Who must comply with SOCI Positive Security Obligation (PSO) per sector?
The applicability test for Comply with SOCI Positive Security Obligation (PSO) per sector (Home Affairs (SOCI)), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Only if
Applies when the business has a critical infrastructure asset.
What the obligation is
Sector-specific cyber + risk obligations under SOCI Part 2.
The Security of Critical Infrastructure Act 2018 (Cth) imposes positive security obligations so that critical infrastructure assets embed risk management, preparedness and resilience as business-as-usual practice. The Cyber and Infrastructure Security Centre lists three that apply to most assets: giving operational and ownership information to the Register (Part 2), reporting cyber incidents with a relevant or significant impact (Part 2B), and adopting, maintaining and complying with a written critical infrastructure risk management program (Part 2A). The program must identify each hazard where there is a material risk of a relevant impact on the asset and, so far as reasonably practicable, minimise or eliminate that risk and mitigate its impact. Each year the responsible entity reports on the program, with board approval where it has a board. Which obligations apply depends on the asset class and the entity's role.
The applicability test
Applies when the business has a critical infrastructure asset.
How the regulator frames it: The responsible entity for a critical infrastructure asset to which Part 2A applies (assets specified in the rules or covered by a ministerial declaration). Exemptions apply where the entity holds strategic-level hosting certification for the relevant services, or where a Commonwealth, State or Territory law specified in the rules already covers the entity or asset.
What triggers it: Becoming the responsible entity for an asset covered by Part 2A, after any grace period the rules allow for a newly captured asset.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (35 of 35: no).
The answer is the same in every industry: no. Industry does not change who must comply.
Business structure and size
Structure does not change the answer across all industries: for every structure the answer is "no".
Size does not change the answer across all industries: at every size band the answer is "no".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires a critical infrastructure asset.
Answers that bring it into scope
Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:
- The business operates a critical infrastructure asset: it then applies (operates a critical infrastructure asset (SOCI Act)).
What you must do, and when
- When due
- Continuous: adopt and maintain the program, comply with it, review it regularly and keep it up to date. Annual report due within 90 days after the end of each financial year, to the relevant Commonwealth regulator or, if none, to the Secretary of Home Affairs.
- Frequency
- Ongoing
- Evidence to keep
- The written risk management program and its adoption record; hazard and material-risk assessment covering each asset; evidence of compliance with the program; review schedule and update log; the annual report in the approved form stating whether the program was up to date, evaluating any hazard with a significant relevant impact, and showing board, council or governing-body approval.
- Status
- Current
- Priority
- Critical
Penalty for not complying
Maximum penalty: Failing to adopt and maintain, comply with, review or update the program: 200 penalty units ($72,800) each (ss 30AC-30AF). Failing to give an annual report that meets s 30AG: 150 penalty units ($54,600) (s 30AG). A court can order a body corporate to pay up to 5 times these amounts, for example $364,000 for a 200-unit provision (Regulatory Powers (Standard Provisions) Act 2014 s 82(5))
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
Obligations with the same applicability test
If this obligation applies to you, so do these 5: the engine uses the same rule for each.
Where it sits in the corpus
Rules Mate tracks 5 published obligations tagged "soci", 2 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated critical priority, and is an ongoing duty.
Regulator, legislation and tools
Regulated by Cyber and Infrastructure Security Centre — Department of Home Affairs.
Home Affairs (SOCI): Administers the Security of Critical Infrastructure Act 2018 — registration, risk management programs, and mandatory cyber incident reporting for critical infrastructure assets.
SOCI Act: Federal critical infrastructure protection regime.
Free tools that help with this obligation:
Questions
- Who must comply with SOCI Positive Security Obligation (PSO) per sector?
- Applies when the business has a critical infrastructure asset.
- Do sole traders need to comply with SOCI Positive Security Obligation (PSO) per sector?
- No. Across every industry and every size band, the engine's answer for a sole trader is: no.
- Do businesses with 1–5 employees need to comply with SOCI Positive Security Obligation (PSO) per sector?
- No (1–5 employees, turnover $100K–$1M).
- When is "Comply with SOCI Positive Security Obligation (PSO) per sector" due?
- Continuous: adopt and maintain the program, comply with it, review it regularly and keep it up to date. Annual report due within 90 days after the end of each financial year, to the relevant Commonwealth regulator or, if none, to the Secretary of Home Affairs.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.