SOCI Act Penalties for Non-Compliance: What Critical Infrastructure Operators Risk and How Physical Security Assessment Reduces Exposure

The Security of Critical Infrastructure Act 2018 is not a compliance framework with soft consequences. Non-compliance carries civil penalties that apply to both individuals and corporations, with corporate penalties running into the hundreds of thousands of dollars per breach – and continuing breaches attracting additional penalties for each day the non-compliance persists.

For responsible entities that have focused their compliance efforts on cyber and information security, the physical security hazard category is frequently the least documented and least evidenced component of their Critical Infrastructure Risk Management Program. That gap creates real penalty exposure – and it is the gap that an independent physical security assessment is specifically designed to close.

This article covers what the SOCI Act penalty framework looks like from a physical security perspective, what specific obligations carry penalty exposure, and what demonstrating reasonable steps in physical security actually requires.

 

The SOCI Act Penalty Framework

The Security of Critical Infrastructure Act 2018 and its subsequent amendments create a tiered penalty framework. Penalties are expressed in Commonwealth penalty units – currently set at $330 per unit – meaning penalty amounts increase each time the penalty unit rate is revised upward.

The core penalty exposures relevant to physical security compliance are:

Failing to have a CIRMP. Every responsible entity must have a Critical Infrastructure Risk Management Program in place. Failing to have one is a breach. Civil penalties for corporate entities start at $82,500 and can reach $412,500 depending on the specific provision breached.

Failing to comply with the CIRMP. Having a CIRMP on paper is not enough. The responsible entity must actually comply with the program – which means the physical security arrangements described in the plan must be implemented and maintained. A plan that documents physical security controls that don’t actually exist, or that haven’t been tested, creates compliance exposure even where the plan itself is well-written.

Failing to address all four hazard categories. The CIRMP must address physical security hazards alongside cyber, personnel, and supply chain risks. A program that addresses cyber in depth but treats physical security as a secondary consideration – or that includes only generic statements about physical security without specific, evidenced arrangements – does not meet the requirement.

Non-compliance with CISC directions. The Cyber and Infrastructure Security Centre can issue formal directions to a responsible entity to remediate serious deficiencies in their CIRMP. Non-compliance with those directions carries a civil penalty of 250 penalty units – currently around $82,500. Proposed amendments to the SOCI Act would increase this to 2,000 penalty units, significantly increasing the deterrent effect.

Continuing breaches. Where a breach continues over time – where physical security arrangements remain inadequate and no remediation steps are taken – penalties can apply on a continuing basis. Civil penalties of up to $330,000 per day for certain CIRMP breaches have been reported in guidance on the current penalty framework. This is the exposure that makes delayed action extremely costly.

 

Where Physical Security Creates Specific Penalty Exposure

Most of the guidance and commentary on SOCI penalties is written from a cyber and information security perspective. Physical security – the protection of the physical asset, its perimeter, its access arrangements, and its people – is the hazard category that receives the least attention in compliance programs and the least published guidance from consultants.

That creates a specific and underappreciated exposure. Responsible entities that have invested heavily in cyber compliance but have not formally assessed and documented their physical security arrangements are at risk of being unable to demonstrate that their CIRMP adequately addresses the physical security hazard category.

The physical security exposures most likely to attract regulatory attention include:

No independent physical security assessment on file. The CIRMP must be based on evidence. A physical security section that describes controls in general terms, without an independent assessment of whether those controls are adequate against the actual threat environment, is difficult to defend in an audit or regulatory inquiry. The absence of an independent assessment is the single most common physical security gap in CIRMP documentation.

Out-of-date documentation. Physical security arrangements change over time – access control systems are reconfigured, facilities are modified, staffing arrangements change, and the threat environment evolves. A physical security assessment conducted three years ago that has not been reviewed or updated does not demonstrate that the responsible entity is currently managing its physical security risk. The CIRMP requires ongoing management, not a one-time exercise.

No testing of physical security arrangements. The SOCI Act requires responsible entities to test that their security arrangements are effective. For physical security, this means testing that access controls perform as intended, that surveillance systems are producing usable coverage, that alarm responses are working, and that incident response procedures are understood and exercised. An organisation that cannot demonstrate it has tested its physical security arrangements has an evidential gap in its CIRMP compliance.

