DrochaidHorizon3.ai
NodeZero/Australia & NZ compliance/SOCI CIRMP
Australia & NZ compliance

SOCI Act — Critical Infrastructure Risk Management Program

The mandatory risk management program for Australian critical infrastructure operators under the Security of Critical Infrastructure Act 2018. Responsible entities must manage material risks across cyber, personnel, supply chain, and physical hazard vectors.

See where NodeZero applies

What is SOCI CIRMP?

The Security of Critical Infrastructure Act 2018 (amended in 2021 and 2022) requires responsible entities for critical infrastructure assets to establish and maintain a Critical Infrastructure Risk Management Program. The SOCI Act covers 11 sectors and 22 asset classes -- from energy and water to financial services, telecommunications, and data storage. If your organisation is the responsible entity for an asset class specified in the CIRMP Rules, you are legally required to have and comply with a CIRMP that addresses four hazard vectors: cyber and information security, personnel, supply chain, and physical security and natural hazards.

For the cyber hazard, entities must adopt and maintain one of five named frameworks — the Essential Eight (Maturity Level 1), NIST CSF, ISO 27001, C2M2 (MIL-1), or AESCSF (SP-1) — or an equivalent framework. The rules set those minimum maturity levels where a framework defines them, require the program to be appropriate to the nature of the asset, and require the annual report on the program to be board-approved. CISC can audit your program, and entities must report incidents with a significant impact on the asset's availability within 12 hours, and incidents with a relevant impact within 72 hours.

CISC — CIRMP obligations

Where NodeZero applies

NodeZero produces direct technical evidence across the cyber-related sections of the CIRMP — validating the material risks defined in s 6, evidencing the s 7 identification and currency duties, and testing the cyber framework controls required by s 8. For personnel, supply chain, and physical hazards, we clearly identify what sits outside the scope of technical testing so your compliance team can address those obligations through governance and process controls.

SOCI CIRMP Rules 2023 (as amended Apr 2025)

This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.

Please note the following requires separate evidence: Physical security hazards and natural hazards.

Showing coverage grouped by compliance category.

Material risk

Validates which material risks defined in s 6 are actually exploitable in your environment.

Internal pentestingCore

Chains attack paths to assets whose compromise would cause operational stoppage — concrete evidence of which technical weaknesses constitute the material risk s 6(a) calls out.

External pentestingCore

Tests the internet-facing remote-access surface to operational control and monitoring systems — surfaces the exact remote-access exposure s 6(e) classifies as material risk.

Advanced Data PilferingElite only

Auto-classifies the business-critical data an attacker could actually reach, mapped to 12 business-risk categories — concrete evidence of whether the confidentiality of the data storage system can be breached — which business-critical data an attacker could actually reach and take.

Cloud pentestingCore

For cloud-hosted data storage (AWS, Azure/Entra ID), a credentialed cloud pentest enumerates resources and proves IAM misconfiguration, privilege-escalation and lateral-movement paths to storage — including demonstrated Entra ID Global Admin compromise with no CVE — additional direct evidence of whether a cloud-hosted data storage system can be breached.

5 controls mapped

General — all hazards

Produces evidence for the identification and currency obligations that apply across every hazard vector.

Internal pentestingCore

Every NodeZero pentest produces a ranked list of validated material risks against the CI asset — direct technical evidence the CIRMP can register against the s 7(1)(b) identification obligation.

Rapid ResponsePro & Elite

Delivers targeted tests for newly disclosed critical CVEs — often within hours of disclosure, and in some cases ahead of the public patch — so the CIRMP can stay current in response to changes in the cyber threat landscape.

Vulnerability Management HubCore

Tracks every proven weakness through an Open → Mitigated → Regressed lifecycle, with Quick Verify re-running the exact attack path to confirm a fix actually closed the gap (internal environments) — the open-to-verified-closed remediation record that keeps the CIRMP current on more than identification alone, and supports the s 8(2)(a) duty to minimise material cyber risk.

3 controls mapped

Cyber and information security hazards

Tests technical IT security controls relevant to the entity's chosen cyber framework.

Internal pentestingCore

Behaves like a real attacker — chains exploitable weaknesses into end-to-end attack paths to surface the material cyber risks your CIRMP has to eliminate or mitigate.

Web application pentestingPriced separately

Where the critical infrastructure asset includes customer or operational web applications, WebApp Pentesting tests them for exploitable weaknesses that chain into credential compromise and host takeover — one class of material cyber hazard the section 8(2) duty covers. OT and SCADA environments remain outside NodeZero's scope.

NodeZero TripwiresPro & Elite

Drops decoy AD accounts baited for kerberoasting and AS-REP roasting during a test — any interaction is malicious by definition, so it proves in production whether your SOC can see an attacker moving against AD, direct evidence of mitigating the impact of a cyber hazard through detection.

External pentestingCore

The s 8(4) table lists five frameworks (Essential Eight, NIST CSF, ISO 27001, C2M2, AESCSF). Whichever framework the entity adopts, NodeZero produces the technical evidence — proof-of-exploit and attack-path summaries — you can put in front of a CISC reviewer to show whether the chosen framework is actually implemented, not just documented.

3 controls mapped

Personnel hazards

Minimal coverage. NodeZero validates technical outcomes of insider-risk scenarios, not personnel vetting.

Insider Threat TestingCore

Takes an insider perspective and proves the real-world impact a malicious or negligent employee or contractor could have on the CI asset — technical validation of the s 9(1)(c)(i) material risk.

