Law / Cuba

Resolución 105/2021, Reglamento sobre el Modelo de Actuación Nacional para la Respuesta a Incidentes de Ciberseguridad

Resolución 105/2021 of the Ministry of Communications ‘Reglamento sobre el Modelo de Actuación Nacional para la Respuesta a Incidentes de Ciberseguridad’ (Gaceta Oficial de la República de Cuba, Ordinaria No. 92, GOC-2021-762-O92, 17 de agosto de 2021), arts. 1, 2, 21-23 and resolving clause SEGUNDO

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

A vulnerability and incident reporting rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This duty binds any natural or legal person in Cuba responsible for information infrastructure, including a government body, a state enterprise, a cooperative, a mixed enterprise or other foreign-investment vehicle, a nonprofit associative form, and the holder of any data network, public or private, in the National Cyberspace.
  • Report a cybersecurity incident immediately to your immediate superior and to the Cuban Computer Incident Response Team (CuCERT), inside the Ministry of Communications' Oficina de Seguridad para las Redes Informáticas (OSRI), using the incident-report form the Reglamento's Annex III sets out.
  • If you hold a private data network, ensure that a cybersecurity event or incident affecting it is recorded, classified and reported to CuCERT.
  • If you are a natural person, or you hold a private network as a natural person, report a cybersecurity incident through the channel the Ministry of Communications publishes on its own website.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Resolución 105/2021 itself sets a reporting and classification duty with no monetary or criminal penalty of its own for failing to report. The administrative sanctions available under Decreto 360/2019, art. 109, are the enforcement mechanism this reporting duty shares with the baseline TIC Security System duty recorded elsewhere in this jurisdiction's filing.

Who enforces it

Enforcement body

The Cuban Computer Incident Response Team (CuCERT), housed within the Ministry of Communications' Oficina de Seguridad para las Redes Informáticas (OSRI), receives and classifies incident reports until a dedicated Cybersecurity entity staffed jointly with the Ministries of the Revolutionary Armed Forces and of the Interior is created (Resolución 105/2021, arts. 22-23, disposición especial TERCERA).

Settledness

As of
19 September 2026
Open questions
  • Resolución 105/2021 assigns incident intake to CuCERT ‘hasta tanto se cree la entidad especializada de Ciberseguridad’ (English: until the specialized Cybersecurity entity is created): has that entity since been created, and if so, does a newer instrument reassign this duty?
  • The Reglamento's Annex III incident-report form asks for the reporting entity's own details but names no maximum reporting-time window in the text read: does a separate, unread instrument set a reporting clock?

What it reaches

Obligation class

Security, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Resolución 105/2021 of the Ministry of Communications approves a Reglamento establishing the National Action Model for responding to cybersecurity incidents within the National Cyberspace, to guarantee an effective response for its protection.

The Reglamento applies to natural and legal persons, naming government bodies, diplomatic missions and Cuba's own commercial and cooperation representations abroad, the state business system, cooperatives, mixed enterprises and other foreign-investment forms, nonprofit associative forms, and the holders of data networks in the National Cyberspace.

A person directly responsible for the computing infrastructure where a cybersecurity incident occurs must report it to their immediate superior and to the Cuban Computer Incident Response Team (CuCERT), housed in the Ministry of Communications' Oficina de Seguridad para las Redes Informáticas (OSRI).

The holder of a private data network is separately responsible for ensuring that a cybersecurity event or incident affecting that network is recorded and classified, and for delivering the information that reporting to CuCERT requires. The holder of a private network belonging to a natural person, and a natural person individually, must also report a cybersecurity incident through the channel the Ministry of Communications publishes on its own website.

CuCERT receives and forwards incident information until a dedicated Cybersecurity entity, to be staffed jointly by the Ministries of Communications, of the Revolutionary Armed Forces and of the Interior, is created to take over that function.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product
  • handles_health_records
  • provides_financial_services
  • operates_essential_service
  • is_listed_company
  • provides_telecom_services

Read the law

Official text of Resolución 105/2021 as published in Gaceta Oficial de la República de Cuba, Ordinaria No. 92 (17 August 2021)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app