
This is the first in a series of free guides we’re publishing over the next three months under the banner Cybersecurity, the Australian way. Each one takes a single topic and explains it in plain English for the people who build and run Australia’s wind farms, solar farms and batteries. We’re starting with the law that sits underneath everything else: the Security of Critical Infrastructure Act 2018, or SOCI.
What SOCI is, in one paragraph
SOCI is the Commonwealth’s way of making sure the owners and operators of essential services take responsibility for protecting them. It doesn’t tell you which firewall to buy. Instead, it sets out a small number of “positive security obligations” and expects you to manage your own risks, with your board accountable for the result. For most electricity assets there are three obligations:
- Tell the government who owns and runs the asset. Ownership and operational details go on the Register of Critical Infrastructure Assets, and you keep them up to date when they change.
- Report serious cyber incidents. Within 12 hours for an incident with a significant impact on the asset, and within 72 hours for one with a relevant impact.
- Keep a risk management program. A written Critical Infrastructure Risk Management Program (CIRMP) that covers cyber, personnel, supply chain, and physical and natural hazards, approved by your board and reported on every year. The Rules call out certain significant risks that you are obliged to address.
Behind those sit government powers to request information, issue directions and, as a last resort, step in during a serious incident. A small number of the most important assets are also privately declared Systems of National Significance and can be given extra obligations, such as incident response planning and exercises.
Is my project caught?
For generation, the test has two parts, and you need both. A generation station is a critical electricity asset if it has an installed capacity of 30 MW or more (or provides system restart services), and it is connected to a wholesale electricity market such as the NEM or the WEM. Most utility-scale wind, solar and battery projects meet both limbs once they connect. A genuinely off-grid asset, such as a behind-the-fence wind farm supplying a remote mine, generally does not, but many will likely follow SOCI as the national benchmark.
Assets or systems that are connected to critical assets, such as auto-bidding and trading platforms, may be deemed critical assets if they are necessary for the continued operation of the asset. This is something for large-scale battery projects to consider carefully.
The obligations fall on the responsible entity, usually the entity that holds the generator registration and runs the asset. Investors with a direct interest have their own reporting duties for the Register, which matters for joint ventures and for equity changes around financial close. If your structure is unusual, get a scoping opinion early.
How we got here
SOCI has been extended several times since 2018, and each change added obligations. The direction has always been the same: from knowing who owns an asset, to knowing how well it is protected, and now to knowing what is inside it and who can reach it.
| When | What changed |
|---|---|
| July 2018 | SOCI Act commences. Covers electricity, gas, water and ports. Main obligation: the Register of ownership and operational information. |
| December 2021 | First major expansion: 11 sectors and 22 asset classes. Adds mandatory cyber incident reporting (in force from 2022) and government assistance powers. |
| April 2022 | Second expansion: the risk management program obligation, and Systems of National Significance. |
| February 2023 | CIRMP Rules commence. Programs had to be in place by August 2023, with a recognised cyber framework (such as the AESCSF or ISO 27001) by August 2024. First annual board reports were due in September 2024. |
| November 2024 | Cyber Security Legislative Package: data storage systems holding business-critical data come into scope, along with new powers to direct post-incident action and to fix deficient risk programs. |
| 10 June 2026 | Enhanced CIRMP Rules commence for high-risk asset classes, including critical electricity assets, with staged compliance dates. |
| June 2027 | Must manage, as material risks: foreign ownership, control or influence (FOCI), and offshore or remote access to critical components and data. Plus patching, legacy and end-of-life equipment, and managing who has access to what. |
| Q4 2027 (expected) | Tranche 2 changes to the SOCI Act (proposed): new asset classes such as distributed energy resources (DER) and offshore wind, changes for major OEM vendors, and supply chain assurance processes. Consultation closed in July 2026; draft legislation is expected in Q4 2026. |
| June 2028 | Must meet a recognised cyber framework, phishing-resistant multi-factor authentication, network segregation of critical systems, background checks for critical workers (AusCheck or NV1 clearance), supply chain mapping and vendor assessment, and physical security across all hazards. |
What the 2026 rules actually change
The original CIRMP Rules were principles-based: identify your material risks and deal with them. The enhanced Rules keep that idea but name specific risks you must address, and attach dates. Four changes matter most for renewables:
- Foreign ownership, control or influence is now a named risk. This is about which laws your suppliers are subject to, and how much access, influence and control they keep over your asset through their product or service. It is not a list of banned countries or vendors. The Rules expect you to assess the risk and manage it, not necessarily to replace equipment.
