---
title: Regulatory Obligations: There's now an 18-month deadline to implement a critical infrastructure Risk Management Program
description: "The implementation of Australia’s #criticalinfrastructure reforms (SOCI 2018) is continuing and gaining practical momentum. On 17 Feb, Minister Claire O’Neil activated the legislation’s Risk Management Program (RMP) obligations for 13 specific critical infrastructure asset classes, including data processing and storage, and payment systems...."
image: https://blog.nextgen.group/hubfs/cyber%20banner%20resize%20960.jpg
---

- [Latest Articles](https://blog.nextgen.group/content-hub)
- [Announcements](https://blog.nextgen.group/content-hub/tag/announcements)
- [AWS](https://blog.nextgen.group/content-hub/tag/aws)
- [Case study](https://blog.nextgen.group/content-hub/tag/case-study)
- [Cloud](https://blog.nextgen.group/content-hub/tag/cloud)
- [Cyber Security](https://blog.nextgen.group/content-hub/tag/cyber-security)

More Topics Government

Topics Latest Articles Announcements AWS Case study Cloud Cyber Security Government

 background-color: transparent; background-image: linear-gradient(-90deg, rgba(221, 221, 221, 100% ), rgba(238, 238, 238, 100% )); color: #333333;

---

![](https://blog.nextgen.group/hubfs/cyber%20banner%20resize%20960.jpg)

The implementation of Australia’s #criticalinfrastructure reforms (SOCI 2018) is continuing and gaining practical momentum. On 17 Feb, Minister Claire O’Neil activated the legislation’s Risk Management Program (RMP) obligations for 13 specific critical infrastructure asset classes, including data processing and storage, and payment systems.

Don’t yawn.

The RMP is the requirement that makes cyber security a Board-level concern for critical infrastructure and its supply chain. Why? Because it requires a Board-equivalent to sign off, and report annually on, to the Minister that the RMP is being maintained and complied with (and presumably funded!).

Now there’s some time at play here: 6 months (from 17/02/23) to adopt a written RMP; and another 12 months to implement and ‘comply’ with it. Essentially, that is, to make good on your security promises. Let’s put that into perspective. How’re you going with your 2022 NYE resolutions?

Better than mine, in all probability.

Anyways, ready for another jump scare? Well, the RMP has to manage the ‘material risks’ of ‘hazards’ which could have a ‘relevant impact’ on their critical infrastructure asset. Then the owner/operator has to minimise or eliminate, and mitigate, any identified material risks. So, to help out, Home Affairs has advised that 'the storage, transmission or processing of sensitive operational information outside Australia poses a material risk as declared in the Security of Critical Infrastructure Act 2018 (SOCI) Risk Management Program Rules'. Their italics and underline. My bolds.

The way I read it, a critical infrastructure asset owner or operator now has a HA-advised requirement to consider ANY existence of sensitive operational #data outside Oz as - potentially - a bad thing. Or, at least, that an overseas touch of some types of data is a risk that needs explicit consideration, mitigation, and minimisation in the RMP. Annually. Attested to Government. At the Board-level.

Wow.

And here’s the thing, my impression from the commentary around the government’s review of Australia’s Cyber Security Strategy is that it’ll dial UP the requirements in both SOCI 2018 and in Australia's possible new Cyber Security Act. My italics, underline, bold and caps.

The way I see it, there's a choice. You either procrastinate on this OR see it as a chance to do some good for the national interest AND to get in front of your #cybersecurity obligations. If your gut feel is more aligned to the phrases after my "OR", then hit me up for a discussion … or contact infinitely more capable people, like Hayden Loader and Rennick Rogers, about transformative, future-forward, (N)extgen software and hardware solutions.

Looking for more detail? Either search for it or:

For the RMP: [**https://www.cisc.gov.au/legislative-information-and-reforms/critical-infrastructure/regulatory-obligations**](https://www.cisc.gov.au/legislative-information-and-reforms/critical-infrastructure/regulatory-obligations) and its child links. This includes details on the asset classes whose RMP has been triggered.