Failure to address out-of-hours vulnerability. Critical infrastructure assets are often most vulnerable outside business hours – when staffing is reduced, monitoring is intermittent, and response times are longer. A physical security plan that addresses business hours arrangements but does not specifically address after-hours controls and monitoring does not fully meet the requirement to manage physical security hazards.

No documented incident response for physical security breaches. The CIRMP must include incident response arrangements for physical security events. A physical intrusion, a perimeter breach, an access control failure, or an insider threat incident each requires a defined response. Organisations without documented, tested physical security incident response procedures have a gap that a CISC audit would identify.

 

What Demonstrating Reasonable Steps Requires

The SOCI Act sets “reasonable steps” as the compliance standard. This is a judgement about what a responsible entity in your position, operating your type of asset, should have done to manage physical security risk. It is not a prescriptive checklist – which means the standard is flexible, but it also means there is no minimum box to tick that guarantees compliance.

In practice, demonstrating reasonable steps in physical security requires four things.

An independent, documented assessment. An assessment conducted by a credentialed independent consultant – aligned with ISO 31000:2018 – that identifies the realistic physical security threats to the asset, evaluates current controls against those threats, and rates residual risk. Self-assessment or a vendor-conducted assessment carries significantly less weight than an independent assessment when the question of reasonable steps is being examined.

A physical security plan grounded in the assessment findings. The enhanced CIRMP Rules – proposed by the Department of Home Affairs in 2026 – require a dedicated physical security plan. That plan must address site nature and access arrangements, perimeter and access controls, surveillance and monitoring, out-of-hours arrangements, incident response, and testing. The plan must be grounded in the assessment evidence, not written independently of it.

Evidence of testing and review. The testing requirement is active and ongoing. Records of CCTV health checks, access control audits, alarm response tests, and patrol verification all contribute to demonstrating that physical security arrangements are being actively managed rather than simply documented.

A current risk register. The CIRMP risk register must include physical security hazards, rated by likelihood and consequence, with treatment actions documented and tracked. A risk register that lists physical security as a generic category without specific hazards, ratings, and treatment evidence does not demonstrate the level of engagement the Act requires.

 

The Cost of Delay

The penalty framework creates a strong financial case for acting now rather than waiting until closer to the June 2028 compliance deadline for the physical security plan requirement.

There are two cost dynamics that responsible entities frequently underestimate.

The first is the daily penalty exposure for continuing non-compliance. An organisation that becomes aware of a deficiency in its physical security arrangements – whether through an internal review, a CISC engagement, or a regulatory inquiry – and does not take steps to remediate that deficiency is accumulating continuing breach exposure for each day the deficiency persists. Acting promptly once a gap is identified is not just good governance – it directly limits penalty exposure.

The second is the evidentiary value of early action. A responsible entity that has commissioned an independent physical security assessment, developed a documented plan, and begun implementing its findings is in a fundamentally stronger position in any regulatory interaction than one that is starting from scratch in response to a direction or inquiry. The CISC’s approach to enforcement takes into account the steps an entity has taken to identify and address non-compliance. Early, voluntary action is a mitigating factor. Late, reactive action in response to regulatory pressure is not.

 

Engaging Smartsec for SOCI Physical Security Compliance

Smartsec Security Solutions delivers independent physical security assessments and CIRMP physical security plan development for critical infrastructure operators across Western Australia.

Our work is focused exclusively on the physical security hazard category – the protection of the physical asset, its perimeter, its access arrangements, and the people who work within it. We do not provide cyber security consulting, personnel security advice, or supply chain risk management. That focus means the physical security assessment is deep, specific, and conducted by a consultant who understands what physical security compliance under the SOCI Act actually requires.

Our assessments are aligned with ISO 31000:2018, vendor-neutral, and produced to the standard that boards, auditors, and regulators expect. We are a licensed WA Security Risk Consultant and Security Agent, holding the Security Risk Management Certified Professional (SRMCP) credential.

Contact Smartsec Security Solutions to discuss your physical security CIRMP obligations and arrange a scoping conversation.

more insights

Call for a scope chat