Artifact GuideAustraliaSOCI Overlap Triage Workflow

SOCI overlap triage for the Cyber Security Act

Use this workflow when one Australian cyber issue may touch the Security of Critical Infrastructure Act 2018, the Cyber Security Act 2024 ransomware-payment rules, or the smart-device security standards.

Identify the responsible entity and critical-infrastructure asset first. Then decide whether Part 2B incident reporting, Part 2A risk-management evidence, Part 3 ransomware reporting, or smart-device compliance needs its own owner and record.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

overlap triage starts by asking which legal stream the facts belong to. A for a may have SOCI register, risk-management-program, and cyber incident work. The same incident can also trigger Cyber Security Act reporting if a makes a payment or becomes aware that another entity made one on its behalf. A smart device raises a separate product-security question unless the device or service is also part of a critical-infrastructure asset.

Section 1

Separate SOCI, ransomware, and smart-device streams

Open the triage record with three yes-or-no lanes. Lane one is : is there a , a , and a Part 2, , or obligation? Lane two is Cyber Security Act Part 3: did a make, or become aware that another entity made on its behalf, a after a cyber security incident? Lane three is smart-device compliance: is the product a that the or knows, or could reasonably be expected to know, will be acquired in Australia by a ?

Do not merge the evidence packs. incident reporting, reporting, and smart-device statements of compliance answer different questions and may be handled by different owners even when the same event or product family triggered the review.

  • lane: record the asset name, asset class, , operational owner, and whether the question concerns the Register of Critical Infrastructure Assets, the critical infrastructure risk management program, or mandatory cyber incident reporting.
  • Ransomware lane: record the cyber security incident, impacted , demand, payment or benefit, payment maker, awareness time, and whether the $3 million turnover threshold or responsible-entity limb is the basis for scope.
  • Smart-device lane: record the product type, , , -acquisition basis, exemption check, statement of compliance, password design evidence, vulnerability-reporting contact, and .
  • Overlap result: assign each lane a separate owner, source citation, evidence location, reviewer, and status so a product-security record is not mistaken for a asset record or report.
Section 2

Responsible-entity and critical-infrastructure asset check

The branch should start with the asset, not a generic organisation name. Section 12L identifies the separately for each asset class; it is not a single across-the-board test that can safely be reduced to whoever owns or operates the asset. Record the applicable asset provision and the person or organisation that provision designates.

Once the asset and are identified, check which obligation is in play. Part 2 concerns the Register of Critical Infrastructure Assets. concerns the critical infrastructure risk management program. concerns mandatory cyber incident reporting. The Application Rules are the source to check whether Part 2 or Part 2B applies to the relevant asset class.

For , use the 10 June 2026 compilation of the program rules. now apply to specified broadcasting, domain-name-system, electricity, energy-market-operator, freight, gas, liquid-fuel, and water assets. Section 4A gives existing covered assets 12 months from commencement for section 6A and specified parts of sections 8A and 9A, and 24 months for the other enhanced provisions; an asset that becomes critical infrastructure later receives the corresponding period from that date.

  • Evidence to request: asset-class analysis, responsible-entity rationale, corporate ownership or operating-control evidence, service or system architecture, third-party data storage or processing dependency, and any prior register submission or update record.
  • Part 2 outcome: if the issue concerns register information or notifiable events, route it to the owner who maintains operational and ownership information for the Register of Critical Infrastructure Assets.
  • outcome: if the issue concerns ongoing resilience, route it to the critical infrastructure risk management program owner and link the hazard, material-risk assessment, selected controls, and annual-report evidence.
  • outcome: if the issue is a cyber incident affecting the asset, route it to the incident-reporting owner and keep the Part 2B report record separate from any report under the Cyber Security Act 2024.
Section 3

Part 2B and ransomware-payment triage

Treat a cyber incident report and a Cyber Security Act report as separate filings. Part 2B belongs to the SOCI critical-infrastructure stream. The Cyber Security Act Part 3 stream applies when the ransomware-payment conditions are met: a is impacted by a cyber security incident and provides, or becomes aware that another entity provided on its behalf, a payment or benefit to the extorting entity.

Start the clock from awareness of the qualifying impact on the covered asset: within 12 hours for a critical incident that materially disrupts essential goods or services, or within 72 hours for another incident with a relevant impact. Start the ransomware clock from the payment or awareness of an on-behalf payment. Build the ransomware record around what the knows or can find out by reasonable search or enquiry within that separate 72-hour period.

