Skip to main content
Rules Mate

Who must comply with SOCI Positive Security Obligation (PSO) per sector?

The applicability test for Comply with SOCI Positive Security Obligation (PSO) per sector (Home Affairs (SOCI)), computed across 35 industries, 9 business structures and 6 size bands.

Short answer: Only if

Applies when the business has a critical infrastructure asset.

What the obligation is

Sector-specific cyber + risk obligations under SOCI Part 2.

The Security of Critical Infrastructure Act 2018 (Cth) imposes positive security obligations so that critical infrastructure assets embed risk management, preparedness and resilience as business-as-usual practice. The Cyber and Infrastructure Security Centre lists three that apply to most assets: giving operational and ownership information to the Register (Part 2), reporting cyber incidents with a relevant or significant impact (Part 2B), and adopting, maintaining and complying with a written critical infrastructure risk management program (Part 2A). The program must identify each hazard where there is a material risk of a relevant impact on the asset and, so far as reasonably practicable, minimise or eliminate that risk and mitigate its impact. Each year the responsible entity reports on the program, with board approval where it has a board. Which obligations apply depends on the asset class and the entity's role.

The applicability test

Applies when the business has a critical infrastructure asset.

How the regulator frames it: The responsible entity for a critical infrastructure asset to which Part 2A applies (assets specified in the rules or covered by a ministerial declaration). Exemptions apply where the entity holds strategic-level hosting certification for the relevant services, or where a Commonwealth, State or Territory law specified in the rules already covers the entity or asset.

What triggers it: Becoming the responsible entity for an asset covered by Part 2A, after any grace period the rules allow for a newly captured asset.

Jurisdiction: Commonwealth law, so the test is the same in every state and territory.

Which industries are in or out

Outcome across the 35 industries Rules Mate maps (35 of 35: no).

The answer is the same in every industry: no. Industry does not change who must comply.

Business structure and size

Structure does not change the answer across all industries: for every structure the answer is "no".

Size does not change the answer across all industries: at every size band the answer is "no".

Worked examples

Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:

  • Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires a critical infrastructure asset.

Answers that bring it into scope

Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:

  • The business operates a critical infrastructure asset: it then applies (operates a critical infrastructure asset (SOCI Act)).

What you must do, and when

When due
Continuous: adopt and maintain the program, comply with it, review it regularly and keep it up to date. Annual report due within 90 days after the end of each financial year, to the relevant Commonwealth regulator or, if none, to the Secretary of Home Affairs.
Frequency
Ongoing
Evidence to keep
The written risk management program and its adoption record; hazard and material-risk assessment covering each asset; evidence of compliance with the program; review schedule and update log; the annual report in the approved form stating whether the program was up to date, evaluating any hazard with a significant relevant impact, and showing board, council or governing-body approval.
Status
Current
Priority
Critical

Penalty for not complying

Maximum penalty: Failing to adopt and maintain, comply with, review or update the program: 200 penalty units ($72,800) each (ss 30AC-30AF). Failing to give an annual report that meets s 30AG: 150 penalty units ($54,600) (s 30AG). A court can order a body corporate to pay up to 5 times these amounts, for example $364,000 for a 200-unit provision (Regulatory Powers (Standard Provisions) Act 2014 s 82(5))

Audit or assurance level

Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.

Obligations with the same applicability test

Where it sits in the corpus

Rules Mate tracks 5 published obligations tagged "soci", 2 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated critical priority, and is an ongoing duty.

Regulator, legislation and tools

Regulated by Cyber and Infrastructure Security Centre — Department of Home Affairs.

Home Affairs (SOCI): Administers the Security of Critical Infrastructure Act 2018 — registration, risk management programs, and mandatory cyber incident reporting for critical infrastructure assets.

SOCI Act: Federal critical infrastructure protection regime.

Free tools that help with this obligation:

Questions

Who must comply with SOCI Positive Security Obligation (PSO) per sector?
Applies when the business has a critical infrastructure asset.
Do sole traders need to comply with SOCI Positive Security Obligation (PSO) per sector?
No. Across every industry and every size band, the engine's answer for a sole trader is: no.
Do businesses with 1–5 employees need to comply with SOCI Positive Security Obligation (PSO) per sector?
No (1–5 employees, turnover $100K–$1M).
When is "Comply with SOCI Positive Security Obligation (PSO) per sector" due?
Continuous: adopt and maintain the program, comply with it, review it regularly and keep it up to date. Annual report due within 90 days after the end of each financial year, to the relevant Commonwealth regulator or, if none, to the Secretary of Home Affairs.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.