Share this article

SOCI and CIRMP: The cybersecurity frameworks Australian critical infrastructure operators can use
Accelerating security solutions for small businesses Tagore offers strategic services to small businesses. | A partnership that can scale Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. | Standing out from competitors Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market. |
The Security of Critical Infrastructure (SOCI) Act and the Critical Infrastructure Risk Management Program (CIRMP) are central to Australia’s critical infrastructure compliance regime. Because the local compliance landscape is made up of interconnected laws, standards, and programs, understanding how the SOCI Act, CIRMP, and underlying frameworks fit together can be a real challenge.
One of the trickiest decisions organisations face is choosing the right GRC or cybersecurity framework to satisfy the CIRMP criteria. While CIRMP requires organisations to adopt and maintain at least one of five frameworks, it doesn’t specify which. You have to make the choice after factoring in your sector, asset criticality, existing maturity, and operating environment.
This guide explains key SOCI and CIRMP requirements and how to evaluate the five approved cybersecurity standards against relevant criteria.
What is SOCI?
The Security of Critical Infrastructure Act 2018 is an Australian legislation that establishes a regulatory framework for protecting the country’s infrastructure against both physical and cyber threats. It applies to 11 critical infrastructure sectors:
- Communications
- Financial services and markets
- Data storage or processing
- Defence industry
- Higher education and research
- Energy
- Food and grocery
- Healthcare and medical
- Space technology
- Transport
- Water and sewerage
SOCI directs organisations in these sectors to strengthen their cyber resilience, risk management, and incident response capabilities. Compliance obligations expand beyond the isolated assets and cover downstream dependencies that can impact critical infrastructure during incidents.
SOCI defines the regulatory foundations for supporting cyber and information security obligations, including the CIRMP and approved cybersecurity frameworks such as the Essential Eight, ISO 27001, and NIST CSF. For financial entities, SOCI overlaps with standards such as CPS 230 (Operational Risk Management) and CPS 234 (Information Security).
Overall, alignment with SOCI means ensuring your controls, reporting, and evidence satisfy obligations across the underlying frameworks and CIRMP.
{{cta_withimage40="/cta-blocks"}} | CPS 234 checklist
What is CIRMP?
The Critical Infrastructure Risk Management Program is a mandatory risk management program under the SOCI Act that emphasises maintaining operational continuity. The program requires responsible entities to identify, assess, and manage cyber, physical, personnel, and supply chain risks that could affect critical infrastructure.
CIRMP follows a risk and proportionality-based approach, asking organisations to implement controls appropriate to the material risk, size, complexity, and operating context of critical infrastructure. Under this approach, you identify, assess, and manage risks across four vectors:
- Cyber and information security hazards
- Personnel hazards
- Physical and natural hazards
- Supply chain hazards
Not all organisations subject to the SOCI Act are in scope for CIRMP. Only responsible entities with critical infrastructure must meet the program’s requirements. Here are a few examples:
*Only hospitals designated under the SOCI Act are subject to CIRMP.
Which cybersecurity frameworks satisfy CIRMP?
Organisations can satisfy CIRMP by following one of its five approved (or an equivalent) cybersecurity frameworks for its cyber and information security hazard component:
- Essential Eight
- ISO 27001
- NIST Cybersecurity Framework (NIST CSF)
- Cybersecurity Capability Maturity Model (C2M2)
- AESCSF
The choice of framework shapes your controls and the way you report risk management to the board annually. To choose the right one, consider your sector, your existing cybersecurity maturity, and whether your environment is primarily information technology (IT), operational technology (OT), or a mix of both.
1. Essential Eight
Essential Eight is a set of eight prioritised mitigation strategies published by the Australian Signals Directorate's Australian Cyber Security Centre (ACSC). Originally designed for Australian government agencies, it has since become one of Australia's most widely adopted cybersecurity frameworks. The framework helps organisations strengthen their security systems to mitigate some of the most common cyber threats. Essential Eight outlines four maturity levels (ML0–ML3), supporting a progressive path to strengthen your cybersecurity posture.
For most organisations, baseline CIRMP Rules require Essential Eight Maturity Level 1. But certain high-risk critical infrastructure asset classes must follow the Enhanced CIRMP Rules, which introduce ML2 requirements over a phased implementation period. In practice, this means implementing the eight mitigation strategies with stronger technical controls for:
- Application patching
- Multi-factor authentication
- Restricting administrative privileges
- Application control
- User application hardening
- Data backups
E8 works for entities with primarily IT environments that are already relying on ASD guidance, or those looking for a structured path to improving maturity. The framework provides limited support for OT environments and has real coverage gaps for energy and utilities operators.
