HomeBlogCritical Infrastructure
Critical Infrastructure

Autonomous Fleets Meet Critical Infrastructure Law: SOCI, New Zealand and the Gulf

Sep 2026 · 11 min read

Low-poly illustration at sunset of driverless shuttles on a curving elevated road between a port, a rail yard and a control tower, linked to a central beacon

The first commercial robotaxi services in the Gulf opened in 2025 and 2026, Australia plans to allow conditional automated vehicle deployment from 2027, and autonomous trucking is being trialled on freight corridors. Most discussion of these fleets is about vehicle safety. Less attention goes to what happens when the operator of a fleet becomes part of a country's critical infrastructure. This article looks at that question from the operator's side: which critical infrastructure obligations can reach an autonomous fleet in Australia, New Zealand, the UAE and Saudi Arabia, what changed in 2026, and what evidence a regulator will expect to see.

When a fleet operator becomes a critical infrastructure operator

A fleet of automated vehicles is a distributed control system. It depends on a cloud platform, telematics networks, map and software update pipelines, remote operations centres and suppliers across several countries. Industry research published in February 2026 found that 92% of automotive and mobility attacks in 2025 were carried out remotely, and 67% involved telematics or cloud systems, which is the operator's infrastructure rather than the car.

Critical infrastructure law regulates exactly that kind of infrastructure. The question is not whether a vehicle is critical, but whether the service the fleet delivers, freight movement or public transport, falls into a regulated asset class.

Australia: the SOCI Act transport classes

Isometric illustration of an autonomous truck, a freight terminal, a rail line and a port crane linked to a central control hub
SOCI transport classes include freight infrastructure, freight services, public transport, ports and aviation.

The Security of Critical Infrastructure Act 2018 covers five transport asset classes: critical ports, freight infrastructure, freight services, public transport and aviation. Most classes carry incident reporting and asset register obligations. Under the current rules as published by the Cyber and Infrastructure Security Centre, the obligation to run a Critical Infrastructure Risk Management Program (CIRMP) applies in transport to critical freight infrastructure and critical freight services assets.

That matters for autonomous freight. An operator whose automated trucks deliver a critical freight service could hold CIRMP obligations, while a robotaxi service would be assessed against the public transport definitions. The designation depends on the facts, so treat any fleet at scale as a candidate and check early.

The Enhanced CIRMP Rules made in June 2026 raise the bar for the asset classes they cover, including critical freight infrastructure and freight services. We covered them in detail in the Enhanced CIRMP Rules 2026. The changes most relevant to a fleet operator are:

  • assessment of foreign ownership, control or influence over major suppliers and critical components;
  • controls on offshore or remote access to critical components and business-critical data, which covers remote operations centres and teleoperation;
  • phishing-resistant multi-factor authentication with central logging and monitoring;
  • network segregation that keeps critical systems running for at least three months while other systems are restored;
  • a recognised framework at a defined maturity, such as ISO/IEC 27001, NIST CSF 2.0, Essential Eight Maturity Level Two, C2M2 MIL2 or AESCSF Security Profile 2;
  • background checks for critical workers, re-checked at least every five years.

Grace periods run for 12 months, to around June 2027, for foreign influence, offshore access, core cyber risks and access management, and 24 months, to around June 2028, for the remaining items. See the AESCSF and SOCI framework page and the Australia country guide for the full picture.

New Zealand: a regime in design

New Zealand has no automated vehicle framework yet, and trials run on exemptions. It does have a proposed critical infrastructure cyber regime. The discussion document released by the Department of the Prime Minister and Cabinet in February 2026, with consultation closing on 19 April 2026, proposes to bring about 200 entities into scope.

ElementWhat was proposed
Transport in scopeNational and high-volume roads, priority rail freight lines, specified airports and air traffic control, ports handling more than 4 million tonnes a year, major inland ports, Cook Strait ports and interisland freight ferries
Risk programmeA cyber risk management programme aligned with NIST CSF or ISO/IEC 27001:2022
Incident reportingSignificant incidents to the NCSC within 24 hours (initial) and 72 hours (full)
AccountabilityDirectors responsible for compliance, shown through attestations
PenaltiesUp to the greater of $5 million or 2% of turnover for entities, and up to $500,000 for directors, after a one-year grace period

No bill had been introduced as at September 2026. An autonomous freight or ferry operator connected to these assets should expect to be asked for the same programme, even if it is not named directly. The New Zealand country guide tracks the related frameworks.

