Who must report cyber security incidents to ASD (SOCI)?
The applicability test for Report cyber security incidents to ASD (SOCI) (ASD and Home Affairs (SOCI)), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Only if
Applies when the business has a critical infrastructure asset.
What the obligation is
Critical infrastructure asset operators must report critical incidents within 12 hours and other incidents within 72 hours.
Under the Security of Critical Infrastructure Act 2018, responsible entities for critical infrastructure assets must report cyber security incidents that have a 'significant impact' on the availability of the asset within 12 hours; other reportable cyber incidents within 72 hours. Reports go to ASD's ACSC.
The applicability test
Applies when the business has a critical infrastructure asset.
How the regulator frames it: Responsible entities for the 11 critical infrastructure sectors covered by SOCI.
What triggers it: A cyber security incident with significant impact (12h) or other reportable impact (72h).
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (35 of 35: no).
The answer is the same in every industry: no. Industry does not change who must comply.
Business structure and size
Structure does not change the answer across all industries: for every structure the answer is "no".
Size does not change the answer across all industries: at every size band the answer is "no".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires a critical infrastructure asset.
Answers that bring it into scope
Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:
- The business operates a critical infrastructure asset: it then applies (operates a critical infrastructure asset (SOCI Act)).
What you must do, and when
- When due
- 12 hours (significant) / 72 hours (other) of becoming aware.
- Frequency
- When a triggering event occurs
- Evidence to keep
- Incident report to ASD, internal IR playbook records, log evidence.
- Status
- Current
- Priority
- Critical
Penalty for not complying
Maximum penalty: Civil penalties up to $91,000 (250 penalty units, body corporate) per contravention, plus mandatory direction risks.
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
Enforcement examples
- Home Affairs SOCI directions 2024 (2024): SOCI direction powers actively used; critical infrastructure must have robust CIRMP + cyber posture.
- Home Affairs SOCI mandatory cyber direction (illustrative) (2024): Critical infrastructure entities should expect ministerial direction powers to be exercised. CIRMP documentation must support rapid compliance responses.
Obligations with the same applicability test
If this obligation applies to you, so do these 5: the engine uses the same rule for each.
- Adopt and maintain a Critical Infrastructure Risk Management Program (CIRMP)
- Register as a responsible entity / direct interest holder under SOCI
- Comply with SOCI Positive Security Obligation (PSO) per sector
- Government cyber incident reporting via ASD ACSC
- SoNS — Systems of National Significance (SOCI)
Where it sits in the corpus
Rules Mate tracks 9 published obligations tagged "cyber", 4 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated critical priority, and is triggered by events.
Regulator, legislation and tools
Regulated by Australian Signals Directorate (Australian Cyber Security Centre) and Cyber and Infrastructure Security Centre — Department of Home Affairs.
ASD: Cyber security guidance and incident response. Publishes the Information Security Manual (ISM), Essential Eight, and Right Fit For Risk requirements for federal subcontractors.
Home Affairs (SOCI): Administers the Security of Critical Infrastructure Act 2018 — registration, risk management programs, and mandatory cyber incident reporting for critical infrastructure assets.
- Australian Signals Directorate (Australian Cyber Security Centre)
- Cyber and Infrastructure Security Centre — Department of Home Affairs
SOCI Act: Federal critical infrastructure protection regime.
Free tools that help with this obligation:
Questions
- Who must report cyber security incidents to ASD (SOCI)?
- Applies when the business has a critical infrastructure asset.
- Do sole traders need to report cyber security incidents to ASD (SOCI)?
- No. Across every industry and every size band, the engine's answer for a sole trader is: no.
- Do businesses with 1–5 employees need to report cyber security incidents to ASD (SOCI)?
- No (1–5 employees, turnover $100K–$1M).
- When is "Report cyber security incidents to ASD (SOCI)" due?
- 12 hours (significant) / 72 hours (other) of becoming aware.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.