Introduction
The Security of Critical Infrastructure Act 2018 (SOCI Act) sounds like something only power companies and ports need to worry about. It isn’t. Since the 2021 reforms, SOCI covers 11 sectors and 22 asset classes, and plenty of organisations that would never describe themselves as “critical infrastructure” turn out to be a responsible entity under the Act without realising it. That status isn’t just a label either. It comes with real legal obligations: registering your asset, reporting cyber incidents on a strict timeline, and in many cases running a formal risk management program that needs board approval. This article walks through what “responsible entity” actually means, the sectors and asset classes worth checking yourself against, and a practical way to work out where you stand.
What the SOCI Act Actually Covers
The SOCI Act is Commonwealth legislation, administered by the Department of Home Affairs and regulated day to day by the Cyber and Infrastructure Security Centre (CISC). It started in 2018 covering just four sectors: electricity, gas, water, and ports. Reforms passed in 2021 expanded that to 11 sectors: communications, data storage or processing, defence industry, energy, financial services and markets, food and grocery, health care and medical, higher education and research, space technology, transport, and water and sewerage. Reforms haven’t stopped there either. Amendments through 2024 and 2025 extended coverage further, including to certain data storage systems, and broadened the government’s powers to respond to incidents beyond cyber threats alone. If you checked your obligations once and moved on, it’s worth checking again.
What “Responsible Entity” Actually Means
A responsible entity is the entity that owns or operates a specific critical infrastructure asset. That sounds simple enough, but the exact definition is set separately for each asset class in the Act, and it doesn’t always land where you’d expect. Sometimes it’s the licence holder. Sometimes it’s whoever operates the asset day to day, even if a different company owns it. Sometimes the owner and the operator both have obligations at once. This is worth checking properly rather than assuming, because the definition genuinely shifts depending on the asset type.
There’s a related but different status worth knowing about too: a direct interest holder. That’s any entity holding a legal or equitable interest of 10% or more in a critical infrastructure asset, or one able to influence or control the asset even without formal ownership. Direct interest holders carry some obligations under the Act, but not the same ones as responsible entities, so it’s worth being clear on which status, if either, actually applies to you.
The 11 Sectors, at a Glance
If your organisation touches any of the following, it’s worth checking further:
- Communications: broadcasting, domain name systems, telecommunications
- Data storage or processing: data centres and infrastructure storing or processing business critical data
- Defence industry: assets tied to defence contracts and capability
- Energy: electricity, gas, liquid fuel, energy market operators
- Financial services and markets: banking, insurance, superannuation, payment systems
- Food and grocery: large-scale food and grocery supply infrastructure
- Health care and medical: critical and designated hospitals
- Higher education and research: certain university and research assets
- Space technology: space-related infrastructure
- Transport: aviation, ports, freight, and public transport
- Water and sewerage: water and sewerage utilities
Being in one of these sectors doesn’t automatically make you a responsible entity. It just means the specific asset class definitions and thresholds are worth checking, which is the step most organisations skip.
A Practical Way to Check
Rather than guessing from the sector list alone, work through it in roughly the order CISC’s own guidance does:
- Does what you run match a defined asset class? Owning “a data centre” isn’t the test on its own. The Act defines specific asset classes, a critical data storage or processing asset, a critical hospital, and so on, each with its own criteria.
- Does it meet the relevant size or significance threshold? Most asset classes carry a specific threshold in the rules, a customer number, a generation capacity, a transaction volume, that determines whether a given asset actually counts.
- Is the asset located in Australia? Assets outside Australia generally sit outside SOCI’s scope.
- Is it excluded because of who owns it? Some Commonwealth-owned assets are treated differently under the Act.
- Who actually owns it, and who operates it? If it clears the steps above, work out whether that makes your organisation the responsible entity, a direct interest holder, both, or neither. Ownership and day to day operation aren’t always the same company.
If you work through all of that and you’re still not sure, treat the uncertainty itself as a signal to get advice rather than assume you’re in the clear. Plenty of organisations only find out they were a responsible entity after an incident, which is the worst possible time to learn it.
What It Means If You Are One
If your organisation is a responsible entity, three obligations are the ones most likely to apply. You’ll generally need to register ownership and operational details with the Register of Critical Infrastructure Assets. If a cyber incident has a significant impact on your asset, you must notify the ASD’s Australian Cyber Security Centre within 12 hours of becoming aware of it, or within 72 hours for incidents with a less severe but still relevant impact. And for many asset classes, you’ll need a written Critical Infrastructure Risk Management Program covering cyber, personnel, supply chain, and physical hazards, reviewed and signed off by your board. A smaller subset of assets, declared Systems of National Significance, carry further obligations on top of that, including incident response planning and government-directed vulnerability assessments. Not every obligation is switched on for every asset class yet, so which of these actually apply depends on exactly where you land in the rules.
Where to Go From Here
If you’ve read this far and you’re still not certain whether your organisation is a responsible entity, treat that as reason enough to check properly rather than reason to leave it for later. The SOCI Act’s obligations don’t wait for you to opt in, and the cost of finding out late, after an incident or a compliance notice, is a lot higher than the cost of checking now.
If you’ve worked through this and you’re still not sure, or you already know you’re covered and need help meeting what comes with it, that’s exactly where Cyber Ethos comes in. We’re based in Queensland and work with critical infrastructure operators across Australia. Get in touch and we’ll help you find out where you actually stand.
