Cyber Security Act, Computer Emergency Response Team, Duty to Report a Cyber Incident
Cyber Security Act, 2026 (Act No. 81 of 2026), s. 9
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 21 May 2025.
A vulnerability and incident reporting rule binding public and private bodies.
As of 18 September 2026.
What it requires
- This binds a government, private, or autonomous organization or institution in Bangladesh, the Act's own general categories for essentially any actor rather than a licensed or sector-specific status, so an ordinary software distributor or app operator falls within it without needing a critical-infrastructure designation.
- Without delay after a cyber incident occurs, inform the National Computer Emergency Response Team the National Cyber Security Agency maintains; the Act names no fixed number of hours or days for this notification.
Who enforces it
Enforcement body
The National Cyber Security Agency, through the National Computer Emergency Response Team it maintains under section 9(1)
Settledness
No implementing rules under section 49 had been made as of 2026-09-18; the Agency's own responsibilities and functions are also left to rules under section 5(4).
- As of
- 18 September 2026
- Open questions
- Does the duty to inform the National Computer Emergency Response Team without delay under section 9(4) carry a penalty of its own, where no other offence provision in the Act names the same failure?
- Does "without delay" in section 9(4) resolve to a fixed reporting window once the Government makes rules under section 49, and on what clock?
What it reaches
Obligation class
Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Agency maintains a National Computer Emergency Response Team and a National Security Operation Center, and every entity the Government designates as Critical Information Infrastructure must maintain its own Computer Emergency Response Team or Computer Incident Response Team and Security Operation Center.
Any government, private, or autonomous organization or institution that experiences a cyber incident must, without delay, inform the National Computer Emergency Response Team under the Agency. The Act names no fixed number of hours or days for that notification. No provision of the Act states a penalty specific to a failure to give this notification.
The Act's own offences for unauthorized access to a computer system or to Critical Information Infrastructure bind the person, software developer, or artificial intelligence tool user who intrudes, and are recorded on this jurisdiction's scraping row.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official text of the Cyber Security Act, 2026, Bangladesh Laws (bdlaws.minlaw.gov.bd), Bengali original mirrored via the Wayback Machine
no English translation is published on the official site