{{cta_withimage6="/cta-blocks"}} | Scale security ebook
2. ISO 27001
ISO/IEC 27001 is an internationally recognised information security management system (ISMS) standard that helps organisations protect sensitive data. Out of the CIRMP-approved frameworks, ISO 27001 is the only one that offers third-party certification. This makes it easier to demonstrate your ISMS aligns with the standard across jurisdictions.
ISO 27001’s clauses 4–10 define specific requirements to meet the standard’s criteria. Since ISO 27001 is primarily risk-based, you select and implement controls that apply to your risk environment. The controls cover organisational, people, physical, and technological security measures, which help you align with the governance and security practices expected under CIRMP. Document your selected controls in a Statement of Applicability to support CIRMP reporting and assurance.
ISO 27001 is best suited for organisations with existing ISMS programs, multi-jurisdictional operations, and or those seeking a global certification that satisfies broader enterprise risk governance alongside CIRMP.
However, ISO 27001 also provides limited coverage for OT environments. Organisations in the energy and industrial sectors must supplement it with OT-specific controls and guidance.
3. NIST Cybersecurity Framework (NIST CSF)
NIST CSF is a flexible, risk-based framework developed by the U.S. National Institute of Standards and Technology (NIST). It helps organisations identify, assess, and manage cybersecurity risks using desired cybersecurity outcomes rather than prescribing specific controls.
NIST CSF 2.0 is organised around six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. The framework describes four implementation tiers that help organisations benchmark their cybersecurity risk management practices and design improvement paths:
- Tier 1: Partial
- Tier 2: Risk-informed
- Tier 3: Repeatable
- Tier 4: Adaptive
Because NIST CSF is outcome-based, organisations can adapt it to their own risk profiles and operating environments. This flexibility works well when you’re aligning with CIRMP’s risk-based approach.
NIST CSF is best suited for organisations with existing NIST alignment, including defence suppliers, entities with U.S. parent companies, and those looking for a framework that maps well across IT and OT environments.
The tradeoff is that the flexibility can make it more challenging to implement for less mature organisations, which often need additional effort to translate high-level NIST CSF outcomes into specific controls.
4. Cybersecurity Capability Maturity Model (C2M2)
C2M2 is a maturity model developed by the U.S. Department of Energy specifically to help organisations in the energy sector evaluate and improve their cybersecurity capabilities.
C2M2 is organised into domains that cover key security areas such as risk management, situational awareness, workforce management, cybersecurity architecture, and cybersecurity program management. Organisations benchmark their practices against Maturity Indicator Levels (MILs), which apply independently to each domain.
Under the CIRMP rules, organisations relying on C2M2 to satisfy the baseline cyber and information and hazard requirements must reach at least MIL1. At this level, organisations perform fundamental cybersecurity practices without fully standardising or documenting them. Certain high-risk critical infrastructure asset classes are also expected to reach MIL2.
Using C2M2 to meet CIRMP requirements is best suited for energy sector operators already familiar with the framework or those working toward AESCSF. For Australian energy operators, AESCSF is almost always the better choice since it incorporates C2M2 requirements and adds Australia-specific requirements.
5. AESCSF
The Australian Energy Sector Cyber Security Framework (AESCSF) is built on C2M2 as the foundational model and tailored to the energy sector. It helps organisations in the electricity, gas, and liquid fuel sub-sectors strengthen their operational cybersecurity.
AESCSF outlines security practices relevant to the energy sector and provides guidance on identifying, assessing, and managing cyber risks. These practices are split into 11 domains, including Identity and Access Management, Situational Awareness, and Cybersecurity Program Management.
Across the domains, AESCSF defines 354 practices and anti-patterns (practices and behaviours that weaken cybersecurity) organisations can use to evaluate their cyber maturity.
The original version of AESCSF mapped to relevant standards like the Essential Eight, while the latest version also maps to CIRMP, allowing in-scope entities to demonstrate their SOCI compliance easily.
AESCSF is best suited for electricity, gas, and liquid fuels operators, especially within OT environments. Completing the annual AESCSF self-assessment through the AEMO portal generates evidence for CIRMP cyber reporting, making it the most streamlined option for entities covered by both obligations.
How SOCI, CIRMP, AESCSF, and other frameworks work together
SOCI, CIRMP, and the approved cybersecurity frameworks are not parallel obligations. They operate at different layers of Australia’s critical infrastructure compliance regime. Understanding the hierarchy is critical, as implementing a framework alone doesn't satisfy your CIRMP obligations.
