Empire Protection

SOCI · Critical infrastructure · Governance

The CIRMP annual report: what the SOCI Act actually asks for

Responsible entities must report on their risk management program within 90 days of the financial year end, with board approval. Here is what the report has to say.

Published 31 August 2026 · 2 min read

If you are a responsible entity for a critical infrastructure asset, the annual report on your Critical Infrastructure Risk Management Program is the one obligation that has a hard date attached to it, and the one most often left until the month it is due.

The deadline, and who signs it

The report goes to the relevant regulator within 90 days of the end of the Australian financial year. It must be approved by the entity’s board, council or other governing body.

That second requirement is the one that determines your real timeline. If your board meets quarterly, the meeting that approves this report has to be inside the window, with papers circulated before it, so the work has to be finished well before the 90 days are up. Organisations that plan to the deadline rather than to the board calendar are the ones that end up seeking an out of session approval in a hurry.

What the report has to contain

The report is an assurance document, not a copy of your program. It must state:

  • whether the risk management program was up to date during the year;
  • any variations made to the program; and
  • how the program was effective in mitigating the relevant impacts of any hazards that affected the asset during the year.

It does not need to contain the full program. It does need to be sufficient to assure the regulator that the program remains up to date and appropriate, which is a higher bar than a page saying nothing went wrong.

The third point is where reports get thin

Whether the program was up to date is a matter of record. Variations are a matter of record. Effectiveness is an argument, and it is the part that cannot be reconstructed at the end of the year from memory.

If an incident happened, the useful version of this section says what the program was supposed to do, what it actually did, and what changed as a result. If nothing happened, it says how you know the controls were working rather than merely untested. Either answer needs evidence that was captured when the event occurred, which is a decision you make in July, not in September.

The all hazards scope catches people out

A CIRMP is not a cyber program. It takes an all hazards view: physical and natural hazards, personnel, supply chain, and cyber and information security. Organisations whose security function sits entirely inside IT routinely produce a strong cyber section and a thin personnel and supply chain one, and that imbalance is visible in the report.

Obligations under the SOCI Act and its Rules change, and the requirements that apply depend on your asset class. Treat this as an orientation, not as the authority: confirm what applies to you against the current instrument and the CISC guidance before you rely on it.

Empire Protection works with responsible entities on the program behind the report: the risk register, the controls, and the evidence that makes the effectiveness section something you can actually write.

General information, not advice for your circumstances. Obligations change: confirm anything you intend to rely on against the current instrument.