  • Scope gate: identify whether the entity is a for a to which applies, or is carrying on business in Australia above the ransomware-reporting turnover threshold.
  • reporting gate: determine whether the incident has a significant impact on asset availability or another relevant impact. An oral critical-incident report needs an approved-form written record within 84 hours unless exempted; an oral report about another relevant-impact incident needs one within 48 hours unless exempted.
  • Trigger gate: confirm a cyber security incident, the direct or indirect impact on the , the demand by the extorting entity, and the payment or benefit directly related to that demand.
  • Report content: capture and address where required, incident timing and awareness, infrastructure and customer impact, ransomware or malware variant, exploited vulnerabilities, demand quantum and method, payment quantum and method, and communications with the extorting entity.
  • Cyber Security Act section 44 says information provided under Part 4 does not affect other Commonwealth information requirements, so do not close the question merely because a coordinator information-sharing record exists. Assess any Part 3 ransomware report separately.
Section 4

Smart-device separation check

The smart-device branch is product compliance, not critical-infrastructure asset classification. Cyber Security Act Part 2 commenced on 29 November 2025, while Part 2 and Schedule 1 of the Smart Devices Rules, which contain the -grade standard and statement requirements, commenced on 4 March 2026. Use this branch for consumer grade relevant connectable products that can directly or indirectly connect to the internet when the or is aware, or could reasonably be expected to be aware, that a consumer will acquire the product in Australia, subject to the Rules' exclusions. The Rules set the binding scope test; the official explanatory statement gives smart TVs, smart watches, home assistants, baby monitors, and consumer energy resources as examples, but each product still needs its own connectivity, intended-use, acquisition, awareness, date, and exclusion analysis. A smart product used inside a critical-infrastructure environment may create operational risk evidence for , but the statement-of-compliance and security-standard evidence remain product records.

The Rules require a -prepared statement of compliance for covered products and set product-security evidence around passwords, reporting security issues, and defined support periods for security updates. Suppliers have their own supply-side check because the Rules outline when non-compliant products must not be supplied and when products must be supplied with the statement of compliance.

  • Product scope evidence: product type, intended use, -acquisition basis, direct or indirect internet connectivity, exemption analysis, identity, identity, and Australian supply channel.
  • Security-standard evidence: password design showing user-defined or unique-per-product passwords, published security-issue reporting contact and update process, and the for security updates.
  • Statement evidence: product type and batch identifier, and details, compliance declaration, , signatory, place and date of issue, and retention owner for the five-year statement period.
  • bridge: if the product is deployed in a critical-infrastructure asset, link the smart-device evidence into the SOCI material-risk or -risk record without treating the product statement as proof that SOCI or is satisfied.
Section 5

Evidence and owner matrix for the triage record

Keep the overlap triage record after the incident or product release. It should show why a lane was opened or closed, who owned it, which official source supported the decision, what evidence was reviewed, and which record remains authoritative for later audit or regulator questions.

Use a short matrix rather than a narrative memo. Each row should identify the lane, trigger fact, obligation checked, owner, evidence, source, decision, reviewer, and follow-up. Mark unknown facts as unknown and assign a collection owner instead of filling gaps with assumptions.

  • Legal or compliance owner: approves the asset, responsible-entity, Part 2, , , ransomware, and smart-device scope decisions against the cited sources.
  • Asset owner: confirms the critical-infrastructure asset, essential function, operational dependencies, third-party providers, and whether a hazard or incident has a relevant impact on the asset.
  • Security incident owner: maintains incident timing, impact, exploited vulnerabilities, malware or ransomware indicators, containment evidence, report status, and other regulator-notification cross-references.
  • Product owner: maintains smart-device scope, and evidence, statement of compliance, password controls, vulnerability-reporting publication, and support-period publication.
  • Finance or procurement owner: confirms facts, payment maker, payment method, demand details, role, and contracts that may affect evidence collection.
Primary sources

References and citations

legislation.gov.au
Referenced sections
  • Supports collecting ransomware payment, demand, communications, incident impact, ABN, address, malware, vulnerability, and payment-method evidence in the payment-reporting lane.
"communications with the extorting entity"
legislation.gov.au
Referenced sections
  • Supports treating smart-device security standards as a Cyber Security Act Part 2 product-compliance stream rather than a SOCI asset-class decision.
"Security standards for smart devices"
legislation.gov.au
Referenced sections
  • Supports keeping SOCI evidence tied to the relevant asset, responsible entity, register, risk-management-program, incident-reporting, and protected-information provisions.
"Register of Critical Infrastructure Assets"
Related guides

