Articles

What is a “Relevant Operator” Under the SOCI Act Reform Review?

A relevant operator walking towards a wind farm
Table Of Contents

Quick Overview of “Relevant Operator”

  • The Department of Home Affairs introduced the new 'Enhanced CIRMP Rules' in June 2026, based on the review of the SOCI Act by Dr. Jilly Slay.
  • The proposed amendments introduced the term “relevant operator”, which is currently under discussion post the open consultation.
  • “Relevant operator” will be responsible for compliance, commensurate with the nature of work performed on the critical asset and the type of engagement with the responsible entity.

The Concept of “Relevant Operator”

The legislation reviews in the Australian critical infrastructure industry have brought up an interesting proposal, with implications going beyond the asset owner, a term called “relevant operator.”

This year the Department of Home Affairs opened consultation for the second tranche of reforms to the Security of Critical Infrastructure (SOCI) Act 2018. Tranche 2 is an impactful structural rewrite based on the independent review by Dr. Jill Slay AM, who’s findings and suggestions to the department have led to attempts of making obligations less complex, prevent overlapping, and more connected with how the Australian critical infrastructure assets actually operate.

The government accepted most of her recommendations in principle and hiding in those newly proposed measures was the concept of a certain type of third-party service provider.  

A formal legislative draft is yet to be released by the Home Affairs post industry feedback, however, the incumbents are seeking answers as to what it means to be a “relevant operator”.

Who is “Relevant Operator”?

An organisation or a person will be categorised as a "relevant operator”, if they meet both of the below criteria:

  • Practical operational authority involving configuration, maintenance, disablement, restoration, alteration, and material influence over the operation, availability, integrity, or security of the asset or critical functions.
  • Material dependency or ability to exercise control on the asset to keep running securely.

The above criteria will most often apply to a third-party service provider such as managed service provider (MSP), O&M, administrator, or contractor with influence, control, and power over the operations of critical asset. This status will be assumed based on the real responsibilities and day-to-day work performed by the organisation instead of what’s labelled in a contract. Invariably, it will exclude engagements like consultation, solely monitoring services, minor maintenance, or ad hoc support.  

“Relevant operator” Obligations and Implications for The Responsible Entity

Are you wondering what happens if you are classified as a “relevant operator”?

Let’s look at the proposed responsibilities for this:

  • The responsible entities will need to identify and register their relevant operators and the engagement details, with the aim to make visible to the government through registration and information mandates.
  • The arrangement must be made between the responsible entity and their relevant operators to maintain compliance with the CIRMP obligations in matters of dependency for critical functions, including support for incident response, access to information, oversight, assurance, testing, and remediation.
  • The relevant operators will face limited duties in proportion to their role, including cooperation with responsible entity’s compliance and obligation to notify of any changes, events, or circumstances affecting the asset, without omitting anything that will cause reasonable compromises to asset.
  • The responsible entity will be subject to the full extent of SOCI obligations but the relevant operator’s liability will be limited to their role and control over the asset.
  • The responsible entity will be protected by the framework for taking reasonable steps to secure.

The concept also offers some safety net to the responsible entities who can’t fully get co-operated efforts from their relevant operator in ensuring security of systems and processes if documented well.

How to Prepare for the “Relevant Operator” Implications

If your organisation deals with third-party services to help run the critical asset or systems, or if you are the external provider whose services align with this concept beyond what it looks like on the contract, you need to map inventories, systems, security practices, and documentation as per the CIRMP rules now. The time to implement the obligations starts now while the rules continue to take shape and become a part of the legislated regulations.

This is the space that OpusV operates in daily, enabling us to offer a unique perspective on OT networks, cyber security, and network design informed by our boots-on-the- ground experience with some of the biggest critical infrastructure assets in Australia. We are not only talking about policy or compliance but we are the ones with hands on OT networks, cyber security landscape, and network designs for some of the biggest electricity generation patrons.

We have witnessed that supply chain participants and third-party access points are one of the most under the radar risk surfaces posing challenges in the critical infrastructure today.

Do you know if you or your service provider meets the threshold of “relevant operator”? If you’re unsure, it’s worth a conversation with the seasoned industry specialists, before it becomes a legal ask than a best practice. Contact us.

Ready to defend your critical infrastructure?

Get in Contact
Interested in what we do? Join our team
OpusV is an industry leading team defending critical infrastructure.
View Careers
Learn more about us
Learn about OpusV's history, vision statement, team and more.
About Us