Law / Bangladesh

Cyber Security Act, Computer Emergency Response Team, Duty to Report a Cyber Incident

Cyber Security Act, 2026 (Act No. 81 of 2026), s. 9

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 21 May 2025.

A vulnerability and incident reporting rule binding public and private bodies.

As of 18 September 2026.

What it requires

  • This binds a government, private, or autonomous organization or institution in Bangladesh, the Act's own general categories for essentially any actor rather than a licensed or sector-specific status, so an ordinary software distributor or app operator falls within it without needing a critical-infrastructure designation.
  • Without delay after a cyber incident occurs, inform the National Computer Emergency Response Team the National Cyber Security Agency maintains; the Act names no fixed number of hours or days for this notification.

Who enforces it

Enforcement body

The National Cyber Security Agency, through the National Computer Emergency Response Team it maintains under section 9(1)

Settledness

No implementing rules under section 49 had been made as of 2026-09-18; the Agency's own responsibilities and functions are also left to rules under section 5(4).

As of
18 September 2026
Open questions
  • Does the duty to inform the National Computer Emergency Response Team without delay under section 9(4) carry a penalty of its own, where no other offence provision in the Act names the same failure?
  • Does "without delay" in section 9(4) resolve to a fixed reporting window once the Government makes rules under section 49, and on what clock?

What it reaches

Obligation class

Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Agency maintains a National Computer Emergency Response Team and a National Security Operation Center, and every entity the Government designates as Critical Information Infrastructure must maintain its own Computer Emergency Response Team or Computer Incident Response Team and Security Operation Center.

Any government, private, or autonomous organization or institution that experiences a cyber incident must, without delay, inform the National Computer Emergency Response Team under the Agency. The Act names no fixed number of hours or days for that notification. No provision of the Act states a penalty specific to a failure to give this notification.

The Act's own offences for unauthorized access to a computer system or to Critical Information Infrastructure bind the person, software developer, or artificial intelligence tool user who intrudes, and are recorded on this jurisdiction's scraping row.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official text of the Cyber Security Act, 2026, Bangladesh Laws (bdlaws.minlaw.gov.bd), Bengali original mirrored via the Wayback Machine
no English translation is published on the official site

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 6, 2026. Publisher's page: http://bdlaws.minlaw.gov.bd/act-details-1710.html

Back to the example  ·  Lint your app