Home Affairs (SOCI)
Cyber and Infrastructure Security Centre — Department of Home Affairs
Administers the Security of Critical Infrastructure Act 2018 — registration, risk management programs, and mandatory cyber incident reporting for critical infrastructure assets.
7
Obligations enforced
3
Enforcement actions tracked
4
Scope topics
Obligations enforced by Home Affairs (SOCI) (7)
- criticalCWLTHComply with SOCI Positive Security Obligation (PSO) per sector
Sector-specific cyber + risk obligations under SOCI Part 2.
- criticalCWLTHComply with Standard Business Sponsor obligations (482 + 494)
Business sponsors of 482 / 494 visas must meet labour market testing, equivalent terms + record-keeping.
- criticalCWLTHReport cyber security incidents to ASD (SOCI)
Critical infrastructure asset operators must report critical incidents within 12 hours and other incidents within 72 hours.
- criticalCWLTHSoNS — Systems of National Significance (SOCI)
Declared SoNS face enhanced cyber security obligations.
- highCWLTHAdopt and maintain a Critical Infrastructure Risk Management Program (CIRMP)
Covered critical infrastructure entities must adopt a CIRMP addressing cyber, physical, personnel, and supply-chain hazards.
- highCWLTHRegister as a responsible entity / direct interest holder under SOCI
Captured critical-infrastructure assets must be registered with Home Affairs.
- highCWLTHVerify work rights via VEVO before employment
Employers must verify visa work rights via VEVO before hiring non-citizens.
Recent Home Affairs (SOCI) enforcement
- enforcement focus2025SOCI CIRMP audit findings — first compliance phase 2025
First major SOCI CIRMP attestation cycle by 28 September 2024; Home Affairs audited + identified gaps in 2024-2025.
- direction2024Home Affairs SOCI directions 2024
Multiple SOCI Part 3A directions issued to responsible entities for critical infrastructure assets following cyber incidents + risk assessments.
- direction2024Home Affairs SOCI mandatory cyber direction (illustrative)
Following a significant cyber incident, the Minister exercised SOCI Part 3A direction powers to require a responsible entity to comply with specific mitigation actions.
Scope topics
Parent legislation
Source: regulator's own website. Rules Mate links and summarises — we don't republish full statutory text.