Critical Infrastructure Pack

Critical infrastructure compliance across four frameworks.
Every obligation mapped.

SOCI, CPS 234, NIS2, DORA — critical infrastructure operators face overlapping cyber resilience requirements from multiple regulators. AuditDSS maps every obligation and shows where they converge.

1,498

CI obligations

4

Frameworks

320+

Regulatory frameworks

146,445+

Scored obligations

Critical infrastructure is under attack — and regulators are responding with overlapping frameworks

Critical infrastructure operators face a convergence of cyber resilience regulation unlike any other sector. In Australia, the Security of Critical Infrastructure Act (SOCI) imposes risk management programs, incident reporting, and government assistance orders. APRA's CPS 234 mandates information security capability commensurate with threats. The EU's NIS2 Directive applies to essential and important entities across 18 sectors. And DORA imposes digital operational resilience requirements on financial entities and their ICT service providers.

Each framework emerged from different regulators with different enforcement powers — but the underlying requirements share 60-70% common ground. A single incident response capability can satisfy SOCI mandatory reporting, CPS 234 security incident notification, NIS2 incident handling, and DORA ICT incident classification simultaneously. AuditDSS maps every cross-reference.

That's what AuditDSS does.

Four critical infrastructure frameworks — decomposed

1,498 obligations across 4 frameworks, scored and ready. AuditDSS maps every obligation and shows where SOCI, CPS 234, NIS2, and DORA converge.

Updated March 2026 — new frameworks added regularly

Tier 2 EU Requirements — What NIS2 and DORA Require

From regulation to compliance in four steps

1

Classify

Determine your critical infrastructure classification under SOCI, NIS2, and DORA. Identify which sector-specific obligations apply.

2

Cross-Map

See how a single cyber resilience control satisfies obligations across SOCI, CPS 234, NIS2, and DORA simultaneously. Identify unique requirements for each framework.

3

Remediate

Generate risk management programs, incident response procedures, and resilience testing plans that satisfy all four frameworks. Every clause traced to specific regulatory text.

4

Report

Pre-mapped evidence for SOCI compliance audits, APRA prudential reviews, NIS2 supervisory assessments, and DORA resilience testing requirements.

Your existing security data is compliance evidence — we connect the dots

Incident Response

Incident detection logs, response playbooks, notification records, and post-incident reviews. AuditDSS maps your IR evidence to SOCI 12-hour reporting, CPS 234 board notification, NIS2 24-hour early warning, and DORA ICT incident classification simultaneously.

Risk Management

Risk registers, threat assessments, vulnerability management records, and risk treatment plans. Direct evidence for SOCI risk management programs, CPS 234 security capability, NIS2 risk management measures, and DORA ICT risk framework.

Resilience Testing

Penetration test results, scenario-based testing, business continuity exercises, and disaster recovery tests. Maps to SOCI exercise requirements, CPS 234 testing obligations, NIS2 resilience testing, and DORA TLPT (threat-led penetration testing).

Supply Chain Security

Third-party risk assessments, vendor security questionnaires, ICT service provider contracts, and supply chain incident notifications. Evidence for SOCI supply chain obligations, NIS2 supply chain security, and DORA ICT third-party risk management.

You don't need four separate compliance programs. You need one platform that shows where SOCI, CPS 234, NIS2, and DORA converge — and where they diverge. 60-70% of requirements overlap. AuditDSS maps every cross-reference.

Compliance isn't just a cost — it's a competitive advantage

Most compliance platforms tell you what you must do to avoid penalties. AuditDSS also tells you what you gain by complying.

Cross-framework efficiency

60-70% of requirements overlap. One control set, four frameworks satisfied.

Incident readiness

Know your reporting obligations across all frameworks — 12 hours for SOCI, 24 hours for NIS2, 72 hours for DORA.

Regulatory confidence

Pre-mapped evidence for SOCI audits, APRA reviews, NIS2 assessments, and DORA testing.

Board reporting

Obligation-level compliance scoring across all four frameworks for board risk committees.

Penalty avoidance

SOCI directions carry significant penalties. NIS2 fines up to €10M or 2% of global turnover.

Operational resilience

Genuine resilience improvement, not just checkbox compliance.

Built for everyone in the critical infrastructure compliance chain

Critical Infrastructure Operators

Energy, water, telecommunications, healthcare, financial services — if you're a SOCI-regulated entity, map your risk management program obligations and incident reporting requirements.

APRA-Regulated Entities

Banks, insurers, super funds — CPS 234 and SOCI both apply. See where they overlap and where CPS 234 has additional security capability requirements.

CISOs & Security Teams

Map your existing security controls across all four frameworks. Identify the minimum control set that satisfies SOCI, CPS 234, NIS2, and DORA — no duplicate effort.

EU-Operating Australian Companies

NIS2 and DORA apply to your EU operations. SOCI and CPS 234 apply domestically. AuditDSS shows the complete cross-jurisdictional picture.

Enterprise compliance intelligence, built for critical infrastructure

Regulation Finder

Answer a few questions, discover every regulation that applies to your critical infrastructure operations

Obligation-Level Decomposition

Not just 'you need SOCI compliance' but 1,498 specific obligations across 4 frameworks, scored by risk

Gap Analysis & Risk Scoring

See exactly where you're compliant and where you're exposed across all four frameworks

Policy & Procedure Generation

Deterministic document generation for risk management programs, incident response plans, and resilience testing procedures. Every clause traced to specific regulatory text.

Dual Workspace Mode

Company Mode for your own compliance. Advisor Mode for consultants managing multiple critical infrastructure clients.

Ready to map your critical infrastructure compliance?

Discover which frameworks apply to your business in minutes — or book a walkthrough to see AuditDSS in action.

Building critical infrastructure technology? AuditDSS provides the compliance intelligence layer for SIEM, OT security, incident management, and resilience testing platforms. Contact us about integration partnerships