Loading
pop-up content starts
pop-up content ends

SOCI Regulatory Philosophy

​​​​​​Our Regulatory Principles

The Security of Critical Infrastructure Act 2018 (SOCI Act)​ is designed to:

  • protect Australian critical infrastructure
  • ensure resilience against disruptions
  • safeguard national security, the economy and community wellbeing.

This is achieved by ensuring:

  • owners and operators of critical infrastructure assets are taking appropriate steps to secure their assets
  • the Australian Government has the information required to manage national security risks and appropriate and proportionate powers to respond to risks.

The following five principles guide the Critical Infrastructure Security Centre (CISC). These principles inform how we exercise our regulatory powers and establish how we engage with industry stakeholders and regulated entities.

​

Focus on risk and positive outcomes

We perform regulatory actions and prioritise resources in a risk-based and outcomes focused manner to enhance the resilience and security of the sectors we regulate.

Promote voluntary compliance

We adopt a consultative approach with industry stakeholders to reduce regulatory burden and implement solutions that have the greatest positive impact to the broader community. We support regulated entities to understand and meet their obligations through clear guidance and engagement.

Be accountable, fair, and transparent

We communicate any regulatory actions clearly and do not impose unnecessary burden on regulated entities. The impacts of regulation across stakeholders are considered and balanced against the benefit of pursuing regulatory actions.

Consistency and predictability

We deliver robust and consistent decision-making across sectors, while allowing for case-specific factors such as risk or serious and persistent non-compliance. We inform industry of any changes in our regulatory posture or approach.

Proportionate decision-making

Regulatory responses are proportionate to the nature and seriousness of the identified risk, behaviour, or non-compliance.

Threats to Critical Infrastructure

Effective compliance activities support the objective of the SOCI Act to provide a framework for managing threats to critical infrastructure. Threats to the secure and effective performance of Australia’s critical infrastructure are varied and ever present. The impact of an incident can have cascading consequences for multiple assets and services that are increasingly interdependent. Threats can come from inside or outside an organisation. They may include:

  • hostile or criminal activity
  • foreign interference
  • terrorism and politically motivated violence
  • natural disasters
  • supply chain disruption
  • exploitation of poor physical, personnel and cyber security practices. 

It is essential that threats to Australia’s critical infrastructure are mitigated in a threat environment that is constantly evolving. Government and industry must anticipate and be ready to respond to unpredictable changes in:

  • the global geopolitical environment
  • supply chains
  • foreign ownership, control or influence
  • espionage tactics
  • the security implications of emerging technology.

The obligations of the SOCI Act are designed to lead to better security and resilience outcomes for Australia. The government must work side by side with industry to continually strengthen our critical systems, to safeguard national security and economic prosperity. Maintaining a clear awareness of these risks is vital to protect the essential services we all rely on. It is important for critical infrastructure to adapt to the evolving threat landscape and collaborate with government. This will help achieve strong security outcomes through effective regulatory settings and partnerships.

Compliance and Enforcement Priorities

Each year, the CISC reviews our compliance and enforcement priorities. Priorities are targeted towards sectors, asset classes and entities where non-compliance with the SOCI Act is most likely to adversely impact:

  • national security
  • critical infrastructure resilience
  • the continuity of essential services.

We determine priorities using a risk-based and outcomes-focused approach and assess the threat environment as outlined above. We also consider the following factors:

  • previous compliance findings and emerging trends
  • intelligence and operational reporting
  • legislative, policy and regulatory changes
  • responding to crises and issues of government, public and industry concern
  • the full range of obligations under the SOCI Act
  • CISC resourcing and capability.

This approach supports the consistent, transparent and lawful application of regulatory powers. It ensures regulatory effort, such as our assurance program, is directed to areas where there is higher risk and it is most likely to improve compliance outcomes.

We will communicate specific detail on our compliance focus areas through our engagement channels.

Our Regulatory Approach

The CISC, as the regulator for the SOCI Act, drives an all-hazards critical infrastructure regime. The CISC actively helps critical infrastructure owners and operators to understand risks to their assets and supports entities to meet their regulatory obligations. Where we identify potential non-compliance, we will take action proportionate to the nature and severity of the non-compliance. We are guided by statutory objectives to safeguard Australia's critical infrastructure from hazards that present ongoing threats or risks to:

  • national security
  • the economy
  • community wellbeing.

We take action to enforce and give effect to the legislation we administer where it is appropriate and proportionate to do so.

Effective compliance activities support the purpose of the SOCI Act to provide a framework for managing risks relating to critical infrastructure. The CISC helps the regulated community to understand that compliance is not just a matter of legal obligation, but integral to protecting the essential services all Australians rely on.

We recognise that both engagement and enforcement mechanisms are necessary to provide an effective regulatory system. A range of regulatory and non-regulatory options are available to address non-compliance, including:

  • education
  • engagement
  • Regulatory Guidance Notices (RGNs) - formal guidance regarding legislative obligations
  • Non-Compliance Notices (NCNs) - formal advice non-compliance with the SOCI Act has been identified
  • infringement notices
  • powers, directions or enforceable undertakings available under relevant legislation
  • prosecu​tion.

Evolving Regulatory Posture

The 2026 Independent Review of the SOCI Act recommended that CISC “move from a ‘light touch’ compliance approach with a focus on administration and documentation to that of a penalty-based risk management process with the real enforcement of penalties.”

In response to this recommendation, we are evolving our regulatory compliance posture in relation to the SOCI Act. We encourage voluntary compliance first, then escalate proportionately and deploy enforcement when necessary. We will undertake enforcement actions such as the issuing of infringement notices as required. For example, this may occur in instances of serious or persistent non-compliance or where a significant unmitigated national security threat is present. ​We cover this in our ‘Evolving Regulatory Posture’ article​.

We will continually review our regulatory activities based on the results and impact on industry. As the risk environment evolves over time, we will also develop our activities and amend our processes. This will ensure we are achieving the objectives of the SOCI Act to enhance critical infrastructure resilience and protect Australia’s economy, security and community wellbeing.

For more information contact enquiries@cisc.gov.au

​