Decreto No. 360/2019 and its Reglamento de Seguridad de las TIC (Resolución 128/2019), TIC Security System duty
Decreto No. 360/2019 ‘Sobre la Seguridad de las Tecnologías de la Información y la Comunicación y la Defensa del Ciberespacio Nacional’… (Gaceta Oficial de la República de Cuba, Ordinaria No. 45, GOC-2019-549-O45, 4 de julio de 2019), arts. 10, 12, 17-20, 41, 56, 89, 109; and its implementing Reglamento de Seguridad de las Tecnologías de la Información y la Comunicación, approved by Resolución 128/2019 of the Ministry of Communications (GOC-2019-555-O45), arts. 2, 4-8, 50
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A security baseline statutes rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This duty binds any entity or natural person in Cuba that owns or uses information and communication technologies, government bodies and state enterprises as well as cooperatives, mixed enterprises, nonprofit associative forms and non-state forms of ownership and management (the self-employed, private cooperatives, and, since Decreto-Ley 46/2021, micro, small and medium private enterprises), and it applies to a non-state actor or a natural person even where they have no specialized security staff.
- Design, implement, manage and keep updated a TIC Security System proportionate to the assets it protects and the risks it faces, and adopt a written TIC Security Plan describing the policies, measures and procedures that follow from it.
- If you provide Internet access service, additionally draft internal security-operation procedures, name the person responsible for network security, and adopt technical and organizational measures against malware contamination and network attacks and intrusions.
- If you produce equipment or provide network, program, application or IT services, whether from inside or outside Cuba, implement the requirements that guarantee the secure operation of the equipment and services you supply; obtain a Ministry of Communications operating license before offering TIC security services to a third party, a license reserved to a state entity whose staff reside permanently in the country.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Decreto 360/2019's own sanctions are administrative only (a preventive notice, suspension or cancellation of an authorization or of contracted services, and confiscation of the means used). A separate criminal computer-misuse regime exists under Ley 151/2022's Código Penal, Título IX, but that regime binds an intruder rather than a system operator or manufacturer, and it is recorded under the scraping topic rather than repeated here.
Who enforces it
Enforcement body
The Ministry of Communications (MINCOM), through its Dirección General de Informática and its inspectors, controls compliance with TIC security rules at every level of the Central State Administration and other legal persons, except where it delegates that control to another body; the Ministry of the Interior and the Ministry of the Revolutionary Armed Forces hold parallel authority over their own systems (Decreto 360/2019, arts. 24-29, 107-108).
Settledness
- As of
- 19 September 2026
- Open questions
- Neither Decreto 360/2019 nor its Reglamento (Resolución 128/2019) states an entry-into-force date distinct from their shared 4 July 2019 Gaceta Oficial publication date: does an unread disposition set a different effective date?
- Has the Ministry of Communications or the Oficina de Seguridad para las Redes Informáticas issued MIPYME-specific implementing guidance since Decreto-Ley 46/2021 legalized micro, small and medium private enterprises, a legal category roughly two years newer than the Reglamento's own non-state-sector language?
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Decreto No. 360/2019 sets Cuba's legal framework for the secure use of information and communication technologies (TIC) and binds bodies and organs of the Central State Administration, the Central Bank of Cuba, national entities, People's Power bodies, the state business system and budgeted units, cooperatives, mixed enterprises, nonprofit associative forms, political, social and mass organizations, and natural persons.
Its implementing Reglamento, approved the same day by Resolución 128/2019 of the Ministry of Communications, extends that list by name to non-state forms of ownership and management. Non-state forms of ownership and management and natural persons must comply with the Reglamento to the extent it applies to them even where they have no specialized security personnel.
Every entity that uses TIC must design, implement, manage and keep updated a TIC Security System proportionate to the importance of the assets it protects and the risks it faces, and must adopt a written TIC Security Plan setting out the policies, measures and procedures that follow from it.
An Internet access service provider must additionally draft internal security-operation procedures, name the person responsible for the security of its network, and adopt technical and organizational measures to prevent malware contamination and network attacks and intrusions. The Ministry of Communications licenses any entity that wishes to provide TIC security services to third parties. Only a state entity whose personnel reside permanently in the country may hold that license.
Producers of equipment and providers of network, program, application and IT services, whether domestic or foreign, are responsible for implementing the requirements that guarantee the secure operation of the equipment and services they supply.
Neither Decreto 360/2019 nor its Reglamento sets a specific technical security standard, a pre-market certification gate, a mandatory support period, or a dedicated vulnerability-disclosure channel that a manufacturer must meet, so this regime does not reach the product-security dimension this topic tracks.
A violation draws administrative sanctions, a preventive notice, temporary or partial invalidation or outright cancellation of an administrative authorization the Ministry of Communications granted, temporary or partial suspension or cancellation of computing and communications services contracted with an authorized enterprise, and confiscation of the means used to commit the infraction, rather than a monetary fine.
Neither Decreto 360/2019 nor its Reglamento states an entry-into-force date distinct from their shared Gaceta Oficial publication date of 4 July 2019.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_producthandles_health_recordsprovides_financial_servicesoperates_essential_serviceis_listed_companyprovides_telecom_services
Read the law
Official text of Decreto No. 360/2019 and Resolución 128/2019 as published in Gaceta Oficial de la República de Cuba
Ordinaria No. 45 (4 July 2019)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.