A Practical Guide to Australia's SOCI Amendment Act 2024 Compliance Using Picus
| May 13, 2026
The Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024, passed by the Australian Parliament and assented to on 29 November 2024, significantly strengthens the obligations placed on responsible entities for critical infrastructure assets under the Security of Critical Infrastructure Act 2018 (SOCI Act). The amendments expand the scope of regulated assets, introduce new proactive security obligations for critical telecommunications, empower regulators to direct entities to fix deficiencies in their risk management programs, and broaden the government's incident response powers beyond cyber security incidents to any serious incident affecting critical infrastructure.
With Schedules 1–4 commencing on 20 December 2024 and Schedule 5 (critical telecommunications) commencing on 4 April 2025, these obligations are now fully in effect.
While the regulatory intent of the SOCI Amendment Act is clear, the operational challenge is not. Compliance is no longer satisfied by documenting a Critical Infrastructure Risk Management Program (CIRMP), configuring controls, or completing point-in-time assessments alone. Responsible entities are now expected to demonstrate that their security controls operate effectively under real attack conditions, and to do so continuously, with evidence that can be produced at any time for regulators, auditors, and the Secretary.
Across CIRMP governance, telecommunications security, data storage protection, incident response, and vulnerability management domains, the SOCI Amendment Act shifts expectations from control presence to control effectiveness. This creates a growing need for defensible, repeatable, and current evidence that controls work as intended in real-world environments.
This is where the Picus Platform changes how SOCI compliance is achieved. By continuously validating security controls against real adversary behavior, Picus turns technical control performance into operational, audit-ready evidence, enabling responsible entities to meet the enhanced SOCI requirements with confidence.
How Picus Supports Key SOCI Amendment Act 2024 Requirements
The following sections map specific SOCI Amendment Act 2024 obligations to the Picus Platform's validation capabilities. Each section identifies the regulatory requirement, explains what it demands from responsible entities, and demonstrates how continuous security validation supports compliance with defensible, audit-ready evidence.
- Schedule 4 / Section 30AI: Direction to Vary CIRMP
- Schedule 5 / Section 30EB: Obligation to Protect Critical Telecommunications Assets
- Schedule 5 / Sections 30EC & 30ED: Change Notification and Security Assessment
- Schedule 5 / Section 30EF: Ministerial Direction — Carriage Services Prejudicial to Security
- Schedule 5 / Section 30AG(2)(da): Enhanced Annual CIRMP Reporting for Telecommunications Assets
- Schedule 1 / Section 9(7): Data Storage Systems Holding Business Critical Data
- Schedule 2 / Part 3A: Responding to Serious Incidents
- Schedule 3 / Section 42AA & Section 43F: Authorised Use and Disclosure of Protected Information
- Part 2A (Reinforced by Schedule 3): Evaluation Reports and Vulnerability Assessment
- Schedule 6 / Sections 52B & 52D: Systems of National Significance
Schedule 4 / Section 30AI: Direction to Vary Critical Infrastructure Risk Management Program
|
"A relevant official may give the responsible entity for one or more critical infrastructure assets a written direction to vary the entity's critical infrastructure risk management program if the relevant official is satisfied that there are one or more serious deficiencies with the program." (Section 30AI(1)) "A serious deficiency is a deficiency that poses a material risk to: (a) national security; or (b) the defence of Australia; or (c) the social or economic stability of Australia or its people." (Section 30AI(3)) |
How Picus supports this requirement
Schedule 4 introduces a significant new regulatory power: the Secretary or a relevant Commonwealth regulator can now formally direct a responsible entity to remediate serious deficiencies in its CIRMP. Non-compliance carries a civil penalty of 250 penalty units, and the direction (along with how the program was varied in response) must be disclosed in the entity's annual report.
Picus supports this requirement by continuously validating the effectiveness of controls that underpin the CIRMP. Rather than relying on periodic assessments to identify deficiencies after they have already been noticed by regulators, Picus enables responsible entities to detect and remediate control gaps proactively. By executing adversary-emulated attack techniques mapped to real-world TTPs, Picus identifies whether the security measures documented in the CIRMP are actually blocking, if not, detecting, and properly logging and alerting on the threats they are supposed to address.
In addition, the Picus Mitigation Library provides vendor-specific and vendor-neutral mitigation guidance for identified control failures, enabling responsible entities to act on validated deficiencies with concrete remediation steps rather than generic recommendations, supporting faster, more defensible CIRMP improvements within the timeframes a Section 30AI direction requires.
The result is a continuously updated, defensible record demonstrating that the program reflects actual security posture, not a static policy document that could attract a Section 30AI direction.
