By Stu Long, Chief Technology Officer, Orro
Over the past few weeks, three separate conversations with clients in mining, water utilities and state government have circled back to the same theme: what the second tranche of SOCI Act reforms actually changes, and for whom. The Department of Home Affairs released its consultation paper on 3 July 2026, proposing the most significant overhaul of the Security of Critical Infrastructure Act 2018 since it was introduced. The consultation closed on 31 July, and Home Affairs is now working through submissions ahead of the next stage of the reform. Whatever the final legislative text looks like, the direction of travel is already clear enough that organisations running OT and critical infrastructure security programs should be planning for it now.
Why this reform exists
The reforms respond to an Independent Review of the SOCI Act conducted by Dr Jill Slay AM between November 2025 and January 2026, with the final report tabled in Parliament on 24 March 2026. The review’s central finding was direct: the Act has built genuine security uplift over its life, but has become complex, duplicative and difficult to apply as ownership, operating and service delivery models have moved on. Government accepted all six of the review’s recommendations in principle, and the tranche two consultation paper is where that response starts to take legislative shape.
Governing body: The Department of Home Affairs, through the Cyber and Infrastructure Security Centre, administers the SOCI Act and its subordinate Rules.
What it requires: Responsible entities for regulated critical infrastructure assets must maintain a Critical Infrastructure Risk Management Program addressing cyber, personnel, physical and supply chain risk, register asset information, notify certain cyber security incidents, and submit an annual compliance report approved by their governing body.
Who it applies to: Entities responsible for critical infrastructure assets across sectors including energy, water, communications, financial services, healthcare, transport, food and grocery, defence, higher education and research, data storage and processing, and space technology. The proposed tranche two reforms would extend obligations to a new category of relevant operator and refine asset coverage across several of these sectors.
Consequence of non-compliance: Civil penalties apply for breaches of core obligations, on a graduated scale depending on the duty involved. Government has proposed increasing the maximum penalty for preventive and assurance duties from 200 to 500 penalty units, which at the current Commonwealth penalty unit value of $364 takes the maximum exposure from $72,800 to $182,000.
The relevant operator problem
Of everything in the consultation paper, the change with the most direct relevance to Orro’s clients, and to Orro itself, is the proposed relevant operator concept. Today, SOCI obligations sit with the responsible entity, typically the asset owner. The reform would extend direct obligations, for the first time, to entities that exercise material practical control over a critical infrastructure asset or function, including managed service providers, OEMs and platform administrators, regardless of whether they hold any ownership interest at all.
This matters because so much of what keeps critical infrastructure running today, from OT network management to industrial SOC monitoring to platform administration, is delivered through exactly these kinds of arrangements. If your organisation is a responsible entity, this reform reframes supply chain risk from something you assess in your own environment to something your providers may soon be legally accountable for directly. If you sit on the delivery side of that relationship, as Orro does for a number of clients, the obligations proposed for relevant operators (targeted registration, duties to cooperate and notify, and a duty not to materially compromise the asset) would be new and direct, not something that only ever flows through a contract.
The perimeter is moving, not just tightening
The consultation paper also proposes to expand and refine the classes of assets the Act covers. Submarine telecommunications cables, data storage and processing facilities, space technology ground infrastructure and positioning, navigation and timing support, distributed energy resources, hospitals and other health infrastructure, critical blood supply and pathology systems, critical freight nodes, and higher education and research infrastructure are all in scope of the proposed changes. Some of these sit well outside the sectors people typically associate with critical infrastructure regulation. Organisations that have assumed SOCI doesn’t touch them should treat that assumption as due for a review, not a conclusion. Classification is asset-specific and will depend on the detailed thresholds still to be settled through the Rules, so the right first step is assessment, not a blanket claim either way.
From documentation to demonstration
The theme running through the governance proposals is the one I’d want every board and executive team to sit with: it’s no longer enough to have a Critical Infrastructure Risk Management Program on file. The reforms propose stronger board and senior management accountability for the CIRMP, moving beyond a once-a-year sign-off, and a new requirement for periodic independent assurance that tests whether the program is actually operating as designed, not just whether it exists on paper.
Evidence Snapshot
46% – Proportion of cyber-physical systems security professionals whose organisations experienced a breach via third-party vendor access in the past 12 months, with more than half discovering the security gaps in vendor contracts only after the incident. (Claroty, 2025)
That penalty increase is meaningful, but the more important shift is qualitative. Assurance that tests whether controls are operating, rather than whether a document exists, is a different discipline. It requires the same kind of evidence base a mature OT security program should already be generating: asset visibility, monitoring coverage, incident response testing, and a clear line from control design through to control performance.
What I’d do now
The consultation paper also flags the possible introduction of a supplier cyber security certification or accreditation scheme, intended to give responsible entities a more standardised way to assess supply chain risk. It’s early, and the detail isn’t settled, but it points in the same direction as everything else in this reform: your ability to demonstrate, not just describe, the state of your risk management is becoming the thing that matters.
The practical response doesn’t need to wait for the legislation to land, whichever side of this reform you sit on. If you’re in transport and logistics or healthcare, take this as the prompt to assess exposure now: the proposed critical freight and health care asset classes are new ground, and getting ahead of the Rules-level detail beats reacting to it once it’s settled. If you’re already inside the regulated perimeter, in mining, utilities, government or financial services, the priority is different: map which of your managed service providers, OEMs and platform administrators could be captured as relevant operators, and start that conversation with them now, well before it becomes a contractual requirement rather than a courtesy. Either way, test whether your CIRMP would survive independent scrutiny today, not just board sign-off.
Orro works with critical infrastructure operators across mining, utilities, government, transport and logistics, and healthcare on exactly this kind of readiness, from OT/IT architecture and network segmentation through to compliance and assurance support for CIRMP obligations. As an Australian-owned partner with Australian-based support escalation and 24/7 global operations capability, we help organisations move from having a risk management plan to being able to prove it works.
To discuss your environment, contact our team at orro.group/contact.
For a practical breakdown of both compliance shifts side by side, see our readiness guide covering both frameworks.