Llei 22/2022, Cybersecurity Risk-Management Obligations
Llei 22/2022, del 9 de juny, arts. 12, 13, 17 i 18
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 23 June 2022.
A sector security regimes rule binding public and private bodies.
As of 18 September 2026.
What it requires
- This duty reaches your service where you employ 50 or more people, or your annual turnover or annual balance sheet total exceeds ten million euros, and you fall within an Annex I essential-entity sector (energy, transport, banking, financial-market infrastructure, health, water, digital infrastructure, public administration) or an Annex II important-entity sector, which names providers of online marketplaces, online search engines and social networking services platforms among Andorra's digital service providers.
- Adopt technical and organisational measures proportionate to the cybersecurity risks facing your networks and information systems, covering at minimum a security policy for your critical infrastructure and information systems, a risk-management policy, incident management, business continuity and crisis management, supply-chain security, security in the acquisition, development and maintenance of your systems, testing and audit procedures, and the use of cryptography and encryption.
- Designate an Information Security Delegate, a natural person, a unit or a collegiate body, as the point of contact and technical coordination between your organisation and the competent national authority and the CSIRT-AD, and designate a substitute to assume the role during an absence, vacancy or illness.
- Adopt the security measures the National Security Scheme (Esquema Nacional de Seguretat) sets for your sector, which you may supplement with recognised international standards.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
Article 34.4(a) classifies non-compliance with a regulatory provision or technical security instruction issued under this Law as a minor violation, a warning or a fine of 500 to 15,000 euros, unless it rises to a serious violation. Article 34.3(a) classifies non-compliance with the rest of this Law's obligations, which is where a breach of Articles 12, 13, 17 or 18 falls by default, as a serious violation, 15,001 to 30,000 euros. A breach of Articles 12, 13, 17 or 18 does not reach the very-serious tier (30,001 to 100,000 euros), which Article 34.2 reserves for identification failures, uncorrected supervision-chapter deficiencies, and the incident-handling and notification failures Articles 14 and 15 impose.
- Rule
- Fixed only
- As of
- 18 September 2026
- Minimum
- 500
- Currency
- EUR
- Fixed cap
- 30,000
Who enforces it
Enforcement body
The Agència Nacional de Ciberseguretat del Principat d'Andorra (ANC-AD, Andorra's National Cybersecurity Agency) holds the sanctioning power under Article 30, including over entities supervised by the Autoritat Financera Andorrana (AFA, the Andorran Financial Authority), at AFA's request. AFA is itself the competent national authority, coordinating with ANC-AD, for the banking and financial-market-infrastructure sectors.
Settledness
- As of
- 18 September 2026
- Open questions
- Does the 50-employee or ten-million-euro size threshold under Article 2.1 test a digital service provider on a standalone basis, or does an affiliated or linked enterprise's headcount and turnover count toward it?
- Has the Esquema Nacional de Seguretat that Article 12 requires essential and important entities to apply been adopted in the technical detail Article 6.4(d) contemplates, or does an entity's Article 12 duty currently rest on the Law's own text alone?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Llei 22/2022, del 9 de juny, de mesures per a la seguretat de les xarxes i dels sistemes d'informació (the Law of 9 June 2022 on Measures for the Security of Networks and Information Systems) applies to essential and important entities, defined by its Annex I and Annex II sector lists, that employ 50 or more people or whose annual turnover or annual balance sheet total exceeds ten million euros.
Article 13 requires these entities to adopt technical and organisational measures proportionate to the cybersecurity risks facing the networks and information systems they use to provide their services, in order to achieve a high level of resilience, covering at minimum a security policy for their critical infrastructure and information systems, a risk-management policy, incident management, business continuity and crisis management, supply-chain security, security in the acquisition, development and maintenance of systems, testing and audit procedures, and the use of cryptography and encryption.
Annex II names digital service providers, specifically providers of online marketplaces, online search engines and social networking services platforms, among the important entities this duty reaches, and Annex I separately reaches the banking and financial-market-infrastructure sectors and public administration entities of the Andorran government.
Each essential or important entity must also designate an Information Security Delegate (Delegat de la Seguretat de la Informació, DSI), a natural person, a unit or a collegiate body, as the point of contact and technical coordination between the entity and the competent national authority and CSIRT-AD.
When LexLint raises it
operates_social_platform