Explore more topics

Australia Compliance Statement Evidence Workflow
Evidence workflow for preparing, supplying, and retaining statements of compliance under Australia's Cyber Security Act 2024 and Smart Devices Rules.
Australia Cyber Security Act 2024 scope and definitions
Official source scope guide for Australia's Cyber Security Act 2024: relevant connectable products, consumer-grade smart devices, reporting business entities, ransomware payment reports, and SOCI overlap.
Australia Cyber Security Act and SOCI Act overlap
How the Australia Cyber Security Act overlaps with the Security of Critical Infrastructure Act for responsible entities, ransomware payment reporting, smart devices, and evidence records.
Australia Cyber Security Act Applicability Test
Decide whether the Australia Cyber Security Act 2024 applies to a smart-device product, supplier, manufacturer, or ransomware payment reporting scenario.
Australia Cyber Security Act Commencement Timeline
Cyber Security Act 2024 commencement timeline for ransomware reporting, CIRB reviews, smart-device duties, statement retention, and statutory review.
Australia Cyber Security Act Compliance Checklist
Concrete checklist items for Australian Cyber Security Act smart-device and ransomware duties, with SOCI and APRA CPS 234 evidence checks.
Australia Cyber Security Act Compliance Guide
A cited compliance guide for Australia Cyber Security Act smart-device statements, ransomware payment reporting, incident coordination, and review-board readiness.
Australia Cyber Security Act Deadlines and Calendar
Cyber Security Act 2024 dates and event-driven deadlines for ransomware payment reports, smart-device duties, records, notices, and statutory review.
Australia Cyber Security Act FAQ
Answers to Australia Cyber Security Act questions on smart device scope, statements of compliance, ransomware reports, enforcement notices, and incident review.
Australia Cyber Security Act penalties and fines
Cyber Security Act 2024 civil penalties explained by section, including ransomware reports, protected information, CIRB notices, and smart-device enforcement.
Australia Cyber Security Act recordkeeping FAQ
What records to keep for Cyber Security Act 2024 smart-device statements, ransomware payment reports, and supported SOCI or APRA overlap checks.
Australia Cyber Security Act Requirements
Australia Cyber Security Act requirements for smart-device security standards, statements of compliance, ransomware payment reports, notices, and evidence records.
Australia Cyber Security Act Statement of Compliance Evidence
Evidence guide for Australia Cyber Security Act smart-device statements of compliance: required fields, manufacturer and supplier records, five-year retention, and examination readiness.
Australia Cyber Security Act templates
Source-backed field lists for Australia Cyber Security Act smart-device scope, statements of compliance, ransomware reports, notices, SOCI overlap, and records.
Australia Cyber Security Act vs EU Cyber Resilience Act
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
Australia Cyber Security Act vs UK PSTI Act Guide
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
Australia ransomware payment reporting 72-hour duty
Explain when Australia's Cyber Security Act 2024 requires a ransomware payment report, when the 72-hour clock starts, and what information the report must contain.
Australia Ransomware Payment Reporting Workflow
Operational workflow for Australia Cyber Security Act 2024 ransomware payment reports: scope, 72-hour trigger, report fields, owners, evidence, and cited Act and Rules sources.
Australia Ransomware Payment Reporting: Threshold and Report Content
FAQ answer on Australia's Cyber Security Act ransomware payment reporting scope, $3 million turnover threshold, 72-hour trigger, report fields, and evidence.
Australia Smart Device Applicability Workflow
Decide whether Australia's mandatory smart-device security standard applies, including commencement, connectivity, consumer use, exclusions, roles, and evidence.
Australia Smart Device Compliance Statement
What a smart-device statement of compliance must contain under Australia's Cyber Security Act 2024 and Smart Devices Rules, who prepares and supplies it, how long to retain it, and how to prepare for examination.
Australia Smart Device Security Standards under the Cyber Security Act
Plain-English guide to Australia's Cyber Security (Security Standards for Smart Devices) Rules 2025: scope, passwords, vulnerability reporting, support periods, statements of compliance, and evidence records.
CSA 2024 Smart Device Applicability Test
Check whether a smart device is a consumer-grade relevant connectable product under Australia's Cyber Security Act and Smart Devices Rules.
Cyber Security Act 2024 Smart Device Compliance Checklist
Checklist for Australia Cyber Security Act 2024 smart-device scope, password controls, vulnerability reporting, security-update support periods, statements of compliance, retention, and evidence.
Cyber Security Act 2024 Statements of Compliance FAQ
Australian smart-device statements of compliance: covered products, responsible actors, required contents, supporting evidence, and five-year retention.
Cyber Security Act vs EU CRA: scope and obligations comparison
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
Cyber Security Act vs UK PSTI Act: device security obligations compared
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
How do notices and recalls work under the Australia Cyber Security Act?
FAQ on Australia Cyber Security Act compliance notices, stop notices, recall notices, public notifications, owners, evidence fields, and cited timing.
How does the Australia Cyber Security Act overlap with the SOCI Act?
FAQ on when Australia Cyber Security Act ransomware reporting overlaps with SOCI critical infrastructure assets, responsible entities, and smart-device duties.
Manufacturer, Importer, and Supplier Duties under Australia's Cyber Security Act 2024
Cyber Security Act 2024 smart-device duties for manufacturers, importers, and suppliers, including role tests, scope, statements, and records.
Which smart devices are in scope under Australia's Cyber Security Act 2024?
FAQ on Cyber Security Act 2024 smart-device scope: relevant connectable products, consumer-grade criteria, exclusions, Australian consumer acquisition, and records to keep.