SOCI Act Readiness Checklist

Assess your organisation’s CIRMP readiness, identify potential compliance gaps and understand where your governance, risk and assurance arrangements may need strengthening.

SOCI Act Compliance

SOCI Act Readiness Checklist

A practical self-assessment for responsible entities preparing for a Critical Infrastructure Risk Management Program (CIRMP) compliance review.

About This Checklist

This self-assessment has been developed to help responsible entities evaluate the maturity of their Critical Infrastructure Risk Management Program (CIRMP) and identify potential areas for improvement.

It is intended as a practical readiness tool and should not be relied upon as a substitute for legal advice or a formal compliance audit.

How to Use It

For each statement, select the option that best reflects your organisation's current position.

Yes 2 points
Partially 1 point
No 0 points
01

Governance & Accountability

0 / 10
Yes
Partially
No
The CIRMP has been formally approved by the board or governing body.
Roles for implementing and maintaining the CIRMP are clearly documented.
Responsibility for the CIRMP has been assigned to a designated owner.
Review and approval dates are documented.
Governance reporting arrangements are established and documented.
02

Critical Assets & Risk Assessment

0 / 10
Yes
Partially
No
Critical infrastructure assets have been identified and documented.
Critical business functions and essential services have been identified and mapped.
Material risks have been assessed across cyber, personnel, physical security and supply chain hazard vectors.
Risk treatments have been documented and assigned to owners.
Risk assessments have been reviewed within the past 12 months.
03

Cyber Security

0 / 8
Yes
Partially
No
Cyber security controls align with an appropriate framework (e.g. ACSC Essential Eight, ISM or AESCSF).
A documented cyber incident response plan is in place.
Cyber incident response arrangements have been exercised or tested.
Privileged access is regularly reviewed and managed.
04

Personnel Security

0 / 8
Yes
Partially
No
Personnel screening requirements have been defined and implemented.
Processes exist for granting, reviewing and removing access.
Personnel receive regular security awareness training.
Insider threat risks have been considered within the CIRMP.
05

Physical Security & Natural Hazards

0 / 8
Yes
Partially
No
Physical security controls are documented for critical infrastructure assets.
Site access controls are implemented and regularly reviewed.
Natural hazard risks have been assessed for all relevant locations.
Emergency response arrangements have been documented and exercised.
06

Supply Chain Security

0 / 8
Yes
Partially
No
Critical suppliers and service providers have been identified.
Third-party security risks have been assessed.
Contracts include appropriate security obligations.
Contingency arrangements exist for critical suppliers and services.
07

Assurance & Evidence

0 / 10
Yes
Partially
No
Evidence demonstrates that security controls are operating effectively.
Internal reviews or assurance activities have been completed.
Findings and improvement actions are tracked and addressed.
Exercises or testing have validated key emergency and security arrangements.
Records are maintained to support compliance and assurance activities.
08

Reporting & Continuous Improvement

0 / 10
Yes
Partially
No
Annual CIRMP reporting obligations are understood.
Board reporting arrangements have been established.
Improvement actions are monitored through to completion.
Previous audit or assurance findings have been addressed.
Lessons identified from incidents, exercises and reviews are incorporated into the CIRMP.
Your Total Score
0 /72

Complete the assessment above to calculate your readiness.

Your Readiness Level

Assessment Not Yet Complete

Select an answer for each assessment statement to see your organisation's indicative SOCI Act readiness level.

61–72 Advanced Readiness

A mature approach to managing critical infrastructure risks.

43–60 Developing Readiness

Key elements are in place, with opportunities to strengthen implementation and assurance.

25–42 Foundational Readiness

Important controls exist, but gaps are likely across one or more CIRMP requirements.

0–24 Early Readiness

Significant work may be required across governance, risk management and assurance.

What Next?

Turn Your Results Into an Improvement Plan

Whether you're preparing for your next review or simply looking to strengthen your organisation's resilience, understanding where your gaps exist is the first step.

Resilient Services works with critical infrastructure organisations across Australia to strengthen governance, emergency preparedness and regulatory compliance through practical, risk-based solutions.

  • Independent CIRMP reviews
  • SOCI Act readiness assessments
  • Governance and compliance workshops
  • Risk and resilience improvement roadmaps
  • Emergency management planning and exercising
  • Internal audit and assurance support
Speak With Our Team

Book Your Complimentary SOCI Readiness Consultation

If you would like an independent review of your results or guidance on your next steps, our team is here to help.

Book a complimentary 30-minute SOCI Readiness Consultation and receive practical, expert advice tailored to your organisation's needs.

Book a SOCI Readiness Consultation