If you look at their interactive relationship, SOCI is the core legal requirement, operationalised by CIRMP through mandatory risk management criteria. AESCSF, NIST CSF, ISO 27001, C2M2 and Essential Eight provide the implementation model for CIRMP. Note that these frameworks only cover one of the four hazard vectors; you still need separate, documented programs for personnel, physical, and supply chain risks.
Consider integrating your compliance approach to reduce duplicated effort, streamline audits and annual reporting, and make ongoing compliance easier to manage. It also makes framework selection more strategic: instead of defaulting to the most familiar option, choose the one that best aligns with your sector, existing cybersecurity maturity, IT and OT environment, and any existing certifications or security programs.
When pursuing critical infrastructure compliance, apply evidence and controls across all layers of the SOCI-CIRMP framework hierarchy simultaneously. This puts you in a stronger position to demonstrate how your controls satisfy different requirements. The most effective approach is to map your controls once and reuse them across multiple obligations, rather than building separate evidence sets for each framework. Although this seems obvious, many organisations still manage ISO 27001 and AESCSF in parallel spreadsheets, leading to redundant work and unnecessary administrative overhead.
{{cta_withimage40="/cta-blocks"}} | CPS 234 checklist
Implementing SOCI and CIRMP: Challenges
SOCI and CIRMP implementation can be complex because it requires translating controls between the standards. Other common challenges include:
- Keeping up with regulatory changes: Changes to the SOCI Act, CIRMP, or your chosen framework can have cascading effects across your compliance program. Staying ahead requires regular reviews to understand how updates affect existing controls, documentation, and governance processes.
- Mapping controls across frameworks: SOCI and CIRMP compliance requires demonstrating how a single control meets multiple security criteria. Without a structured mapping process, it becomes tedious and carries a high risk of duplicative work.
- Applying CIRMP’s proportionality requirements: CIRMP’s risk- and proportionality-based approach, requiring organisations to implement “reasonable” controls that correspond to their environment. It can be subjective and requires further assessments and defensible decisions.
- Meeting assurance and audit expectations: Organisations need to demonstrate their controls work in practice. This requires keeping accurate, up-to-date records, which can be a disruptive task without a top compliance automation solution.
- Maintaining visibility into downstream dependencies: Critical infrastructure relies on expanding supply chains with cloud platforms, service providers, and other third parties. To manage the new risks these dependencies introduce, you need real-time oversight into your vendor environment.
- Misinterpreting requirements: Many CIRMP requirements are principle-based instead of prescriptive, such as the “reasonable practicability” criterion. Interpreting requires a thorough understanding to ensure implementations can withstand regulatory scrutiny.
In practice, many challenges are less about framework decisions and more about governance and operational gaps.
Implementing a top GRC platform, such as Vanta, can streamline your CIRMP journey by replacing fragmented, manual processes with centralised, automated control and evidence management.
How Vanta supports SOCI and CIRMP compliance
Vanta is the leading agentic trust platform for building a global compliance program with a strong foundation in privacy and cybersecurity. The platform comes with built-in support for three of the five CIRMP-approved cybersecurity frameworks: Essential Eight, NIST CSF, and ISO 27001. It automates common compliance workflows, such as evidence collection and continuous control monitoring, reducing the manual work behind ongoing maintenance.
For instance, Vanta’s Essential Eight platform supports you with:
- 1,400+ hourly automated tests supported by 400+ integrations
- Pre-mapped templates for all eight mitigation strategies
- Customisable maturity levels
- Patch and vulnerability management
- Access and privilege management
You can also use Vanta’s third-party risk management product to support ongoing supply chain monitoring and risk management across critical asset environments.
If you’re pursuing multiple frameworks, Vanta’s custom frameworks can help you make an AESCSF shell framework that lets you map alongside ISO 27001 or Essential Eight without having to duplicate your work.
Schedule a custom demo to check out how Vanta can support your compliance obligations.
{{cta_simple36="/cta-blocks"}} | Essential eight
Vanta is not a law firm, and this article does not constitute or contain legal advice or create an attorney-client relationship. When determining your obligations and compliance with respect to relevant laws and regulations, you should consult a licensed attorney.





FEATURED VANTA RESOURCE
The ultimate guide to scaling your compliance program
Learn how to scale, manage, and optimize alongside your business goals.











.png)


.png)







