FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Incident Reporting Clock
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Proposed: draft date not recorded.
A vulnerability and incident reporting rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This duty does not yet bind: as of September 2026, C.B. No. 24-14 has been introduced but has not passed the Congress of the Federated States of Micronesia.
- Once enacted, it will reach you only where the Secretary of Justice has designated a computer, computer system, or computer data you own or operate as critical information infrastructure; see this jurisdiction's companion risk-management row for the designation criteria.
- Notify the Secretary of Justice and the CERT-FSM of a significant cybersecurity incident affecting your critical information infrastructure or an interconnected system: an early warning within 24 hours of becoming aware of it, a fuller notification within 72 hours, and a final report within 30 days of that notification.
- Establish mechanisms and processes to promptly detect a cybersecurity threat or incident affecting your critical information infrastructure.
- Expect a fine of up to $10,000 or imprisonment of up to one year or both for failing to report on this clock.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Section 412(4) makes a failure, without reasonable excuse, to comply with the incident-notification duty under section 412(1) an offense, liable on conviction to a fine not exceeding $10,000 or imprisonment for a term not exceeding one year or both. This provision has not yet taken effect; the bill had not passed the Congress of the Federated States of Micronesia as of September 2026.
Who enforces it
Enforcement body
Secretary of Justice, Department of Justice of the Federated States of Micronesia, and the CERT-FSM operated by the Department of Transportation, Communications and Infrastructure (DTCI)
Settledness
C.B. No. 24-14 was introduced on May 17, 2025 and remained listed among the Twenty-Third Congress's pending bills, with no companion Congressional Act number recorded against it, so it had not passed the Congress as of September 2026.
- As of
- 19 September 2026
- Open questions
- Will C.B. No. 24-14 be enacted, and if so, will its section 412 reporting clock be amended before passage?
- How will the Secretary define what makes a cybersecurity incident significant enough to trigger the section 412(1) notification duty for a given owner?
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 412(1) of the same bill, C.B. No. 24-14 (Cybersecurity Act 2025), would require the owner of critical information infrastructure to notify the Secretary of Justice and the CERT-FSM (the national Computer Emergency Response Team the bill would create) of a significant cybersecurity incident affecting its critical information infrastructure or an interconnected system. The owner must submit an early warning within twenty-four hours of becoming aware of the incident.
The owner must then submit a fuller incident notification within seventy-two hours. The owner must submit a final report not later than thirty days after that notification, and, for an ongoing incident, a progress report on the same thirty-day clock. Section 412(3) would separately require the owner to establish mechanisms and processes for promptly detecting a cybersecurity threat or incident affecting its critical information infrastructure.
A failure to comply with the reporting duty is a criminal offense carrying a fine of up to $10,000 or imprisonment of up to one year or both. This duty does not yet bind: C.B. No. 24-14 was introduced in the Congress of the Federated States of Micronesia on May 17, 2025, and had not passed as of September 2026.
When LexLint raises it
operates_essential_service
Read the law
C.B. No. 24-14
Congress of the Federated States of Micronesia, introduced May 17, 2025, as published by the Congress's own website (cfsm.gov.fm) not yet enacted
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.