Who must comply with SoNS — Systems of National Significance (SOCI)?
The applicability test for SoNS — Systems of National Significance (SOCI) (Home Affairs (SOCI)), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Only if
Applies when the business has a critical infrastructure asset.
What the obligation is
Declared SoNS face enhanced cyber security obligations.
Under s 52B of the Security of Critical Infrastructure Act 2018 the Minister for Home Affairs may declare a critical infrastructure asset to be a System of National Significance (SoNS), having regard to the consequences a significant hazard would have for Australia's social or economic stability, defence or national security, and to its interdependencies with other assets. SoNS are a very small subset of the 22 asset classes across 11 critical infrastructure sectors. Responsible entities for a SoNS may then be subject to four Enhanced Cyber Security Obligations in Part 2C, applied case by case by the Secretary of Home Affairs after considering cost, reasonableness and proportionality: a statutory incident response plan, cyber security exercises, vulnerability assessments, and system information reporting to the Australian Signals Directorate. These sit on top of the general SOCI obligations.
The applicability test
Applies when the business has a critical infrastructure asset.
How the regulator frames it: The responsible entity for an asset the Minister has declared a System of National Significance, and only for those Enhanced Cyber Security Obligations the Secretary has applied by written notice. Other critical infrastructure owners and operators are outside Part 2C.
What triggers it: A ministerial declaration under s 52B (the Minister must notify the responsible entity within 30 days), followed by a written notice or determination from the Secretary applying a specific obligation. The Secretary must consult the entity, and any relevant Commonwealth regulator, before applying the incident response planning obligation.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (35 of 35: no).
The answer is the same in every industry: no. Industry does not change who must comply.
Business structure and size
Structure does not change the answer across all industries: for every structure the answer is "no".
Size does not change the answer across all industries: at every size band the answer is "no".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires a critical infrastructure asset.
Answers that bring it into scope
Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:
- The business operates a critical infrastructure asset: it then applies (operates a critical infrastructure asset (SOCI Act)).
What you must do, and when
- When due
- Incident response planning applies from the time stated in the Secretary's determination, at least 30 days after notice; exercises and vulnerability assessments within the period in the notice (at least 30 days for exercises); an internal evaluation report to the Secretary within 30 days after completing an exercise; system information reports at the intervals the notice specifies.
- Frequency
- Ongoing
- Evidence to keep
- Adopted and maintained written incident response plan for cyber security incidents affecting the system; cyber security exercise records and the internal (and any external) evaluation report given to the Secretary; vulnerability assessment reports; periodic system information reports; copies of the s 52B declaration and each Secretary notice, lodged through the department's secure SoNS portal.
- Status
- Current
- Priority
- Critical
Penalty for not complying
Maximum penalty: Civil penalty of 200 penalty units ($72,800) for each Part 2C failure, including not adopting and maintaining an incident response plan (s 30CD), not complying with a notice to undertake a cyber security exercise (s 30CP) and not giving the Secretary the evaluation report within 30 days (s 30CQ).
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
Obligations with the same applicability test
If this obligation applies to you, so do these 5: the engine uses the same rule for each.
Where it sits in the corpus
Rules Mate tracks 3 published obligations tagged "cyber security", 2 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated critical priority, and is an ongoing duty.
Regulator, legislation and tools
Regulated by Cyber and Infrastructure Security Centre — Department of Home Affairs.
Home Affairs (SOCI): Administers the Security of Critical Infrastructure Act 2018 — registration, risk management programs, and mandatory cyber incident reporting for critical infrastructure assets.
SOCI Act: Federal critical infrastructure protection regime.
Free tools that help with this obligation:
Questions
- Who must comply with SoNS — Systems of National Significance (SOCI)?
- Applies when the business has a critical infrastructure asset.
- Does SoNS — Systems of National Significance (SOCI) apply to sole traders?
- No. Across every industry and every size band, the engine's answer for a sole trader is: no.
- Does SoNS — Systems of National Significance (SOCI) apply to businesses with 1–5 employees?
- No (1–5 employees, turnover $100K–$1M).
- When is "SoNS — Systems of National Significance (SOCI)" due?
- Incident response planning applies from the time stated in the Secretary's determination, at least 30 days after notice; exercises and vulnerability assessments within the period in the notice (at least 30 days for exercises); an internal evaluation report to the Secretary within 30 days after completing an exercise; system information reports at the intervals the notice specifies.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.