Australia

SOCI and CIRMP, documented as you onboard.

The Security of Critical Infrastructure Act covers 11 sectors, higher education among them, and requires a board-approved Critical Infrastructure Risk Management Program. Blueprint generates the evidence pack alongside the onboarding itself.

What applies in Australia

The SOCI Act requires asset registration and a board-approved CIRMP for responsible entities across 11 critical infrastructure sectors, including higher education, health, energy, water, communications and financial services. From August 2024, CIRMP cyber risk management must align with one of five recognised frameworks, Essential Eight and ISO 27001 among them.

The Cyber Security Act 2024 adds mandatory ransomware payment reporting within 72 hours. The Privacy Act's Notifiable Data Breaches scheme requires assessment within 30 days and notification to the OAIC as soon as practicable. APRA CPS 234 applies to regulated financial entities.

The 12-hour window

A critical cyber incident affecting a critical infrastructure asset must be reported to ASD within 12 hours, the tightest statutory window in any market we cover; other incidents within 72 hours. Every generated Australian IR framework carries these timelines explicitly, not as a footnote.

What the generated pack covers

Each Australian onboarding pack includes the IR framework with ASD and OAIC notification chains, a risk register aligned to your chosen CIRMP framework, Essential Eight maturity mapping, and source runbooks with the retention your frameworks require. Government engagements flag IRAP-assessed hosting where platform choice is constrained.

Statutory notification deadlines

TriggerDeadlineReport to
Critical cyber security incident affecting a critical infrastructure asset12 hoursASD
Other cyber security incident affecting a critical infrastructure asset72 hoursASD
Ransomware payment made by a critical infrastructure operator72 hoursASD
Eligible data breach likely to result in serious harmAssess within 30 days, notify as soon as practicableOAIC and affected individuals

Frequently asked questions

Does SOCI really apply to universities?
Yes. Higher education and research is one of the 11 regulated critical infrastructure sectors under SOCI, which means asset registration and a board-approved CIRMP.
What are the incident reporting deadlines?
Critical incidents affecting a critical infrastructure asset: 12 hours to ASD. Other incidents on such assets: 72 hours. Ransomware payments by critical infrastructure operators: 72 hours, regardless of outcome.
Which frameworks satisfy CIRMP?
Five are recognised: Essential Eight, NIST CSF, C2M2, ISO 27001 and the AESCSF for energy. Blueprint maps the generated pack against whichever your CIRMP nominates.

Partner with us

Blueprint is white-label first: your branding on every generated pack, your domain on the client portal. We are looking for our first delivery partner in Australia.

Apply as a partner