The SOCI Act doesn't ask for a training slide deck — it asks you to prove that your people are a managed risk, not a gap in your critical infrastructure risk management program. This guide breaks the compliance requirement into training steps you can actually execute in 2026.
TL;DR
- SOCI Act CIRMP obligations require documented personnel hazard controls, not generic security awareness training - Cyber Aware maps training records directly to that requirement.
- Reportable entities across the 11 critical infrastructure sectors must show phishing and social engineering training tied to incident response, not a once-a-year module.
- Cyber incidents must be reported to the ASD within 12 hours (significant) or 72 hours (relevant) in 2026 - staff who can't recognise an incident can't hit that clock.
- Annual CIRMP reporting sits inside 90 days of the end of the financial year, so training completion data needs to be audit-ready well before that deadline.
- Verdict for 2026: build training around personnel hazard management first, then layer in phishing simulation cadence - Buy the process, not the certificate.
Why this matters
The Security of Critical Infrastructure Act 2018, amended by the SLACIP Act in 2022, put a legal obligation on responsible entities across 11 sectors to run a Critical Infrastructure Risk Management Program. Personnel hazards - untrained staff, insider risk, social engineering exposure - sit inside that program as a named risk category, not an afterthought.
Most teams treat security awareness training as an HR checkbox and the SOCI Act as an IT problem. That split is exactly what auditors flag in 2026: a CIRMP that lists "staff training" as a control but has no completion data, no phishing simulation results, and no link between training content and the specific hazards the entity actually faces. Cyber Aware exists to close that gap with training records that map to the control, not just a course.
The fix isn't more training volume. It's training that's traceable to a named hazard, timestamped, and reportable inside the same 90-day window your CIRMP annual report is due.
What you'll need
- A current copy of your organisation's Critical Infrastructure Risk Management Program document
- A list of the specific critical infrastructure asset(s) your entity is responsible for under the SOCI Act
- Existing security awareness training platform or a plan to select one for 2026
- Access to incident reporting history (or a blank log if this is your first reporting cycle)
- HR and IT sign-off on who owns personnel hazard reporting
- A calendar view of your financial year end, since the annual CIRMP report is due within 90 days of that date
The steps
1. Map personnel hazards to your CIRMP, not to a generic training catalogue
Pull the personnel hazard section of your risk management program and list every hazard where an untrained or malicious staff member is the point of failure - phishing-enabled account takeover, physical access misuse, insider data exfiltration. Generic "cyber security 101" modules don't satisfy this because they aren't tied to your named hazards.
Common mistake: buying an off-the-shelf course library and assuming volume equals coverage. A CIRMP auditor in 2026 wants to see the line from hazard to control to training content, not a catalogue of 40 unrelated modules.
2. Set training scope by sector-specific risk, not company size
A port operator's personnel hazard profile looks nothing like a telco's or a data centre's, even if both sit under the SOCI Act. Rail and transit staff need training on physical-cyber convergence risks; data storage operators need training weighted toward credential handling and access control abuse.
Build your curriculum around the asset class you're responsible for reporting on, then generalise outward. This step alone cuts wasted training hours because staff stop sitting through content irrelevant to their actual exposure.
3. Build a documented security awareness policy before you run a single simulation
Auditors ask for the policy before they ask for the completion rate. Your policy needs to state training frequency, who's exempt and why, escalation steps for repeat failures, and how records are retained for the reporting period.
Without a written policy, even a 98% completion rate looks like an accident rather than a managed control. Expect this document to be the first thing requested in a SOCI Act compliance review in 2026.
4. Run phishing simulations that mirror real reported incident patterns
Generic phishing templates train staff to spot obvious scams, not the business email compromise and invoice fraud patterns actually driving reportable incidents in Australia. Build simulations around credential harvesting and vendor impersonation, since those are the patterns most likely to trigger the 12-hour or 72-hour reporting clock.
Expected outcome: click rates should drop measurably within two to three simulation cycles. If they don't move after three rounds, the simulation difficulty or realism is wrong, not the staff.
5. Set incident recognition training against the 12-hour and 72-hour clock
Staff need to know the difference between an incident they escalate immediately and one that goes through standard IT support. Training should include a decision tree: what qualifies as a significant cyber incident under the SOCI Act, who they call, and how fast.
This is the step most programs skip because it looks like an IT process rather than a training topic. It's both - staff who can't recognise urgency can't help you hit a 12-hour reporting window no matter how good your incident response plan is on paper.
6. Log completion data in a format your annual CIRMP report can use directly
Don't let training completion sit in a separate LMS with no export path. Structure records so training-by-hazard, training-by-role, and training-by-date all pull cleanly into the annual report due within 90 days of financial year end.