Schedule 5 / Section 30EB: Obligation to Protect Critical Telecommunications Assets
|
"For the purposes of security and the protection of a critical telecommunications asset from any hazard where there is a material risk that the occurrence of the hazard could have a relevant impact on the asset, the responsible entity for the asset must, so far as it is reasonably practicable to do so, protect the asset to ensure: (a) the confidentiality of communications...carried on, and of information contained on, the asset; and (b) the availability and integrity of the asset." (Section 30EB(2)) |
How Picus supports this requirement
Section 30EB creates a positive obligation for responsible entities to actively protect critical telecommunications assets, carrying a civil penalty of 1,500 penalty units for non-compliance. This obligation includes complying with CIRMP requirements under Part 2A, maintaining competent supervision of and effective control over the asset, and any additional requirements prescribed by the rules. Simply installing security tools is not enough; entities must demonstrably prove that their defenses work under real-world conditions and are actively managed.
Picus supports this obligation by providing the continuous validation and objective assurance needed to prove that confidentiality, availability, and integrity are actually being maintained. It does this by executing known adversarial behaviours observed in the wild across a variety of validation surfaces:
- Network & Endpoint Controls: Validating that firewalls, WAF, IPS, and EDR actually block and detect the threats they are configured to stop.
- Detection & Response Stack: Ensuring SIEM rules and alerting pipelines work under real attack conditions.
- Infrastructure & Application Attack Paths: Mapping proven, exploitable paths from initial access through lateral movement to critical assets.
- Identity & Privilege: Systematically testing IAM policies and Active Directory configurations against credential theft and escalation.
- Cloud & Container Environments: Validating Kubernetes policies and cloud security controls to prevent unauthorised access and configuration drift.
Protecting a telecommunications asset requires knowing what is targeting it. Picus Threat Library is continuously updated with adversary campaigns targeting the telecommunications sector, including threat groups' specific TTPs, CVEs exploited for initial access, and supply-chain attack techniques leveraging vulnerabilities in third-party infrastructure. With a mean time to release of 5.3 hours for emerging threats and a guaranteed 24-hour SLA for critical advisories such as CISA alerts, Picus converts this sector-specific threat intelligence into executable validation tests, enabling responsible entities to confirm that their controls can block or detect the techniques most likely to be used against their assets.
This includes simulating unauthorised access attempts, lateral movement, command-and-control communication, data exfiltration, and availability-impacting attack techniques, enabling responsible entities to confirm that their controls are meeting the "so far as it is reasonably practicable" standard with objective evidence rather than assumptions. The continuously updated validation data also directly supports the "competent supervision and effective control" obligation by providing measurable, current evidence that the asset's defences are being actively managed.
The Picus Platform also validates that CIRMP requirements (which Section 30EB(3)(a) explicitly incorporates into the telecommunications protection obligation) are operationally effective, ensuring the two obligations are met in alignment.
Schedule 5 / Sections 30EC & 30ED: Change Notification and Security Assessment
|
"As soon as reasonably practicable after becoming aware that the change, or proposed change, is likely to have a material adverse effect on the entity's capacity to comply with its obligation under subsection 30EB(2)...the responsible entity for the critical telecommunications asset must notify the Secretary, in writing, of the change..." (Section 30EC(2)) |
How Picus supports this requirement
Sections 30EC and 30ED establish a notification and assessment framework requiring responsible entities to identify when changes to their telecommunications services or systems (including new services, equipment procurement, outsourcing, and offshoring) are likely to materially impair their capacity to protect the asset. The obligation to notify carries a civil penalty of 300 penalty units, with a further 150 penalty units for failure to comply with the Secretary's requests for further information.
Picus supports responsible entities in making the notification determination accurately. For implemented changes, Picus re-executes its adversary-emulated attack scenarios against the updated environment, producing measurable evidence of whether the entity's protection posture has been degraded.
For proposed changes, Picus provides a validated, current baseline of control effectiveness that responsible entities can assess the proposed change against, grounding the notification determination in tested evidence rather than assumption. This transforms the change notification decision from a judgment call into an evidence-based determination grounded in tested, real-world control performance.
Schedule 5 / Section 30EF: Ministerial Direction if Use or Supply of Carriage Services Is Prejudicial to Security
|
"If...the Minister considers that the proposed use or supply would be, or the use or supply is, as the case may be, prejudicial to security; the Minister may give the entity a written direction not to use or supply, or to cease using or supplying, the carriage service or the carriage services." (Section 30EF(1)) |
How Picus supports this requirement
Section 30EF carries the most significant civil penalty in the entire Amendment Act at 2,000 penalty units for non-compliance, and empowers the Minister to direct a responsible entity for a critical telecommunications asset to cease using or supplying one or more carriage services entirely. This power may only be exercised after an adverse security assessment from ASIO is provided to the Minister, reflecting the seriousness of the circumstances in which it would be invoked.