- Remote access is in the spotlight. Most turbines, inverters and battery systems are monitored and updated by their manufacturer, often from overseas. You now have to know who holds that access, from where, and how you’d cut it off.
- Supply chains go down to components. You must map major suppliers and critical components, and set a maximum acceptable outage: how long each critical part could be unavailable before your asset can no longer run reliably. We cover this in detail in our white paper, Looking deeper into renewables supply chains.
- The baseline for cybersecurity controls goes up. For sites using the Australian Energy Sector Cyber Security Framework (AESCSF), the baseline moves to Security Profile 2 (SP-2): about 200 practices, up from 88 under the previous Security Profile 1 (SP-1) baseline.
If you’re pre-FID or in procurement
This is the stage where SOCI is cheapest to get right, and most often overlooked. The vendor assessment in the new Rules applies to each existing or proposed major supplier, so the tender you’re running now is, in effect, the first step of your compliance. A wind farm reaching financial close today will probably energise after June 2028, which means it will be born into the full enhanced regime.
- Ask the right questions in the tender. The ownership structure of each major supplier, and the laws that govern it. How remote support is provided, and from what locations. The processes for changing and pushing software, and how those changes are verified. Ask for software and hardware bills of materials (SBOMs and HBOMs) for critical systems such as SCADA, controllers, battery management systems and inverters.
- Put it in the contract. Remote access requirements, and logging and telemetry feeds that flow into security operations. Incident notifications fast enough for you to meet your own 12- and 72-hour reporting windows. Background checks for vendor staff who will be critical workers, along with how their access is granted. Rights to audit, and to updated bills of materials with each version change over the life of the service agreement.
- Price it in. Segregated networks, secure remote access and a security operations service cost far less in the capex budget than as a variation in year three, or as a manual workaround over a 25-year service contract.
- Tell your investors. Lenders and equity partners increasingly ask about SOCI and foreign influence in due diligence. A clear position that is well documented and justified helps get to financial close.
If you’re in design and construct
Contracts are signed, but the design is still yours to influence. Most enhanced-rule requirements are much easier to build in than to retrofit.
- Design the network for segregation. Separate control systems from corporate IT and vendor connections, so a problem in one can be contained without shutting down the site.
- Lock down unnecessary access. Commissioning teams often get broad remote access that is over-privileged and often not fully removed.
- Build the asset register as you build the asset. Record every controller, firmware version and supplier as it’s installed, and update it each time a version is upgraded through the change process. It becomes the starting point for supply chain mapping and the maximum acceptable outage.
- Be ready on day one. Register details, an incident reporting process and a draft risk program should be in place before energisation, not after. The grace periods after an asset becomes critical infrastructure are measured in months, and they pass quickly once operations start.
Already operating?
You will already have a risk program and an annual board report. The task now is to close the gap to the enhanced Rules before June 2027, starting with foreign influence and remote access, then work through the 2028 items. Most operators we speak to find supply chain mapping the largest piece of work, so it’s worth starting early.
Coming up in the series
Over the coming weeks we’ll unpack each part of this in turn: foreign ownership, control and influence; remote access; personnel checks; bills of materials; and what “good” looks like for a renewables security program. All of it free, on this site. If you’d like to talk about where your project stands, get in touch.
This guide is general information, not legal advice. Check how SOCI applies to your asset and corporate structure with your legal advisers.