Systems of National Significance (SoNS)
A privately declared subset of critical infrastructure assets. SoNS can attract Enhanced Cyber Security Obligations on top of the ordinary SOCI duties.
Under the Security of Critical Infrastructure Act 2018, the Minister for Home Affairs can declare a critical infrastructure asset to be a System of National Significance (SoNS). Home Affairs and ministerial material describe SoNS as the assets whose disruption would have catastrophic cascading consequences across sectors. Declarations are made privately under section 52B; the list is not published, precisely so adversaries cannot use it as a targeting menu.
Being a critical infrastructure asset is not the same as being a SoNS. Ordinary positive security obligations (register, CIRMP / Part 2A where applied, Part 2B cyber incident clocks) can apply to designated classes without a SoNS declaration. SoNS sits above that: it is the tier where Enhanced Cyber Security Obligations (ECSO) may be switched on for that asset.
ECSO are four separate powers, applied asset by asset, not a single package you assume. They cover: develop, update and comply with a cyber security incident response plan; undertake cyber security exercises; undertake vulnerability assessments; and provide system information to ASD so ASD can build a near real-time threat picture. A Minister / Home Affairs announcement in 2025–26 noted more than 200 SoNS across energy, communications, transport, financial services and markets, food and grocery, and data storage or processing — still without publishing the list.
Do not confuse the desks. CIRMP is Part 2A risk management for responsible entities of covered assets. The SOCI cyber incident clock is Part 2B (12-hour / 72-hour). Ransomware payment reporting is Cyber Security Act 2024 Part 3. SoNS / ECSO is the enhanced overlay for the assets the Minister has declared. If you are not told you are a SoNS responsible entity, do not invent the duty — and if you are, treat each ECSO notice as its own work order with an owner and a date.
Practical desk: ask counsel whether any asset you operate has a s 52B declaration and which ECSO notices have been issued. Keep IR plans, exercise records, vulnerability-assessment reports, and ASD system-information feeds in one controlled folder. The public SoNS count is a policy signal; your obligation letter is the control.
See also:
Fact source: Minister for Home Affairs, Protecting Australia's critical infrastructure (SoNS / ECSO).
