FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Risk-Management Duties
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Proposed: draft date not recorded.
A sector security regimes rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This duty does not yet bind: as of September 2026, C.B. No. 24-14 has been introduced but has not passed the Congress of the Federated States of Micronesia.
- Once enacted, it will reach you only where the Secretary of Justice has designated a computer, computer system, or computer data you own or operate as critical information infrastructure, which requires that it be necessary for the continuous delivery of a service the Secretary has determined is essential for the economy, national security, public health, public safety, public order, or the continuous provision of basic public services; a smaller owner supplying less than 10% of the market for that essential service, or below a revenue threshold the Secretary sets, may instead receive a special compliance plan and timeline.
- Implement technical, operational, and organizational measures to manage cybersecurity risks to your designated critical information infrastructure, and measures to prevent or mitigate the impact of a cybersecurity incident or threat on it.
- Conduct a cybersecurity risk assessment of that infrastructure at least every two years, and maintain an internal cybersecurity policy, an internal cybersecurity incident-reporting policy, and an internal cybersecurity awareness program.
- Notify the Department of Justice of a change of ownership or control of your designated critical information infrastructure no later than seven days after the change.
- Expect a fine of up to $10,000 or imprisonment of up to one year or both for failing to comply with these duties, and expect the Secretary to be able to compel information about your infrastructure's design, configuration, and security, and to issue binding written directions to you.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Section 408(6) makes a failure, without reasonable excuse, to comply with the owner's cybersecurity duties under section 408 an offense, liable on conviction to a fine not exceeding $10,000 or imprisonment for a term not exceeding one year or both. Section 410(4) sets an identical penalty for failing to comply with a Secretary's written direction, and section 409(5) sets the same penalty for failing to provide information the Secretary compels. Section 411(3) sets a lower penalty, a fine not exceeding $5,000 or imprisonment not exceeding six months or both, for failing to report a change of ownership or control within seven days. None of these provisions has yet taken effect; the bill had not passed the Congress of the Federated States of Micronesia as of September 2026.
Who enforces it
Enforcement body
Secretary of Justice, Department of Justice of the Federated States of Micronesia, in coordination with the Secretary of the Department of Transportation, Communications and Infrastructure (DTCI)
Settledness
C.B. No. 24-14 was introduced on May 17, 2025 and remained listed among the Twenty-Third Congress's pending bills, with no companion Congressional Act number recorded against it, so it had not passed the Congress as of September 2026.
- As of
- 19 September 2026
- Open questions
- Will C.B. No. 24-14 be enacted, and if so, will its Subchapter III risk-management duties be amended before passage?
- What revenue threshold will the Secretary set by regulation for a de minimis owner to qualify for a special compliance plan under section 407(3)?
- Which computers, computer systems, or services will the Secretary designate as critical information infrastructure once the Act's initial twelve-month designation deadline under section 418 applies?
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
C.B. No. 24-14 (Cybersecurity Act 2025), introduced in the Congress of the Federated States of Micronesia, would add a new Chapter 4 to Title 21 whose purpose is to establish a legal framework to prioritize cybersecurity as a means to advance the national policy to strengthen and maintain secure, functioning, and resilient critical information infrastructure in the Federated States of Micronesia.
Section 407 would let the Secretary of Justice designate a computer, computer system, or computer data as critical information infrastructure by written order to its owner. Section 407(1)(a) requires that the computer or computer system be necessary for the continuous delivery of an essential service, and section 407(1)(b) separately requires that its loss or compromise could significantly degrade, impede, disrupt, or otherwise adversely impact delivery of that service.
Section 408(1) would make the owner of critical information infrastructure responsible for implementing technical, operational, and organizational measures to manage cybersecurity risks and to prevent or mitigate the impact of a cybersecurity incident or threat.
Section 408(2)(a) requires a cybersecurity risk assessment of critical information infrastructure at least every two years, alongside an internal cybersecurity policy, an internal incident-reporting policy, and an internal cybersecurity awareness program.
Section 409(1) would let the Secretary require the owner to provide information on the design, configuration, and security of critical infrastructure, and section 410 would let the Secretary issue binding written directions to an owner or a class of owners to manage a cybersecurity threat or risk. Section 411 requires the relevant owner to notify the Department of Justice of a change of ownership or control within seven days.
A failure to comply with the owner's duties under section 408 is a criminal offense carrying a fine of up to $10,000 or imprisonment of up to one year or both, and section 419 would let the Secretary exempt any person or class of persons from all or part of these obligations. This duty does not yet bind: C.B. No. 24-14 was introduced in the Congress of the Federated States of Micronesia on May 17, 2025, and had not passed as of September 2026.
When LexLint raises it
operates_essential_service
Read the law
C.B. No. 24-14
Congress of the Federated States of Micronesia, introduced May 17, 2025, as published by the Congress's own website (cfsm.gov.fm) not yet enacted
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.