Overlap GuideAustraliaCyber Security Act and SOCI Act

Australia Cyber Security Act and SOCI Act overlap

The Cyber Security Act 2024 does not supersede the Security of Critical Infrastructure Act 2018. It adds separate smart-device, ransomware payment reporting, incident coordination, and review-board machinery, while using SOCI status to decide when some entities are in ransomware reporting scope.

This page helps separate product duties from critical-infrastructure duties, identify the responsible entity, and keep evidence that shows which law triggered each action.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
11

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Critical-infrastructure operators, product teams, incident responders, and compliance owners need separate scope checks under the Australia Cyber Security Act 2024 and the Security of Critical Infrastructure Act 2018. The checks are whether an entity is a SOCI for a , whether the ransomware payment reporting rules apply, whether a smart-device obligation is separate from SOCI, and what evidence should be retained for each track.

Section 1

Where the Cyber Security Act and SOCI Act overlap

The clearest statutory overlap is ransomware payment reporting. Cyber Security Act section 26 treats an entity as a if, when the ransomware payment is made, it is a for a to which SOCI applies. SOCI status can therefore bring an impacted entity into Cyber Security Act ransomware reporting without the $3 million turnover test used for other businesses.

Keep the SOCI scope analysis separate from the Cyber Security Act event analysis. The SOCI record should show the asset, sector, , whether applies, the impact category, and the time the entity became aware. The Cyber Security Act record should show whether there is a cyber security incident, a demand, a ransomware payment or benefit, and the 72-hour reporting clock if a payment is made or discovered.

  • Identify the and the before deciding ransomware reporting scope.
  • Record whether the relevant SOCI obligation is mandatory cyber incident reporting or Part 2A risk management program work. Part 2B reports are due as soon as practicable and within 12 hours for a critical incident, or within 72 hours for another incident with a relevant impact.
  • If the first SOCI report is oral, retain the approved-form written follow-up: within 84 hours after a critical-incident report or within 48 hours after another relevant-impact report, unless the relevant Commonwealth body grants an exemption.
  • Do not merge SOCI incident notification evidence with Cyber Security Act ransomware payment evidence; the reports serve different legal triggers.
  • Escalate when the same incident affects a , a consumer smart-device product, and a ransomware payment decision.
Section 2

Responsible-entity and critical-infrastructure evidence

The overlap analysis should start with an asset register entry, not a generic cyber incident ticket. For SOCI purposes, the useful record identifies the asset, why it is treated as a , the , and whether the relevant SOCI Part applies to the asset.

For risk management program overlap, keep the Cyber Security Act incident evidence beside the SOCI all-hazards record but do not make them substitutes. Home Affairs guidance for the critical infrastructure risk management program describes material-risk work across cyber and information security, personnel, supply chain, and physical or natural hazards. A ransomware event may inform that program, but the Cyber Security Act ransomware report still needs its own payment, demand, and communication fields.

  • Asset evidence: asset name, sector classification, operational owner, , and SOCI Part 2A or applicability.
  • Incident evidence: incident timeline, affected systems, infrastructure and customer impact, malware or ransomware variant if known, and exploited vulnerabilities if known.
  • Governance evidence: who approved SOCI reporting, who approved any ransomware-payment report, and who reviewed legal privilege or protected-information handling.
  • Risk evidence: whether the event changes the SOCI risk management program, including cyber and information security hazards and related supply-chain dependencies.
Section 3

Ransomware reporting when a SOCI entity is involved

For a SOCI , the ransomware question is not limited to annual turnover. Cyber Security Act section 26 includes responsible entities for critical infrastructure assets to which SOCI applies. The Ransomware Payment Reporting Rules separately prescribe a $3 million threshold for other businesses, and section 26 requires turnover to exceed it. The current cyber.gov.au form says "equal to or exceeds $3 million," so an entity at exactly $3 million should confirm the filing position promptly. SOCI responsible-entity status should be checked first when a is affected.

The report clock is triggered by the ransomware payment facts, not by completion of the broader incident investigation. The Cyber Security Act requires the report within 72 hours after the entity makes the payment or becomes aware that another entity made it on the 's behalf. The rules require information only to the extent the reporting business entity knows it or can find it by reasonable search or enquiry within that period.

