If your organisation is a responsible entity under the Security of Critical Infrastructure Act 2018 and you need independent physical security advice to support your CIRMP compliance obligations, Smartsec Security Solutions can help.
We are a Perth-based independent physical security consultancy working with critical infrastructure operators across Western Australia and nationally. We focus exclusively on physical security – not cyber, not IT, not personnel security. That focus means the advice is deep, specific, and grounded in direct site knowledge rather than a generalist framework applied to all four CIRMP hazard categories at once.
What SOCI Act Compliance Requires From a Physical Security Perspective
The Security of Critical Infrastructure Act 2018 requires responsible entities across 11 critical infrastructure sectors to establish and maintain a Critical Infrastructure Risk Management Program (CIRMP). The CIRMP must address all hazard categories – including physical security – and must demonstrate that the responsible entity has taken reasonable steps to minimise the risk and impact of physical security incidents on the availability, integrity, reliability, and confidentiality of the asset.
The enhanced CIRMP Rules – proposed by the Department of Home Affairs in 2026 – introduce a dedicated physical security plan requirement. Every responsible entity will need a documented plan addressing:
- Site nature, ownership, tenancy arrangements, and collateral exposure
- Physical access controls – perimeter, surveillance, alarm systems, and continuous monitoring of critical components
- Business hours and out-of-hours access controls
- Protective security measures across the whole asset
- Incident response arrangements for physical security breaches
- Testing and effectiveness review of security arrangements
- Integration with cyber security, personnel security, and emergency response plans
The compliance deadline for the physical security plan is 30 June 2028 – with a requirement to document a compliance pathway in intervening reporting periods. That means the assessment and plan development process needs to begin now.
For a full breakdown of the physical security plan requirements, see: CIRMP Physical Security Plan – What Critical Infrastructure Operators in Australia Need to Know
What “Reasonable Steps” Means in Practice
The SOCI Act sets “reasonable steps” as the compliance standard for physical security. This is not a prescriptive checklist – it is a judgement about what a responsible entity in your position, with your assets and threat environment, should have done to reduce physical security risk.
In practice, demonstrating reasonable steps requires:
A documented, independent assessment. An assessment conducted by an independent, credentialed consultant – aligned with ISO 31000:2018 – that identifies threats, evaluates vulnerabilities, and rates residual risk. Self-certification or a vendor-conducted assessment carries significantly less weight with regulators and auditors than an independent assessment.
A prioritised risk register. The CIRMP must include a risk register for physical security hazards. The register needs to be specific, evidence-based, and updated on the review cycle the CIRMP requires.
A physical security plan. Under the enhanced CIRMP Rules, a documented plan addressing each required element is necessary for attestation. The plan must be grounded in the assessment findings – not written independently of the risk evidence.
Testing and review. Security arrangements must be tested and the plan must be kept current. An organisation that conducted an assessment three years ago and has not reviewed its physical security arrangements since is unlikely to be able to demonstrate reasonable steps at the time of a CISC audit or inquiry.
Why Independent Physical Security Advice Matters for SOCI Compliance
Most national consulting firms approach SOCI compliance from a cyber and governance perspective. Physical security – the site, the perimeter, the access control arrangements, the after-hours monitoring – is often treated as secondary or delegated to a subcontractor.
Smartsec works exclusively in physical security. Every engagement is a physical security assessment – conducted on site, by an experienced consultant, against a structured methodology. We do not subcontract physical security work to people who are primarily cyber or governance consultants.
We are also vendor-neutral. We do not supply or install security systems, and we have no commercial relationships with security product suppliers. Every recommendation reflects what the asset actually needs to meet its physical security obligations – not what a product catalogue offers. For responsible entities whose CIRMP attestation is subject to CISC oversight, vendor-neutral independent advice is the strongest foundation for demonstrating reasonable steps.
Critical Infrastructure Sectors We Support
Smartsec delivers SOCI Act physical security compliance consulting for operators across the following critical infrastructure sectors:
- Energy – electricity assets, gas assets, liquid fuel assets
- Water and sewerage
- Transport – freight infrastructure and freight services, ports and maritime
- Health – hospital and health service assets
- Broadcasting and communications infrastructure
We work across metropolitan Perth and regional and remote WA – including assets in the Pilbara, South West, and Great Southern regions where after-hours vulnerability and extended response times create specific physical security challenges that metropolitan-focused assessments do not adequately address.
What an Engagement Involves
Every engagement begins with a scoping conversation – understanding the asset, the current CIRMP status, what physical security documentation already exists, and what the compliance gap looks like. From that conversation we confirm the scope, the deliverables, and the timeframe.
A typical engagement for a single critical infrastructure asset involves:
Independent physical security assessment – site inspection, threat identification, vulnerability analysis, risk rating aligned with ISO 31000:2018. Typically one to two days on site depending on asset size and complexity, plus report production.
CIRMP physical security plan development – translating the assessment findings into a documented plan suitable for inclusion in the CIRMP and for attestation purposes.
Risk register entries – physical security hazards identified, rated, and formatted for inclusion in the CIRMP risk register.
Ongoing review support – available for annual or biennial review assessments to keep the physical security plan current and demonstrate the ongoing reasonable steps standard.
Credentials and Independence
Smartsec Security Solutions is led by Khabeer Rockley SRMCP – a licensed WA Security Risk Consultant and Security Agent with technical security licensing and nearly two decades of experience in physical security across the public and private sectors.
We are a WALGA Preferred Supplier (PSP001-002 and PSP001-026) and an approved supplier through Local Government Contracts Australia (LGCA).
We do not sell or install security systems. We have no vendor relationships. Our advice is independent, evidence-based, and produced to the standard that boards, auditors, and regulators expect.
Get Started
The right starting point is a brief, confidential scoping conversation. We will confirm your obligations under the SOCI Act, clarify what the physical security plan requirement means for your specific asset, and outline what an independent assessment and plan development engagement would involve for your situation.
Contact Smartsec Security Solutions to arrange a scoping conversation.