Common mistake: discovering in month 11 that the training platform can't produce a report matching the CIRMP hazard categories, forcing a manual reconciliation under deadline pressure.
7. Brief leadership before the reporting deadline, not during it
The board or responsible entity signing off on the CIRMP annual report needs training outcomes in plain language weeks before the 90-day deadline, not the night before submission. A short executive summary covering completion rate, click-rate trend, and any unresolved personnel hazards keeps sign-off fast.
Expected outcome: leadership sign-off in days, not weeks, because the data was pre-packaged for a non-technical reader.
Map your training to CIRMP obligations
See how Cyber Aware structures training records for SOCI Act reporting.
Troubleshooting
- Completion data doesn't match hazard categories in the CIRMP. Rebuild your training taxonomy around the exact hazard names used in the risk management program document, not the platform's default course names.
- Click rates plateau after several phishing rounds. Rotate simulation templates toward current scam patterns - invoice fraud and vendor impersonation are outperforming generic "prize win" phishing in 2026.
- Staff don't know when to escalate a suspected incident. Add a one-page decision tree to onboarding and refresh training, separate from general phishing awareness content.
- Annual report deadline creates a scramble every year. Set a calendar reminder 120 days before financial year end to start data pulls, giving 30 days of buffer before the 90-day submission window opens.
- Contractors and third parties fall outside standard training tracking. Extend your personnel hazard scope to cover contractors with access to critical infrastructure assets - the SOCI Act doesn't exempt them just because they're not payroll staff.
Tools and resources
- Your organisation's current Critical Infrastructure Risk Management Program document
- A security awareness policy built for audits as your baseline governance document
- A phishing simulation platform capable of exporting completion and click-rate data by role and hazard category
- Incident reporting contact details for the Australian Signals Directorate
- A shared calendar tracking the 90-day annual reporting window against your financial year end
What to do next
Once training is mapped to your CIRMP, the next gap most SOCI Act reporting entities hit is proving the same discipline against the Privacy Act, since personal information handling failures often trigger both obligations at once. Cross-reference your training records against both frameworks before your next audit cycle.
FAQ
What is SOCI Act security awareness training?
SOCI Act security awareness training is staff training designed to satisfy the personnel hazard management requirement inside a Critical Infrastructure Risk Management Program under the Security of Critical Infrastructure Act 2018. It needs to be documented, hazard-specific, and tied to incident reporting obligations rather than generic cyber hygiene content.
Which sectors need to comply with the SOCI Act in 2026?
The SOCI Act covers 11 critical infrastructure sectors in 2026, including energy, water and sewerage, transport, health care, communications, data storage and processing, and financial services and markets. Responsible entities in these sectors must maintain a Critical Infrastructure Risk Management Program that addresses personnel hazards.
How fast do cyber incidents need to be reported under the SOCI Act?
Significant cyber incidents must be reported to the Australian Signals Directorate within 12 hours, while other relevant incidents have a 72-hour window. Staff training needs to include incident recognition so these clocks start as early as possible.
Does generic cyber security training satisfy SOCI Act requirements?
No, generic training rarely satisfies SOCI Act requirements because auditors expect training content mapped to the specific personnel hazards named in your risk management program. A course library with no link to your CIRMP hazard categories won't pass review.
When is the annual CIRMP report due?
The annual Critical Infrastructure Risk Management Program report is due within 90 days of the end of your organisation's financial year. Training completion data needs to be audit-ready before that window opens, not compiled during it.
Is phishing simulation required under the SOCI Act?
The SOCI Act doesn't name phishing simulation specifically, but it's the most practical way to demonstrate that personnel hazard controls are active rather than theoretical. Entities that pair training with simulation data have a stronger audit position than those relying on completion certificates alone.
How is SOCI Act training different from Essential Eight alignment?
SOCI Act training focuses on personnel hazard management inside a formal risk management program with reporting deadlines, while Essential Eight alignment covers broader technical control maturity. Many critical infrastructure entities need to satisfy both frameworks simultaneously in 2026.
Who counts as a responsible entity under the SOCI Act?
A responsible entity is the organisation legally accountable for a critical infrastructure asset in one of the 11 covered sectors, and it carries the obligation to maintain and report on the risk management program including personnel hazards. Contractors with asset access typically fall inside that entity's training scope too.
One last thing
The entities that pass SOCI Act reviews cleanly in 2026 aren't the ones with the most training hours logged - they're the ones who can pull a hazard-by-hazard completion report in under five minutes when an auditor asks for it. Build that export path before you build the curriculum.