Many operators assume the Security of Critical Infrastructure Act is something that applies to power stations, ports and water utilities. It applies to data centres too, and the businesses most often caught by surprise are in data storage and processing. The test does not turn on how large you are. It turns on whose data you hold. If you store or process data for the right kinds of customer, you can be a responsible entity for a critical infrastructure asset without ever having thought of yourself that way.
Does the SOCI Act apply to your data centre?
The Act covers eleven sectors and twenty two asset classes, and data storage or processing is one of them. Whether a specific facility is captured depends on the nature of the data and the customers it serves, including data connected to government and to other critical infrastructure sectors. The practical point is simple. Do not assume you are out of scope because you are not a hyperscaler. Confirm your status deliberately, because the obligations that follow are real and they carry board level accountability.
The core obligations, in plain terms
Three obligations sit at the centre of the regime.
1. A Critical Infrastructure Risk Management Program
A responsible entity must maintain a written, board owned program that identifies the material risks to the asset and sets out how those risks are minimised and mitigated. It spans four domains: cyber and information security, personnel, supply chain, and physical and natural hazards. It must be reviewed at least annually, and an annual report on it must go to the regulator within ninety days of the end of the financial year. This is director level responsibility, not an item to delegate and forget.
2. Mandatory incident reporting
Cyber incidents must be reported to the Australian Cyber Security Centre against firm clocks. A significant impact incident must be reported within twelve hours of the entity becoming aware of it. A lesser impact incident must be reported within seventy two hours. Building the internal process to actually meet a twelve hour clock, at any hour of any day, is a design task in its own right.
3. Registration
Responsible entities must provide ownership and operational information to the Register of Critical Infrastructure Assets and keep that information current. It is an administrative obligation, but a missed one is still a compliance failure.
What changed in 2026
The enhanced obligations commenced on 10 June 2026 and phase in over the following years. The direction of travel is clear. By the middle of 2027, expect a stronger focus on personnel security and on managing legacy technology. By the middle of 2028, expect an uplift to a higher framework maturity level, phishing resistant multifactor authentication and controls that limit lateral movement inside a network. The bar rises on a schedule, so the sensible response is to build ahead of it rather than chase it.
The consequences of getting it wrong are not trivial. Proposed penalties for non compliance with ministerial directions can reach into the millions of dollars for corporations, and the board reporting requirement means accountability lands squarely with directors.
Key takeaways
- The SOCI Act can capture data storage and processing operators based on whose data they hold, not their size.
- Core obligations are a board owned risk management program, mandatory incident reporting within 12 or 72 hours, and asset registration.
- Enhanced obligations commenced 10 June 2026 and tighten through 2027 and 2028.
- Accountability is at director level, and penalties for corporations can reach into the millions.
Why this belongs in your site and investment decision
Security obligations are not a post construction afterthought. They shape the operating model, the staffing, the technology choices and, for a serious buyer or investor, the value of the asset. A facility that is demonstrably compliant is worth more and de risks faster than one carrying an unquantified obligation. That is why we scope security alongside power, planning and connection, not after them.
DivineLab Worx coordinates regulatory and compliance and AI advisory and governance as part of critical infrastructure engagements, so the SOCI position is understood before capital is committed and the operating model is designed to carry it. If you are unsure whether your facility is in scope, that uncertainty is itself the risk worth closing first.
Sources and further reading
- Cyber and Infrastructure Security Centre, SOCI Act regulatory obligations
- Department of Home Affairs, Security of Critical Infrastructure
This article is general commentary for infrastructure operators, developers and investors. It is not legal, planning or engineering advice. DivineLab Worx coordinates qualified Australian specialists within each engagement.