  • Capture whether the entity is a SOCI for a to which applies.
  • Capture whether another entity paid on the 's behalf, because the Cyber Security Act trigger covers awareness of that payment.
  • Capture ABN and address details for the and any other entity that made the payment where those details are required and known.
  • Capture the demand, payment amount or non-monetary benefit, method of provision, communications, and pre-payment negotiations required by the ransomware rules.
  • File the Cyber Security Act report through the current ransomware and cyber extortion payment form, while preserving a separate submission record for any SOCI incident notification.
Section 4

Keep smart-device duties separate from SOCI duties

The Cyber Security Act smart-device regime is a product compliance track. Cyber Security Act Part 2 commenced on 29 November 2025. Part 2 and Schedule 1 of the Smart Devices Rules, which contain the consumer-grade standard and statement requirements, commenced on 4 March 2026. The Rules cover consumer grade relevant connectable products intended, or likely, to be used for personal, domestic, or household use or consumption when the manufacturer or supplier is aware, or could reasonably be expected to be aware, that a consumer will acquire the product in Australia. Listed exclusions include desktop and laptop computers, tablets, smartphones, therapeutic goods, road vehicles, and road vehicle components.

That product track can sit beside, but should not be blended with, SOCI obligations. A consumer energy product or connected device may need product-scope, security-standard, statement-of-compliance, support-period, and security-issue-reporting evidence. A critical-infrastructure operator may separately need SOCI asset, responsible-entity, incident-reporting, and risk-management evidence. The same incident can touch both tracks, but each track needs its own source, owner, trigger, and record.

  • Smart-device evidence: product type, batch identifier, manufacturer details, support period, statement of compliance, password controls, security issue reporting, and security-update support.
  • SOCI evidence: classification, , Part 2A risk management program, incident-reporting applicability, and any protected-information handling.
  • Separation rule: do not use a smart-device statement of compliance as proof that SOCI risk management or incident reporting obligations have been met.
  • Review trigger: reopen both tracks when a product is used in a critical infrastructure environment or a critical-infrastructure incident involves consumer-grade connected products.
Section 5

Practical overlap record to keep

Keep a two-column evidence file: one side for Cyber Security Act obligations and one side for SOCI Act obligations. Each row should show the source provision, factual trigger, accountable owner, evidence, report or action taken, and unresolved assumptions.

For a ransomware incident affecting a , the record should be specific enough to prove why the entity was or was not a Cyber Security Act , whether SOCI applied, whether a ransomware payment was made by the entity or on its behalf, and what information was known or reasonably searchable within the reporting period.

  • Scope row: asset, , product, business activity in Australia, SOCI Part, and Cyber Security Act Part.
  • Trigger row: cyber security incident, critical-infrastructure impact, ransomware demand, payment or benefit, smart-device non-compliance, or recall notice.
  • Action row: SOCI notification, ransomware payment report, National Cyber Security Coordinator voluntary sharing, statement of compliance, product notice, or risk-management update.
  • Evidence row: source citation, incident ticket, asset register extract, payment approval record, communications log, statement of compliance, and reviewer approval.
Primary sources

References and citations

legislation.gov.au
Referenced sections
  • The Act grounds the separate Cyber Security Act rows for ransomware reports, smart-device statements, and voluntary incident coordination.
"Interaction with other requirements to provide information"
legislation.gov.au
Referenced sections
  • The explanatory statement explains that products are commonly called smart devices and may include hardware plus external software.
"hardware and internal software"
legislation.gov.au
Referenced sections
  • The SOCI Act table of contents identifies responsible entity, cyber security incident, and critical infrastructure asset provisions used in the overlap checklist.
"Meaning of responsible entity"
Related guides