For offshore data risks, either go deep-sea fishing into HA’s nested menus or: [**https://www.cisc.gov.au/critical-infrastructure-centre-subsite/Files/cisc-factsheet-advice-offshore-data.pdf**](https://www.cisc.gov.au/critical-infrastructure-centre-subsite/Files/cisc-factsheet-advice-offshore-data.pdf)

Finally, as always, I’m not qualified (nor paid) to be a lawyer. 

- Posted In:
- [Cyber Security](https://blog.nextgen.group/content-hub/tag/cyber-security)

###### Like what you see? Share with a friend.

[twitter icon ](https://twitter.com/intent/tweet?text=I+found+this+interesting+blog+post&url=https://blog.nextgen.group/content-hub/regulatory-obligations) [facebook-f icon ](http://www.facebook.com/share.php?u=https://blog.nextgen.group/content-hub/regulatory-obligations) [linkedin-in icon ](http://www.linkedin.com/shareArticle?mini=true&url=https://blog.nextgen.group/content-hub/regulatory-obligations)

##### Related Articles

[![](https://blog.nextgen.group/hubfs/blog%20banner%201%20resize%20960.jpg) ](https://blog.nextgen.group/content-hub/regulatory-obligations-whats-soci)

- Mar 2023

- /[Cyber Security](https://blog.nextgen.group/content-hub/tag/cyber-security)
- /[Government](https://blog.nextgen.group/content-hub/tag/government)

### [Regulatory Obligations: So…what’s a SOCI?](https://blog.nextgen.group/content-hub/regulatory-obligations-whats-soci)

Posted by [NEXTGEN](https://blog.nextgen.group/content-hub/author/nextgen)

[![](https://blog.nextgen.group/hubfs/MSOC%20image.jpg) ](https://blog.nextgen.group/content-hub/nextgen-launches-australia-based-managed-soc-as-a-service-a-game-changer-for-channel-partners)

- Aug 2025

### [NEXTGEN Launches Australia-Based Managed SOC as a Service: Empowering Channel Partners with Enterprise-Grade Security and Full Data Sovereignty](https://blog.nextgen.group/content-hub/nextgen-launches-australia-based-managed-soc-as-a-service-a-game-changer-for-channel-partners)

Posted by [NEXTGEN](https://blog.nextgen.group/content-hub/author/nextgen)

[![SpyCloud Airline Case Study](https://blog.nextgen.group/hubfs/Blog%20Pic-960x560-SpyCloud-1.jpg) ](https://blog.nextgen.group/content-hub/spycloud-secures-australias-largest-airline-a-case-study-in-disrupting-cybercrime)

- Sep 2024

- /[Cyber Security](https://blog.nextgen.group/content-hub/tag/cyber-security)

### [SpyCloud Secures Australia's Largest Airline: A Case Study in Disrupting Cybercrime](https://blog.nextgen.group/content-hub/spycloud-secures-australias-largest-airline-a-case-study-in-disrupting-cybercrime)

Posted by [Nick Love](https://blog.nextgen.group/content-hub/author/nick-love)

### Discover new opportunities to grow your business. Get in touch today

NEXTGEN is dedicated to helping vendors and partners discover new opportunities that enhance brand awareness, generate sales, and drive ambitious business growth plans throughout the ANZ region.

[ CONTACT US ](https://nextgen.group/contact)

[ EXPLORE OUR SERVICES ](https://nextgen.group/services)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "NEXTGEN",
    "url" : "https://blog.nextgen.group/content-hub/author/nextgen"
  },
  "dateModified" : "2024-08-29T00:05:44.797Z",
  "datePublished" : "2023-03-21T23:00:00.000Z",
  "headline" : "Regulatory Obligations: There's now an 18-month deadline to implement a critical infrastructure Risk Management Program",
  "image" : [ "https://blog.nextgen.group/hubfs/cyber%20banner%20resize%20960.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.nextgen.group/content-hub/regulatory-obligations",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.nextgen.group/hubfs/NEXTGEN%20EXN%20LOGO%20NEW.svg"
    },
    "name" : "NEXTGEN"
  }
}
```