Minimum Risk-Management and Preparedness Requirements for Critical Infrastructure
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 September 2020.
A sector security regimes rule binding public and private bodies.
As of 15 September 2026.
What it requires
- This duty binds an operator of essential services in Iceland's digital-infrastructure sector (an internet exchange point, a domain-name-system service provider, or a top-level domain registry) and a provider of digital services operating an online marketplace, an online search engine, or a cloud computing service, other than a micro-enterprise; it also binds an operator of essential services in banking and financial-market infrastructure, transport, health services, or energy, heating and water utilities, a population this vocabulary does not otherwise express.
- Maintain a documented security policy and risk-management process, assess and re-assess risk on a regular basis, and put in place technical and organisational security measures, including access control, tested regularly against current international best practice.
- Maintain a documented incident-response plan and a business-continuity plan covering incident logging, root-cause analysis, restoration of normal operation, and prevention of recurrence, and operate an active internal-control system consistent with this Act and any sector-specific law.
- A breach of this duty draws an administrative fine of up to ISK 10,000,000, capped at 3 percent of turnover for a legal entity, and, if committed intentionally, imprisonment for up to two years.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Article 26: an intentional breach of Article 7 (risk-management and preparedness), Article 8 (notification of a serious incident or risk) or Article 19 (special confidentiality duty) is punishable by imprisonment for up to two years, unless a heavier penalty applies under other law; attempt and complicity are punishable under the General Penal Code's general part. Where the offence is committed in the operations of a legal entity, the legal entity may instead be fined under Chapter II A of the General Penal Code, No. 19/1940.
Penalty structure
Article 23 sets a base range of ISK 10,000 to ISK 10,000,000 for a breach of Article 7, 8 or 19, further capped at 3 percent of the offender's turnover for the last calendar year where the offender is a legal entity, which binds below the ISK 10,000,000 figure for a smaller entity. A separate daily coercive fine of up to ISK 500,000 per day (Article 22) may be imposed for failing to comply with a supervisory order or a request for information or data under Article 12, running until the entity complies.
- Rule
- Fixed only
- As of
- 15 September 2026
- Minimum
- 10,000
- Currency
- ISK
- Fixed cap
- 10,000,000
Who enforces it
Enforcement body
Fjarskiptastofa (the Icelandic Post and Telecom Administration), which Article 11 designates as the sector supervisory authority for the network and information systems of digital-infrastructure operators (internet exchange points, DNS service providers and top-level domain registries) and, under the article's closing paragraph, for providers of a digital service (online marketplace, online search engine or cloud computing service). Each of the Act's other essential-service sectors has its own sector regulator under the same article.
Settledness
Regulation (EU) 2024/2847 (the Cyber Resilience Act) is tracked by the same government database at the equivalent status: an EU act under review by Iceland, Liechtenstein and Norway for EEA incorporation, with domestic implementation work not begun, and not itself in force in Iceland.
- As of
- 15 September 2026
- Guidance link
- https://gagnagrunnur.ees.is/32022l2555
- Guidance body
- Government of Iceland, Ministry for Foreign Affairs, EEA Agreement Database (EES-gagnagrunnur)
- Open questions
- Iceland's own EEA-incorporation tracker records Directive (EU) 2022/2555 (NIS2) as still under review by Iceland, Liechtenstein and Norway with domestic implementation work not begun, and the anticipated implementing vehicle is an amendment to this same Act rather than a new statute: when that amendment lands, will it preserve the digital-infrastructure and digital-service-provider coverage described here, narrow it, or restructure it entirely around NIS2's own Annex I and Annex II sector lists?
What it reaches
Obligation class
Governance, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 7 requires an operator of essential services or a provider of digital services within the Act's scope to maintain a documented policy and processes to assess, manage and minimise the risk to the security of its network and information systems, including risk from rare events with serious consequences, to set a security policy, perform regular risk assessments, and determine and re-assess security measures, both technical and organisational, on that basis, with access control and regular testing against current international best-practice benchmarks.
It also requires a documented incident-response plan and a business-continuity plan to limit damage from a serious operational disruption, covering incident logging, root-cause analysis, restoration of normal operation, and prevention of recurrence, backed by an active internal-control system. The duty binds an operator of essential services in the digital-infrastructure sector, defined as an internet exchange point, a domain-name-system service provider, or a top-level domain registry.
It also binds a provider of digital services operating an online marketplace, an online search engine, or a cloud computing service, other than a provider that qualifies as a micro-enterprise under the Act on Annual Accounts. The Act's other essential-service sectors, banking and financial-market infrastructure, transport, health services, and energy, heating and water utilities, carry the same duty but are gated by sector and criticality criteria this vocabulary does not express.
When LexLint raises it
operates_social_platform
Read the law
Official consolidated text, Althingi Lagasafn (Icelandic Law Database)