While Picus cannot prevent an adverse ASIO security assessment, it strengthens a responsible entity's overall security posture in a way that reduces the likelihood of conditions that could lead to one.
By continuously validating that implemented security controls effectively protect the confidentiality of communications, the integrity of systems, and the availability of services, Picus produces the kind of objective, evidence-backed security assurance that demonstrates a responsible entity is actively managing the risks to its assets. Entities that can produce validated, current evidence of robust security performance are better positioned to demonstrate that their use and supply of carriage services does not create the conditions that Section 30EF is designed to address.
Schedule 5 / Section 30AG(2)(da): Enhanced Annual CIRMP Reporting for Telecommunications Assets
|
"if one or more of those assets are critical telecommunications assets: ...(iv) includes a statement that evaluates the effectiveness of those measures to eliminate or reduce risks advised to the entity during the relevant period or any previous period." (Schedule 5, Item 26, new paragraph 30AG(2)(da)(iv)) |
How Picus supports this requirement
The SOCI Amendment Act enhances the annual CIRMP report requirements for entities with critical telecommunications assets. Reports must now include summaries of notified changes under Section 30EC, descriptions of security risks advised by the Secretary under paragraph 30ED(3)(c), descriptions of measures adopted to address those risks, and, critically, a statement that evaluates the effectiveness of those measures in eliminating or reducing the advised risks.

Figure 1. Prevention and Detection Effectiveness Score Based on Attack Simulations
Picus directly supports this effectiveness evaluation obligation. The workflow the legislation creates is specific: the Secretary identifies a risk prejudicial to security in relation to a notified change, advises the entity, and may suggest measures. The entity adopts measures to address the advised risk. The annual report must then evaluate whether those measures actually worked.
Picus enables responsible entities to answer that question with tested evidence rather than opinion. After remedial measures are adopted in response to a Secretary-advised risk, Picus re-executes targeted validation scenarios against the specific threat behaviours the advised risk represents, testing whether the adopted measures actually block, detect, and alert on the relevant adversary techniques. The resulting simulation data provides measurable evidence of risk reduction that directly informs the effectiveness statement required under paragraph 30AG(2)(da)(iv), turning it from a subjective narrative into a defensible, evidence-backed evaluation grounded in validated control performance.
Schedule 1 / Section 9(7): Data Storage Systems Holding Business Critical Data
|
"If, under this section, an asset is a critical infrastructure asset, then a data storage system in respect of which all of the following requirements are satisfied is taken to be part of the critical infrastructure asset: ...(c) business critical data is stored, or is processed in or by, the data storage system." (Section 9(7)) |
How Picus supports this requirement
Schedule 1 significantly expands the regulatory perimeter by deeming data storage systems that hold business critical data to be part of the critical infrastructure asset itself. This means CIRMP obligations under Part 2A, cyber security incident notification obligations under Part 2B, and all associated security requirements now extend to cover these systems. The application provision confirms this applies to all critical infrastructure assets, including those that existed before commencement, and to data storage systems regardless of when they came into existence.

Figure 2. Picus Security Control Validation, Data Exfiltration Attacks Module
Picus supports responsible entities in understanding and protecting this expanded scope by validating whether business critical data storage systems are reachable and exploitable through real attack paths. By simulating data exfiltration attack techniques, Picus tests whether Data Loss Prevention (DLP) controls, access restrictions, and monitoring mechanisms effectively prevent unauthorised access to and movement of business critical data. This helps responsible entities confirm that their CIRMP accurately accounts for the expanded asset boundary and that the protections applied to data storage systems are operationally effective, not just documented.
Schedule 2 / Part 3A: Responding to Serious Incidents
|
"This Part sets up a regime for the Commonwealth to respond to a serious incident that has had, is having, or is likely to have, one or more relevant impacts on one or more critical infrastructure assets." (Section 35AA, as amended) |
How Picus supports this requirement
Schedule 2 broadens the government's incident response powers from cyber security incidents to any serious incident (physical, operational, or cyber) that has or is likely to have a relevant impact on critical infrastructure assets. The amended Part 3A empowers the Minister to authorise information-gathering directions and action directions across multiple assets and multiple entities simultaneously, a significant operational expansion from the previous single-asset, single-entity model.
Picus supports this requirement by continuously exercising the detection, alerting, escalation, and containment workflows that underpin an entity's incident response capacity.
