EXPLORE KNOWLEDGE BASE
-
CERI Knowledge Base
-
About the CERI knowledge base
-
Introduction to Australia’s electricity markets
-
Australian consumer insights
-
CER technical and interoperability standards
-
Connecting a customer to an electricity network
-
Connecting a generator to a distribution network
-
Utility interconnection (CSIP-AUS)
-
Dynamic network export and generation control schemes
-
Network load control schemes
-
Network tariffs and network support services
-
Participating in the National Electricity Market
-
Participating in a frequency control market
-
Participating in the RERT
-
Participating in the Wholesale Electricity Market (Western Australia)
-
Participating in the I-NTEM (NT)
-
Cyber security and data privacy arrangements
-
Consumer protection frameworks
-
Security of Critical Infrastructure (SOCI) Act
Last Updated on 4 August 2026
SUGGEST AN EDIT
LIKE THIS PAGE?
The Security of Critical Infrastructure Act 2018 (SOCI Act) is a key legislative framework designed to protect Australia’s critical infrastructure from threats that could compromise national security, economic stability, and public safety. The SOCI Act has evolved over time, significantly broadening its scope. The Act covers 11 critical infrastructure sectors, including energy, which encompasses electricity generation, transmission, and distribution networks.
Key points
- Obligations can include asset registration, incident reporting and risk-management programs.
- CER suppliers may be affected through contracts with network operators, retailers and other critical asset owners.
- Suppliers may need to provide security attestations, support vulnerability assessments and demonstrate secure product design.
- Secure firmware, encrypted communications and transparent data governance can support customer compliance requirements.
Obligations under the SOCI Act
Electricity sector participants such as generators, transmission and distribution network operators, and energy market operators are designated as responsible entities under the SOCI Act. Their obligations include:
- 1. Registering Assets: Entities must provide detailed information about ownership, operational control, and key service providers to the Register of Critical Infrastructure Assets. This transparency helps government agencies assess systemic risks and foreign influence.
- 2. Mandatory Incident Reporting: Cybersecurity incidents that impact critical assets must be reported promptly to the CISC. This includes attacks on OT systems, which are increasingly interconnected with IT networks. Timely reporting enables coordinated national responses.
- 3. Critical Infrastructure Risk Management Program: Under Part 2A, responsible entities must address four domains:
- Cybersecurity: Measures to prevent, detect, and respond to cyber threats
- Physical Security: Controls to prevent unauthorised access or sabotage
- Personnel Security: Vetting and monitoring individuals with privileged access
- Supply Chain Security: Assessing and mitigating risks from third-party providers
An electricity generation asset is classified as a critical electricity asset if it meets specific capacity and operational criteria. The primary threshold is 30 MW of installed capacity for assets connected to the NEM or WEM. This threshold applies uniformly across jurisdictions. Additionally, assets providing SRAS are deemed critical regardless of size. Once classified, the responsible entity must comply with obligations such as registering the asset in the Critical Infrastructure Asset Register, implementing a Critical Infrastructure Risk Management Program and reporting cyber incidents.
Key Implications for CER Suppliers
While the SOCI Act only introduces obligations for entities that own, operate, or hold direct interests in critical infrastructure assets, the Act’s emphasis on supply chain security means obligations can extend beyond large asset owners. They can cascade through the supply chains, influencing not only asset owners but also technology providers and service partners, including suppliers of CER products and services.
Suppliers must design products with robust cybersecurity features, recognising that vulnerabilities in distributed assets can create systemic risks. This includes secure firmware updates, encrypted communications and adherence to frameworks such as AESCSF, especially when operating at scale or interfacing with critical electricity asset operators such as electricity retailers or DNSPs that operate large CER fleets.
The SOCI Act also requires responsible entities to notify third-party data service providers when they are engaged to store or process critical business data. CER aggregators and platform providers handling operational data may be subject to these requirements, necessitating transparent data governance practices.
While CER suppliers are not directly obligated under the SOCI Act, they can be contractually required by network operators and retailers to support compliance. This could involve:
- Providing security attestations
- Participating in vulnerability assessments
- Enabling remote disconnection capabilities,
In summary, the SOCI Act creates a top-down compliance cascade:
- Critical asset owners impose contractual and technical requirements on their service providers
- Network businesses integrate SOCI-aligned security measures into connection agreements and procurement processes
- CER suppliers must adapt product design, cybersecurity posture, and operational practices to meet these expectations.
For many CER suppliers, compliance is not optional and by aligning with SOCI Act requirements and AESCSF best practices, CER product and service providers can position themselves as trusted partners, enhancing partnership opportunities with larger electricity sector organisations.