20 August 2026
The Department of Home Affairs (the Department) has released a detailed consultation paper on the second tranche of proposed amendments to the Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act). The Tranche 2 reforms represent the most significant proposed structural reform to Australia's critical infrastructure regulatory framework since the SOCI Act was substantially amended in 2021–2022.
The period for making submissions in response to the consultation paper closed on 31 July 2026 and the Department is currently considering submissions. This follows the commencement of the enhanced Critical Infrastructure Risk Management Program (CIRMP) Rules on 10 June 2026.
Entities across all potentially affected sectors should:
This article provides a summary of the key proposed amendments to the SOCI Act under consideration.
The Tranche 2 reforms represent the next stage of the federal government's response to the Independent Review of the SOCI Act, which was conducted by Dr Jill Slay AM between November 2025 and January 2026 (the Review). The Review found that while the SOCI Act had made an important contribution to Australia's critical infrastructure security framework, the Act's complexity, regulatory duplication and operational difficulty were barriers to the framework working effectively in practice. The government accepted all six of the Review's recommendations in principle.
While Tranche 1 addressed immediate risk management and intervention settings through the enhanced CIRMP Rules and proposed reforms to Part 3 Ministerial direction powers, Tranche 2 proposes broader structural and operational reforms to the SOCI framework itself.
These reforms would significantly reshape Australia's critical infrastructure regulatory framework.
For existing responsible entities, the reforms would:
The proposed reforms also seek to cover new or expanded industry sectors and operators not presently within the scope of the critical sectors covered by the SOCI Act. This would include:
Importantly, the detailed thresholds and boundaries for many of these measures are only proposed to be developed through subsequent Rules consultation. They are not settled in this paper. The consultation paper expressly notes that the key question for this round of consultation is whether the proposed Act-level framework reforms properly respond to the identified risks and regulatory gaps from the Review.
The Tranche 2 reforms, together with the Tranche 1 enhanced CIRMP Rules already in force and the proposed Part 3 Ministerial directions reforms, represent a comprehensive program of reform that will substantially reshape Australia's critical infrastructure regulatory landscape over the coming years.
The consultation paper identifies three linked objectives for the proposed reforms:
The proposals are organised into three parts, comprising 21 distinct reform measures. For the remainder of this article, we summarise each of the three parts and each proposed measure.
The consultation paper proposes a single, consolidated exemptions framework to replace the current patchwork of obligation-specific exemption mechanisms. Exemptions would be available where another Commonwealth, State or Territory law, or another recognised enforceable framework, delivers substantially equivalent or stronger outcomes for the same asset, entity, function or risk. Exemptions would, however, be limited, conditional and subject to review, allowing SOCI requirements to continue where still needed for visibility, notification, assurance or national security risk management. Exemptions need to be granted by the Secretary and may be individual on application or class based at the discretion of the Secretary.
The proposed reforms would restructure the Register of Critical Infrastructure Assets so that the Act sets broad categories of registrable information. The Rules would prescribe detailed information items within those categories. This would move from prescriptive, Act-level data fields to a more adaptable framework. Annual CIRMP reporting would be simplified by replacing hard-coded report content with a simpler obligation to lodge a compliance report in an approved form. Reporting questions would be published in advance and tailored by entity, asset class or obligation type. The Act-wide definition of ‘cyber security incident’ would be refined to also deal with incidents involving automated systems, software agents and AI-enabled tools, while preserving the existing Part 2B reporting thresholds and the cyber security character of the definition. The reform does not propose to create a separate AI incident reporting regime.
The SoNS framework would be simplified so designation has clearer practical consequences. This would replace the current incident response planning obligation with an asset-specific resilience planning obligation focused on continuity, recovery and restoration. Vulnerability assessments would no longer be required automatically on SoNS declaration, but would be required by reference to specific vulnerabilities or threat advice from an intelligence agency. All-hazards (including cyber security, physical security, personnel security, supply chain security and natural hazards) would be within scope, and the System Information Enhanced Cyber Security Obligation (ECSO) would be repealed.
