequent Rules consultation.

Healthcare and medical sector (Measure 10)

The reform would extend CIRMP obligations to all critical hospitals (rather than a designated subset as at present). It would create new asset classes for concentrated and systemically significant (where there are limited substitutes or dependence on a small number of providers) blood supply, pathology, and high-containment or specialised laboratory functions. The paper notes that private pathology is currently concentrated, with three providers holding more than 80% of approved collection centres.

Distributed energy resources (Measure 11)

The electricity framework would be updated to address electricity storage (including battery energy storage systems), DER portfolios, controllable demand, and aggregation, orchestration and dispatch arrangements such as virtual power plants. The responsible entity would generally be the person with substantive contractual or technical ability to direct, coordinate, dispatch or orchestrate portfolio operation.

Offshore electricity assets (Measure 12)

The current geographic limitation for critical electricity assets would be disapplied for assets located in Commonwealth offshore areas. Offshore wind and other offshore electricity infrastructure could then be captured where it otherwise meets the relevant criticality thresholds.

Critical freight (Measure 13)

The freight framework would be broadened to cover nationally significant nodes, interfaces, distribution points, logistics platforms and discrete chokepoints. The Department is also seeking views on whether connected road transport systems (such as traffic management centres and smart motorway control systems) should be capable of capture.

Higher education and research (Measure 14)

The current critical education asset class would be replaced with a critical research asset class focused on nationally significant sensitive research functions. Capture would require three cumulative elements: an organised research function, a prescribed sensitive research field, and a prescribed national security nexus. Coverage would extend beyond universities to public research bodies, private research entities and collaborative structures.

Part C: Governance, assurance and accountability

CIRMP governance and assurance (Measure 15)

The proposed reforms would:

  • remove current admissibility restrictions that prevent annual compliance reports being used as evidence in civil penalty proceedings;
     
  • strengthen CIRMP governance and review obligations, including governing-body approval and event-based review triggers; and
     
  • introduce proportionate mandatory independent assurance of CIRMP design, implementation and effectiveness, with a proposed base cycle of three years.
Increased civil penalty settings (Measure 16)

Maximum civil penalties for core preventive and assurance duties would increase from 200 penalty units to 500 penalty units (an increase from AU$330,000 to AU$825,000 for corporations on the current penalty unit conversion).

Operations, maintenance and managed service providers (Measure 17)

A new ‘relevant operator’ concept would be introduced for entities with material practical control over an asset or critical function, including outsourced operators, managed service providers, OEMs and platform administrators. Relevant operators would be subject to targeted registration and limited direct duties to cooperate, notify and avoid materially compromising the asset. A limited safe harbour for responsible entities that cannot secure adequate arrangements with a relevant operator is also under consideration. This would apply where the responsible entity has taken reasonable steps to secure cooperation and agreement from a relevant critical infrastructure operator who has not responded or refused and the responsible entity has in place a documented risk mitigation plan.

Corporate group cooperation (Measure 18)

A limited cooperation duty would be created for connected corporate-group entities where the responsible entity materially depends on the relevant group entity for CIRMP compliance.

Supply chain cyber security assurance (Measure 19)

CIRMP expectations would be clarified for cyber security assurance of major suppliers. This would include supplier assessment, contractual or equivalent measures, recognised certification or accreditation, documented exceptions for constrained supply chains, and consideration of material sub-tier risks.

Specified risk information (Measure 20)

A targeted mechanism would allow the Secretary to specify published risk, hazard, standards or guidance material that responsible entities must consider through CIRMP processes, without making it a binding technical standard.

Critical workers and critical components (Measure 21)

The current critical worker definition would be replaced with a clearer access-based and authority-based model, supported by a refined critical component concept. The Rules could create categories of critical worker and apply proportionate checking, monitoring, training, supervision or access-control requirements.

Planning for the overhaul of Australia’s critical infrastructure regulatory framework

If enacted in their current form, the reforms would expand the reach of the SOCI Act into new sectors, impose materially increased penalties and require mandatory independent assurance of risk management programs. For the first time, they would also impose direct statutory duties on managed service providers and other outsourced operators exercising practical control over critical assets.

The consultation period on the Tranche 2 proposals closed on 31 July 2026. The Department is currently reviewing submissions and determining its next steps. 

Based on the staged reform program outlined by the Department, we anticipate the following timeline:

  • Late 2026 / early 2027: The Department is expected to finalise its policy position on the Tranche 2 measures and release exposure draft legislation for further consultation.
     
  • 2027: Introduction of amending legislation into Parliament, subject to the Parliamentary calendar.
     
  • Post-enactment: Subsequent consultation rounds on amendments to the Rules and other subordinate instruments, which will set the thresholds, exclusions, transition periods and operational boundaries that determine which entities are ultimately captured. 

Authors

James North

Head of Technology, Media and Telecommunications

Justin Gay

Special Counsel

Jack Matthews

Senior Associate

Louis Panozzo

Associate

Rachael Rozengurt

Law Graduate


Tags

Technology, Media and Telecommunications Regulatory Cyber Security
Share
  • Print article

Key Contacts

NORTH-james-highres_SMALL

James North

Head of Technology, Media and Telecommunications

Other Contacts

GAY Justin highres SMALL

Justin Gay

Special Counsel

MATTHEWS Jack SMALL

Jack Matthews

Senior Associate

Related Capabilities