Most founders assume the Security of Critical Infrastructure Act 2018 (Cth) — the SOCI Act — is about power stations, ports and water treatment plants. It is. But since the 2021–22 amendments expanded the regime to eleven sectors and 22 asset classes, one of those sectors is data storage and processing — and it’s the one that catches software companies. A startup doesn’t need to look anything like infrastructure to be swept in. It needs two things: the right kind of customer — government, or a business that is itself critical infrastructure — and the wrong kind of data, what the Act calls business critical data. Win an enterprise contract that combines them, and your platform can legally become critical infrastructure — with a register obligation, mandatory incident reporting on a 12-hour clock, and a risk management program with a board-approved annual report to follow.
How a SaaS Company Becomes Critical Infrastructure
The trigger is the definition of a critical data storage or processing asset in section 12F of the Act. Stripped of its drafting, an asset — your platform, your databases, the systems that run your service — is caught if you’re a data storage or processing provider (you provide data storage or processing services on a commercial basis) and the asset is used wholly or primarily to provide a service that relates to business critical data for one of two kinds of end-user:
- Government. The service is provided to the Commonwealth, a State or a Territory, or a body corporate established under a law of one of them — and you know the asset is used that way. (Before the 2022 amendments, any government data was enough; since then, the business critical data requirement applies to government customers too.)
- Other critical infrastructure. The service is provided to the responsible entity for another critical infrastructure asset — a bank, an energy retailer, a hospital operator, a telco — and you know the service relates to business critical data.
Business critical data is defined in section 5 and is broader than founders expect: personal information (in the Privacy Act sense) relating to at least 20,000 individuals, or information relating to research and development for a critical infrastructure asset, the systems or information needed to operate one, or risk management and business continuity for one. A B2B SaaS product holding a large enterprise customer’s employee records, or operational data about how a regulated utility runs its systems, can tick the box without holding anything that feels secret.
The knowledge element is doing real work in both limbs — and for critical infrastructure customers, the Act makes sure you can’t stay ignorant. Subsection 12F(3) requires the responsible entity for a critical infrastructure asset to notify its data storage and processing providers when they store or process business critical data for it, on pain of a civil penalty (CISC guidance). In practice, that notice often arrives as an unremarkable compliance letter from an enterprise customer’s procurement team. It is not unremarkable. For government customers there is no equivalent statutory notice — but the contract itself will usually tell you what you’re holding, and knowledge is knowledge however it arrives. From the moment you know, the definition can be satisfied — and the obligations attach to you as the asset’s responsible entity, regardless of headcount or revenue. There is no small business exemption.
What Switches On
Three core obligations apply to critical data storage or processing assets, administered by the Cyber and Infrastructure Security Centre (CISC) within Home Affairs:
- The Register of Critical Infrastructure Assets. You must give the Secretary operational information about the asset — and your direct interest holders (broadly, anyone who, together with associates, holds an interest of at least 10% in the asset, or holds an interest that puts them in a position to directly or indirectly influence or control it) must separately report their own interest and control information. Both must be kept current. Investors take note: this is not just the startup’s obligation — a qualifying investor acquires a SOCI reporting obligation of its own.
- Mandatory cyber incident reporting. A cyber incident with a significant impact on the asset — one that materially disrupts the availability of essential goods or services the asset provides — must be reported to the Australian Signals Directorate within 12 hours of you becoming aware of it. Incidents with a lesser relevant impact must be reported within 72 hours. An oral report buys time, but the written follow-up has its own fixed deadline — 84 hours for a critical report, 48 hours for the rest. These clocks run alongside, not instead of, your notifiable data breach obligations to the OAIC — one incident, multiple regulators, different deadlines.
- A Critical Infrastructure Risk Management Program (CIRMP). Data storage and processing is one of the asset classes switched on under the CIRMP Rules. That means a written, board-owned program addressing four hazard vectors — cyber and information security, personnel, supply chain, and physical and natural hazards — plus adoption of a recognised cyber framework (the ASD Essential Eight, ISO 27001, NIST CSF or equivalent), and an annual report approved by the board and submitted within 90 days of the end of each financial year.
Two further points from the 2024 amendments deserve attention. First, the Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024 extended the regime so that a regulated entity’s own data storage systems holding business critical data — including corporate IT it owns or operates alongside its operational systems — form part of the critical infrastructure asset itself, closing the gap where corporate IT sat outside the regulated operational systems. (Third-party providers aren’t swept up by this deeming rule — they’re addressed through section 12F.) Second, the government’s assistance and last-resort powers — including the ability to direct an entity’s incident response, and in extreme cases to authorise the ASD to intervene directly in your systems — apply to critical data storage or processing assets like any other. That is a level of statutory intervention no privacy law imposes.
Caught Without Being Caught: The Vendor Flow-Down
Even if section 12F never touches you, SOCI reshapes your commercial terms. Every regulated customer’s CIRMP must address supply chain hazards — and their lawyers discharge that obligation through your contract. Expect security questionnaires, audit rights, mandated frameworks, personnel vetting requirements, and incident notification windows shorter than SOCI’s own 12 hours. For a startup selling into banks, telcos, utilities or hospitals, these flow-down clauses are now standard, and pushing back requires knowing which asks are genuinely required by the customer’s CIRMP and which are gold-plating. Expect the asks to sharpen: since June 2026, an enhanced CIRMP tier applies to nine asset classes (electricity, gas, water, broadcasting and others), with tougher frameworks and new hazard categories — and customers in those classes will push the uplift down to their vendors.
A Practical Playbook
- Map your customers and your data. The trigger needs both: a government or critical infrastructure end-user, and a service relating to business critical data. Map customer lists against the eleven sectors, and map what each customer actually stores in your platform — before the sales team signs the deal, not after.
- Treat a section 12F notice as a legal event. Route customer notices about business critical data to whoever owns legal and compliance — not to a shared inbox.
- Count the individuals. If your platform holds personal information on 20,000+ individuals for a critical infrastructure customer, assume the business critical data threshold is met.
- Build the 12-hour clock into your incident response plan. If your cyber incident response plan doesn’t identify SOCI reporting as a workstream with an owner, it isn’t ready.
- Get ahead of the CIRMP. If you’re caught, the framework uplift (Essential Eight or ISO 27001) is the long pole. If you’re a vendor, certification is fast becoming the price of admission to enterprise deals anyway.
The Bottom Line
The SOCI Act is status-based regulation: it doesn’t ask whether you behaved badly, only what you are — and what you are can change with a single contract. For data-holding startups the exposure runs in two directions: being directly caught as a critical data storage or processing asset, and absorbing flow-down obligations as a vendor to everyone else who is caught. Neither is a reason to avoid government or enterprise customers — those are the best contracts a startup can win. But the compliance cost belongs in the deal model, and the trigger analysis belongs in your sales process. The worst position is the common one: becoming critical infrastructure by accident, and finding out from a regulator after the incident.
This article is general information only, not legal advice — whether the SOCI Act applies turns on the specific services you provide, the data you hold and who your end-users are. Viridian Lawyers advises Australian technology startups on regulatory exposure, enterprise and government contracting, and data governance. If a customer has just told you you’re holding their business critical data, get in touch before you sign the next renewal.