OTSecurity

Australia’s CISC strengthens critical infrastructure compliance under SOCI Act with tiered regulatory measures


Australia’s Critical Infrastructure Security Centre is shifting toward a more formal enforcement posture in 2026-27, introducing tiered regulatory mechanisms to address non-compliance under the Security of Critical Infrastructure Act. The move sharpens the evolving regulatory posture, marking a departure from the agency’s emphasis on partnership and education, prompted by changes in the threat environment and recommendations from an independent review of the legislation.

The CISC will now employ three escalating compliance tools, including Regulatory Guidance Notices for gaps below the non-compliance threshold, formal Non-Compliance Notices for identified violations, and Enforcement Actions, including infringement notices for serious or persistent breaches. The agency said it will weigh factors including the severity of misconduct, entity conduct, public benefit and likelihood of behavioral change when determining which enforcement pathway to pursue, signaling a proportionate but firmer regulatory approach to protecting Australia’s critical infrastructure.

“In 2026-27, the CISC is evolving its regulatory compliance posture in response to changes in the threat environment and recommendations of the 2026 Independent Review of the SOCI Act,’ the CISC said in a recent statement. “Working in partnership with regulated entities to promote education and awareness of SOCI obligations will continue. This will be complemented by a greater focus on a range of measures to address potential or identified non-compliance with SOCI obligations.” 

Depending on the findings of compliance assessments, responses may take one of three forms.

First, Regulatory Guidance Notices (RGNs) will be issued to an entity where a gap below the non-compliance threshold has been identified. RGNs are educative and corrective in intent, and they seek to clarify and resolve potential non-compliance matters before non-compliance is formally identified.

Second, Non-Compliance Notices (NCNs) are formal notices to an entity, confirming that non-compliance with the SOCI Act has been identified. Depending on the nature of the contravention, an NCN may require “no action” and simply notify the entity of the non-compliance, or it may include a return-to-compliance process that the CISC will monitor and track.

Third, Enforcement Actions, particularly issuing of infringement notices, may be taken as the case requires. The CISC may issue an infringement notice in response to any potential or identified non-compliance, for example in instances of serious or persistent non-compliance, or where a significant unmitigated national security threat is present. 

Infringement notices support the CISC’s regulatory approach by providing a clear and practical pathway for addressing non-compliance and helping industry return to compliance. Where the recipient meets the requirements of an infringement notice, the matter is considered resolved, and no further regulatory action will be taken in relation to the alleged contravention. Importantly, responding to an infringement notice does not mean the recipient is admitting wrongdoing. However, where the issue is not resolved, the CISC will consider further regulatory options, which can include court-based action in appropriate circumstances.

“The CISC will continually review our activities based on the results and impact on industry,” according to the statement. “As the threat environment evolves over time, we will also develop our activities and amend our processes to ensure we are achieving the objectives of the SOCI Act in enhancing critical infrastructure resilience and protecting Australia’s economy, security and community wellbeing.”

In deciding which compliance action to pursue, the CISC will consider the circumstances of each case. Depending on the facts and evidence, this may result in one or more forms of enforcement action, or an alternative regulatory outcome. Factors the CISC will consider include nature and seriousness of the suspected misconduct, conduct of the person or entity after the suspected misconduct, expected public benefit in taking enforcement action, and likelihood of behavioural improvement and deterrence for the regulated entity and other regulated entities. It will also look into whether the misconduct was isolated and the level of harm caused, and whether the misconduct was inadvertent and whether it has been self-reported.



Source link