SOCI cyber incident clock
Part 2B of the SOCI Act. Significant impact on availability: 12 hours. Other cyber incidents with a relevant impact: 72 hours. The clock starts when the responsible entity becomes aware, not when root cause is finished.
Part 2B of the Security of Critical Infrastructure Act 2018 is the mandatory cyber incident reporting duty for critical infrastructure. The responsible entity for a critical infrastructure asset to which Part 2B applies must report certain cyber security incidents to the relevant Commonwealth body. The clocks run from when that entity becomes aware that the incident and the impact threshold are met, not from when containment finishes or root cause is proven. Section 30BF: if the rules have not named another Department or Commonwealth body, the relevant Commonwealth body is ASD.
Twelve hours, significant impact on availability (s 30BC). If the responsible entity becomes aware that a cyber security incident has occurred or is occurring, and that it has had or is having a significant impact (direct or indirect) on the availability of the asset, it must give a report as soon as practicable and in any event within 12 hours after becoming so aware. Section 30BEA: significant impact exists if, and only if, the asset is used in connection with essential goods or services and the incident has materially disrupted the availability of those goods or services, or circumstances specified in the rules exist. Oral report allowed; if oral, a written record in the approved form must follow within 84 hours after the oral report.
Seventy-two hours, other cyber incidents with a relevant impact (s 30BD). If the responsible entity becomes aware that a cyber security incident has occurred, is occurring, or is imminent, and that it has had, is having, or is likely to have a relevant impact on the asset, it must report as soon as practicable and in any event within 72 hours after becoming so aware. Section 8G: a relevant impact of an incident on a critical infrastructure asset is a direct or indirect impact on availability, integrity, or reliability of the asset, or on the confidentiality of information about the asset, information stored in the asset, or computer data that is the asset. Oral report allowed; if oral, the written approved-form record is due within 48 hours after the oral report, not 84.
Who files, what counts, when Part 2B applies. The filer is the responsible entity for the asset (ss 30BC(1)(a), 30BD(1)(a)). A cyber security incident is defined in s 12M: unauthorised access to or modification of computer data or a program; unauthorised impairment of electronic communication to or from a computer; or unauthorised impairment of the availability, reliability, security or operation of a computer, computer data, or a computer program. Part 2B applies only where s 30BB says it does: the asset is specified in the rules, or is the subject of a s 51 declaration that applies this Part (subject to any rules grace period for newly critical assets). Civil penalty for breach of the reporting and written-record duties: 50 penalty units (ss 30BC, 30BD).
Do not confuse the clocks. This page is SOCI Part 2B. The NDB clock is Privacy Act assessment and notify-as-soon-as-practicable to the OAIC. Ransomware payment reporting is Cyber Security Act 2024 Part 3: 72 hours after a payment, or after becoming aware someone paid on your behalf. Paying does not pause SOCI. An NDB assessment does not pause SOCI. One incident can trip all three. Report what you know; the Act requires a report about the incident, in the approved form when written.
Practical desk. Put the 12-hour and 72-hour triggers in the same IR playbook as the NDB checklist. Name who can declare aware, who phones ASD, and who files the written form. Prefer writing first if you can; if you go oral to hit the clock, start the 84-hour or 48-hour written follow-up immediately. The SOCI Act obligations page is the wider map (positive security obligations and the SoNS overlay). This page is only the Part 2B clock.
See also:
Fact source: Security of Critical Infrastructure Act 2018 (compilation 4 April 2025), Part 2B.