Through production-safe adversary-emulated scenarios, Picus enables responsible entities to validate whether their people, processes, and technology would respond effectively when a serious incident occurs, and to identify and close gaps before a Ministerial authorisation compels them to act. The resulting evidence also supports entities in demonstrating to the Secretary that their response capabilities are operational.
Schedule 3 / Section 42AA & Section 43F: Authorised Use and Disclosure of Protected Information
NOTE: Sections 42AA and 43F introduce new legal authorisations allowing responsible entities to use, record, and disclose protected information for asset protection purposes and in the conduct of their business affairs. This removes a potential compliance friction point for entities using Security Validation Platforms. The security findings, control gap analyses, exposure scores, and detection analytics produced through validation activities constitute relevant information under the SOCI Act's expanded definitions in Section 5A(3).
Responsible entities can confidently operationalise Picus outputs – sharing them across internal security teams, with managed security service providers, or with technology vendors to remediate identified gaps – knowing that their use of this information is expressly authorised under the SOCI Act.
Part 2A Obligations, as Reinforced by Schedule 3: Evaluation Reports and Vulnerability Assessment
The SOCI Act's existing Part 2A requires responsible entities to produce evaluation reports (under sections 30CQ and 30CR) and vulnerability assessment reports (under section 30CZ) as core compliance artefacts. The Amendment Act reinforces their significance by formally classifying them as relevant information under Section 5A(3), meaning they are subject to the protected information framework and must be available to the Secretary on request.
A report that understates risk or overstates control effectiveness is no longer just a governance shortcoming, it is a protected document that could be scrutinised against the entity's actual security posture.
How Picus supports this requirement
Picus supports responsible entities in producing these artefacts with greater accuracy and currency. Through its Exposure Validation (EXV) capability, Picus ingests vulnerability findings from scanners such as Tenable and Qualys, matches them against live security control performance data generated by the platform's own adversarial simulations, and re-prioritises them based on validated exploitability rather than theoretical severity.
This allows vulnerability assessment reports prepared under Section 30CZ to reflect real exposure – distinguishing between vulnerabilities that are genuinely exploitable in the entity's specific environment and those effectively mitigated by existing controls – enabling risk-based prioritisation consistent with SOCI's expectation that remediation efforts are proportionate to actual risk.

Figure 3. Assigning Real Exploitability Score
Evaluation reports prepared under Sections 30CQ and 30CR can likewise be grounded in tested, measured control performance rather than subjective assessments.
Picus provides continuously updated, MITRE ATT&CK-mapped validation data (including prevention scores, detection coverage rates, and remediation tracking) that directly informs the content of these reports. The result is evaluation and vulnerability assessment artefacts that are defensible when produced to the Secretary or an auditor, because they are backed by evidence of what was tested, what worked, and what didn't.
Schedule 6 / Sections 52B & 52D: Systems of National Significance — Notification and Enhanced Obligations
|
"If the responsible entity for an asset declared under subsection 52B(1) to be a system of national significance ceases to be the responsible entity for the asset, the entity must, within 30 days, notify the Secretary of that cessation." (Section 52D, as substituted) |
How Picus supports this requirement
Schedule 6 simplifies and tightens the notification framework for systems of national significance, consolidating the obligation onto the responsible entity with a civil penalty of 150 penalty units. More significantly, assets declared as systems of national significance under Section 52B face enhanced obligations under Part 2C of the SOCI Act, including system information reporting, incident response planning, and the potential for cyber security exercise directions.
Picus supports responsible entities for systems of national significance by providing the continuous, evidence-based validation that these enhanced obligations require.
Through adversary-emulated attack scenarios, Picus enables these entities to demonstrate that the controls protecting nationally significant assets are not only in place but performing against real-world threat techniques. The platform's MITRE ATT&CK-mapped validation data supports the system information reporting obligations, while its detection and response validation capabilities help ensure incident response plans required under Part 2C are operationally tested and effective, not just documented.
Making SOCI Amendment Act Compliance Resilient with Validation
Australia's SOCI Amendment Act 2024 aims to ensure that critical infrastructure remains operationally resilient because the controls protecting it work in practice, not just on paper. The extension of the SOCI Act's review period from three years to five years under Schedule 8 signals that this regulatory framework is settled and enduring. Responsible entities should approach their SOCI obligations as a long-term investment in continuous assurance, not a short-term compliance exercise.
Picus helps responsible entities move from periodic, assumption-based compliance to continuous, evidence-based assurance. By validating control effectiveness against real attack behaviour, Picus turns SOCI compliance into a living, defensible security posture — one that satisfies the Secretary's expectations not just at the time of assessment, but continuously.
Get your demo and see how Picus helps Australian critical infrastructure operators protect their assets with audit-ready evidence.