AD Password AuditCore

Surfaces weak, breached and reused credentials on still-active accounts and computes the blast radius one such credential unlocks — supporting evidence of residual access risk. For access that lingers after off-boarding, pair with Insider Threat Testing, which proves the reach of stale or over-provisioned accounts.

2 controls mapped

Supply chain hazards

Minimal coverage. NodeZero tests the technical boundary where a supplier compromise would land in your environment.

Segmentation testingCore

Proves whether a compromise at a supplier interconnect would actually be contained by segmentation, or would cascade into your critical infrastructure asset.

Insider Threat TestingCore

Starts from a supplier-style authenticated position and proves the real blast radius that a provider's access could reach — the risk s 10(1)(a)(ii) calls out.

Internal pentestingCore

Chains attack paths originating in third-party systems through to the CI asset — evidence of how a supply-chain issue would actually propagate.

4 controls mapped
SOCI CIRMP kit

See every control mapped to NodeZero

The full control-by-control coverage map — every SOCI CIRMPrequirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.

Who does this apply to?

CIRMP obligations apply to responsible entities for critical infrastructure assets in the asset classes specified in the CIRMP Rules -- often the operator rather than the owner. The Act covers 11 sectors and 22 asset classes: energy (electricity, gas, liquid fuel), water and sewerage, communications (telecommunications, broadcasting), financial services and markets, health care and medical, food and grocery, transport (ports, airports, freight), space technology, defence industry, higher education and research, and data storage or processing.

If your organisation is the responsible entity for a covered asset, you are legally required to have and comply with a CIRMP that addresses all four hazard vectors. The program must be reviewed at least annually, and the annual report on it must be approved by your board (or governing body) and submitted within 90 days of the end of the financial year. Entities must also report cyber security incidents with a significant impact on the availability of the asset to the Australian Cyber Security Centre within 12 hours, and incidents with a relevant impact within 72 hours.

The responsible entity is not always the owner -- for many asset classes it is the operator or licence holder that carries the CIRMP obligation, while direct interest holders carry a separate obligation to register the asset. The Register of Critical Infrastructure Assets is not public, so entities should confirm their status against the Act's asset-class definitions and the Cyber and Infrastructure Security Centre's guidance.

FAQ

Common questions

What is a CIRMP and who needs one?

A Critical Infrastructure Risk Management Program (CIRMP) is the risk management program required under Part 2A of the Security of Critical Infrastructure Act 2018. Responsible entities for asset classes specified in the CIRMP Rules must adopt and maintain a program addressing four hazard vectors — cyber and information security, personnel, supply chain, and physical security and natural hazards — review it regularly, and submit an annual report, approved by the board where the entity has one. The Act requires review "on a regular basis"; CISC guidance sets the minimum at once every 12 months. For the nine asset classes covered by the enhanced rules, two further hazard categories apply: credential compromise and lateral movement.

CISC — CIRMP guidance (PDF)
Which sectors are covered by the SOCI Act?

The SOCI Act covers 11 sectors: communications, financial services and markets, data storage or processing, defence industry, higher education and research, energy, food and grocery, health care and medical, space technology, transport, and water and sewerage — 22 defined asset classes in all. The CIRMP obligation applies only to the asset classes specified in the CIRMP Rules, and the responsible entity is often the operator rather than the owner.

CISC — SOCI Act 2018
Which cyber security frameworks can a CIRMP be based on?

Five named frameworks: under Section 8(4) of the CIRMP Rules, the cyber hazard section can be based on the Essential Eight (Maturity Level 1), NIST CSF, ISO/IEC 27001, C2M2 (MIL-1) or AESCSF (SP-1) — with Section 8(5) allowing an equivalent framework instead. The Enhanced CIRMP Rules, in force since 10 June 2026, lift that baseline for nine designated asset classes — Essential Eight ML2, C2M2 MIL-2, AESCSF SP-2, and the current ISO 27001 and NIST CSF 2.0 editions — with the framework uplift phasing in over 24 months (to June 2028).

legislation.gov.au — CIRMP Rules
How does NodeZero help with CIRMP compliance?

NodeZero is a continuous security validation platform that produces direct technical evidence for the cyber-related sections of a CIRMP: it validates the material risks defined in Section 6, evidences the Section 7 identification and currency duties, and tests the cyber framework controls required by Section 8. Coverage of personnel and supply chain hazards is minimal, physical hazards have none, and OT/SCADA environments are out of scope.

CISC — CIRMP guidance (PDF)
Does NodeZero produce the annual board-approved CIRMP report?

No. The annual CIRMP report, board approval and annual review are organisational obligations that NodeZero does not perform. What NodeZero supplies is the evidence underneath them: proof-of-exploit and attack-path summaries showing whether the controls in your chosen cyber framework actually work under adversarial conditions — attack-based evidence you can put in front of an assessor or a CISC compliance review.

CISC — CIRMP annual report form
What are the incident reporting deadlines under the SOCI Act?

Under Part 2B of the SOCI Act, cyber security incidents with a significant impact on the availability of a critical infrastructure asset must be reported to the Australian Cyber Security Centre within 12 hours; incidents with a relevant impact on the asset within 72 hours. These obligations sit alongside the CIRMP; incident reporting is an organisational process, and NodeZero does not file the reports.

CISC — SOCI obligations factsheet (PDF)
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Close the gaps before your next assessment

See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.