Explore more topics

Australia Compliance Statement Evidence Workflow
Evidence workflow for preparing, supplying, and retaining statements of compliance under Australia's Cyber Security Act 2024 and Smart Devices Rules.
Australia Cyber Security Act 2024 scope and definitions
Official source scope guide for Australia's Cyber Security Act 2024: relevant connectable products, consumer-grade smart devices, reporting business entities, ransomware payment reports, and SOCI overlap.
Australia Cyber Security Act Applicability Test
Decide whether the Australia Cyber Security Act 2024 applies to a smart-device product, supplier, manufacturer, or ransomware payment reporting scenario.
Australia Cyber Security Act Commencement Timeline
Cyber Security Act 2024 commencement timeline for ransomware reporting, CIRB reviews, smart-device duties, statement retention, and statutory review.
Australia Cyber Security Act Compliance Checklist
Concrete checklist items for Australian Cyber Security Act smart-device and ransomware duties, with SOCI and APRA CPS 234 evidence checks.
Australia Cyber Security Act Compliance Guide
A cited compliance guide for Australia Cyber Security Act smart-device statements, ransomware payment reporting, incident coordination, and review-board readiness.
Australia Cyber Security Act Deadlines and Calendar
Cyber Security Act 2024 dates and event-driven deadlines for ransomware payment reports, smart-device duties, records, notices, and statutory review.
Australia Cyber Security Act FAQ
Answers to Australia Cyber Security Act questions on smart device scope, statements of compliance, ransomware reports, enforcement notices, and incident review.
Australia Cyber Security Act penalties and fines
Cyber Security Act 2024 civil penalties explained by section, including ransomware reports, protected information, CIRB notices, and smart-device enforcement.
Australia Cyber Security Act recordkeeping FAQ
What records to keep for Cyber Security Act 2024 smart-device statements, ransomware payment reports, and supported SOCI or APRA overlap checks.
Australia Cyber Security Act Requirements
Australia Cyber Security Act requirements for smart-device security standards, statements of compliance, ransomware payment reports, notices, and evidence records.
Australia Cyber Security Act Statement of Compliance Evidence
Evidence guide for Australia Cyber Security Act smart-device statements of compliance: required fields, manufacturer and supplier records, five-year retention, and examination readiness.
Australia Cyber Security Act templates
Source-backed field lists for Australia Cyber Security Act smart-device scope, statements of compliance, ransomware reports, notices, SOCI overlap, and records.
Australia Cyber Security Act vs EU Cyber Resilience Act
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
Australia Cyber Security Act vs UK PSTI Act Guide
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
Australia ransomware payment reporting 72-hour duty
Explain when Australia's Cyber Security Act 2024 requires a ransomware payment report, when the 72-hour clock starts, and what information the report must contain.
Australia Ransomware Payment Reporting Workflow
Operational workflow for Australia Cyber Security Act 2024 ransomware payment reports: scope, 72-hour trigger, report fields, owners, evidence, and cited Act and Rules sources.
Australia Ransomware Payment Reporting: Threshold and Report Content
FAQ answer on Australia's Cyber Security Act ransomware payment reporting scope, $3 million turnover threshold, 72-hour trigger, report fields, and evidence.
Australia Smart Device Applicability Workflow
Decide whether Australia's mandatory smart-device security standard applies, including commencement, connectivity, consumer use, exclusions, roles, and evidence.
Australia Smart Device Compliance Statement
What a smart-device statement of compliance must contain under Australia's Cyber Security Act 2024 and Smart Devices Rules, who prepares and supplies it, how long to retain it, and how to prepare for examination.
Australia Smart Device Security Standards under the Cyber Security Act
Plain-English guide to Australia's Cyber Security (Security Standards for Smart Devices) Rules 2025: scope, passwords, vulnerability reporting, support periods, statements of compliance, and evidence records.
CSA 2024 Smart Device Applicability Test
Check whether a smart device is a consumer-grade relevant connectable product under Australia's Cyber Security Act and Smart Devices Rules.
Cyber Security Act 2024 Smart Device Compliance Checklist
Checklist for Australia Cyber Security Act 2024 smart-device scope, password controls, vulnerability reporting, security-update support periods, statements of compliance, retention, and evidence.
Cyber Security Act 2024 Statements of Compliance FAQ
Australian smart-device statements of compliance: covered products, responsible actors, required contents, supporting evidence, and five-year retention.
Cyber Security Act vs EU CRA: scope and obligations comparison
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
Cyber Security Act vs UK PSTI Act: device security obligations compared
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
How do notices and recalls work under the Australia Cyber Security Act?
FAQ on Australia Cyber Security Act compliance notices, stop notices, recall notices, public notifications, owners, evidence fields, and cited timing.
How does the Australia Cyber Security Act overlap with the SOCI Act?
FAQ on when Australia Cyber Security Act ransomware reporting overlaps with SOCI critical infrastructure assets, responsible entities, and smart-device duties.
Manufacturer, Importer, and Supplier Duties under Australia's Cyber Security Act 2024
Cyber Security Act 2024 smart-device duties for manufacturers, importers, and suppliers, including role tests, scope, statements, and records.
SOCI overlap triage workflow for Australia Cyber Security Act
Triage SOCI Act overlap with Australia Cyber Security Act ransomware reporting and smart-device standards using separate owners, evidence, and cited scope checks.
Which smart devices are in scope under Australia's Cyber Security Act 2024?
FAQ on Cyber Security Act 2024 smart-device scope: relevant connectable products, consumer-grade criteria, exclusions, Australian consumer acquisition, and records to keep.