The Gulf: driverless services already carrying passengers

The Gulf moved first. Dubai's Roads and Transport Authority launched commercial driverless taxi operations at the end of March 2026 with Baidu's Apollo Go and with WeRide through Uber, supporting Dubai's target of 25% of journeys being autonomous by 2030. In Abu Dhabi, WeRide obtained a fully driverless commercial robotaxi permit in October 2025, and in Saudi Arabia WeRide completed the Transport General Authority's pilot and began public rides in Riyadh with Uber in October 2025.

Two governance themes follow. First, the leading operators are headquartered outside the region, so foreign ownership, data residency and remote access are live questions for regulators and for the entities that contract with them. Second, the applicable cyber regime depends on who the operator is and who it serves:

Vehicle standards and operator standards are different evidence

A common mistake is to treat a manufacturer's vehicle certification as evidence of the operator's security. They answer different questions.

StandardWho it applies toThe evidence it produces
UN Regulation 155Vehicle manufacturers (type approval, where adopted)Certified cyber security management system for the vehicle lifecycle
UN Regulation 156Vehicle manufacturersSoftware update management system
ISO/SAE 21434Manufacturers and their suppliersThreat analysis and risk assessment for each vehicle item
ISO/IEC 27001 or NIST CSFThe fleet operator's organisationInformation security management system around the cloud platform, operations centre and suppliers
SOCI CIRMP or national equivalentsDesignated critical infrastructure operatorsRisk management programme, incident reporting, board attestation

An operator in Australia or New Zealand may need both halves: supplier evidence from the vehicle side, and its own management system and critical infrastructure programme. For the vehicle-level threats themselves, see driverless cars: cybersecurity risks and controls.

Running it as one programme

Isometric illustration of a fleet operations centre with screens, a supplier network map and a compliance checklist tile linked to a central hub
One control model: a supplier assessment or access review captured once can serve CIRMP, ISO 27001 and the Gulf frameworks.

The practical risk for a fleet operator is running four overlapping programmes with four sets of evidence. GRCLens carries the SOCI CIRMP catalogue, including its eleven prescribed sections and control status under the 2026 Enhanced Rules, alongside AESCSF, ISO/IEC 27001, NIST SP 800-53, NCA ECC and the UAE frameworks on one shared control model. A supplier assessment for foreign influence, an access review for the remote operations centre, or a restore test for the dispatch platform is captured once and linked to every obligation it satisfies.

Reporting clocks, such as the 12-hour and 72-hour SOCI incident windows or New Zealand's proposed 24 and 72 hours, are tracked as indicators, and the supplier register feeds the foreign influence assessments the Enhanced Rules require. GRCLens can run as SaaS, in your own cloud, or fully on-premises where data residency requires it.

Frequently asked questions

Does the SOCI Act apply to robotaxi operators?

It can. Public transport is a SOCI asset class, and freight services and freight infrastructure are too. Whether a particular fleet is captured depends on its designation and scale, so operators should assess this before launch.

Which transport assets must run a CIRMP in Australia?

Under the current rules published by the Cyber and Infrastructure Security Centre, critical freight infrastructure and critical freight services assets. The Enhanced CIRMP Rules that commenced on 10 June 2026 apply to those classes and to energy, water, broadcasting and domain name systems.

Has New Zealand passed its critical infrastructure cyber law?

No. Consultation on the proposed regime closed on 19 April 2026, and no bill had been introduced as at September 2026.

Do vehicle certifications like UN R155 cover the operator?

No. UN R155 and ISO/SAE 21434 cover the vehicle and its supply chain. The operator's cloud, operations centre and suppliers need their own management system, such as ISO/IEC 27001 or NIST CSF, and a critical infrastructure programme where designated.

How Security Solution Consultants can help

Security Solution Consultants helps fleet operators, transport authorities and their suppliers work out which critical infrastructure obligations apply, build the CIRMP or equivalent programme, and assess suppliers for foreign influence and remote access risk. For the board and liability side of automated vehicles, read who is accountable when a driverless car is hacked, or see our enterprise risk management and CIRMP advisory. GRCLens then holds the programme, the evidence and the reporting clocks in one place. Request a demonstration.

This article is general information, not legal advice. Regulations change, so confirm current requirements with the relevant regulator before relying on them. Questions?info@grclens.net.

← All articles