The framework for critical telecommunications assets would be refined to deal with nationally significant submarine cable systems, including shore-end infrastructure, landing stations and material cable interests such as indefeasible rights of use (IRUs). The current, customer-driven capture model for critical data storage or processing assets would be replaced with clearer operator-facing pathways. This would include facility-based capture (potentially based on a rated IT load threshold of 1 MW), service-based capture for larger cloud and hosting providers, certification-based capture through the Hosting Certification Framework, and a limited reserved Ministerial designation pathway.
The existing space technology sector, which currently has no operative critical asset classes, would receive four new asset classes: ground segment infrastructure, positioning, navigation and timing (PNT) support infrastructure, earth observation data infrastructure, and space situational awareness infrastructure. These would focus on ground-based and terrestrial systems physically located in Australia, with operative thresholds to be developed through subsequent Rules consultation.
The reform would extend CIRMP obligations to all critical hospitals (rather than a designated subset as at present). It would create new asset classes for concentrated and systemically significant (where there are limited substitutes or dependence on a small number of providers) blood supply, pathology, and high-containment or specialised laboratory functions. The paper notes that private pathology is currently concentrated, with three providers holding more than 80% of approved collection centres.
The electricity framework would be updated to address electricity storage (including battery energy storage systems), DER portfolios, controllable demand, and aggregation, orchestration and dispatch arrangements such as virtual power plants. The responsible entity would generally be the person with substantive contractual or technical ability to direct, coordinate, dispatch or orchestrate portfolio operation.
The current geographic limitation for critical electricity assets would be disapplied for assets located in Commonwealth offshore areas. Offshore wind and other offshore electricity infrastructure could then be captured where it otherwise meets the relevant criticality thresholds.
The freight framework would be broadened to cover nationally significant nodes, interfaces, distribution points, logistics platforms and discrete chokepoints. The Department is also seeking views on whether connected road transport systems (such as traffic management centres and smart motorway control systems) should be capable of capture.
The current critical education asset class would be replaced with a critical research asset class focused on nationally significant sensitive research functions. Capture would require three cumulative elements: an organised research function, a prescribed sensitive research field, and a prescribed national security nexus. Coverage would extend beyond universities to public research bodies, private research entities and collaborative structures.
The proposed reforms would:
Maximum civil penalties for core preventive and assurance duties would increase from 200 penalty units to 500 penalty units (an increase from AU$330,000 to AU$825,000 for corporations on the current penalty unit conversion).
A new ‘relevant operator’ concept would be introduced for entities with material practical control over an asset or critical function, including outsourced operators, managed service providers, OEMs and platform administrators. Relevant operators would be subject to targeted registration and limited direct duties to cooperate, notify and avoid materially compromising the asset. A limited safe harbour for responsible entities that cannot secure adequate arrangements with a relevant operator is also under consideration. This would apply where the responsible entity has taken reasonable steps to secure cooperation and agreement from a relevant critical infrastructure operator who has not responded or refused and the responsible entity has in place a documented risk mitigation plan.
A limited cooperation duty would be created for connected corporate-group entities where the responsible entity materially depends on the relevant group entity for CIRMP compliance.
CIRMP expectations would be clarified for cyber security assurance of major suppliers. This would include supplier assessment, contractual or equivalent measures, recognised certification or accreditation, documented exceptions for constrained supply chains, and consideration of material sub-tier risks.
A targeted mechanism would allow the Secretary to specify published risk, hazard, standards or guidance material that responsible entities must consider through CIRMP processes, without making it a binding technical standard.
The current critical worker definition would be replaced with a clearer access-based and authority-based model, supported by a refined critical component concept. The Rules could create categories of critical worker and apply proportionate checking, monitoring, training, supervision or access-control requirements.
If enacted in their current form, the reforms would expand the reach of the SOCI Act into new sectors, impose materially increased penalties and require mandatory independent assurance of risk management programs. For the first time, they would also impose direct statutory duties on managed service providers and other outsourced operators exercising practical control over critical assets.
The consultation period on the Tranche 2 proposals closed on 31 July 2026. The Department is currently reviewing submissions and determining its next steps.
Based on the staged reform program outlined by the Department, we anticipate the following timeline:
Authors
Head of Technology, Media and Telecommunications
Partner
Special Counsel
Senior Associate
Associate
Law Graduate
Tags