Cybersecurity Act 2025, Cybersecurity of Critical Information Infrastructure
Cybersecurity Act 2025, 40 MIRC Ch. 4 §§ 405-406 (P.L. 2025-0027)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 21 April 2025.
A sector security regimes rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This binds the 'owner' of a computer or computer system the Director of the Office of National Security has designated critical information infrastructure under section 405: a natural person, public body, or commercial or non-commercial organization the Director determines operates a service essential for the Republic's national security, economy, foreign relations, public health, public safety, public order, or the continuous provision of basic public services, or, where the critical information infrastructure is government owned, the Secretary of the Ministry that operates it. Designation is case by case, made after consultation, and appealable to the Cabinet; a de minimis owner (one supplying less than ten percent of the market for the essential service) or a low-revenue owner may instead be given a phased compliance plan.
- Implement technical, operational, and organizational measures to manage the cybersecurity risks that may affect your designated critical information infrastructure, and measures to prevent and mitigate the impact of a cybersecurity incident or threat.
- At minimum: conduct rolling cybersecurity risk assessments at a frequency the Chief Information Security Officer prescribes; develop and implement internal cybersecurity policies and procedures, an internal incident-reporting policy, and an internal cybersecurity awareness program; and transmit the resulting mitigation actions to the Director within thirty days of completing each risk assessment.
- Submit to a Director-ordered audit of your critical information infrastructure, at your own cost and no more than once every two years, where the Director has reason to believe you have not complied with the Act or with a technical standard applicable to you, or that information you supplied is false, misleading, or incomplete.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Section 406(9) makes intentionally and without reasonable excuse failing to comply with this section's risk-management obligations a petty misdemeanor. Section 420 separately allows a corporation to be convicted of an offense under this Act under the Criminal Code's corporate-liability provision (section 2.07(1)), and section 422's general non-compliance schedule attaches a fine, and for an individual potential imprisonment, to a violation of any obligation under the Act.
Penalty structure
Section 422's general non-compliance penalty for failing to comply with any obligation this Act imposes: an individual faces a fine not exceeding $10,000, imprisonment not exceeding two years, or both, and a corporation faces a fine not exceeding $100,000, or suspension or revocation of its cybersecurity accreditations where applicable. fixed_cap here records the higher corporate figure. Sections 406(9) and 407(4) separately classify a violation of the risk-management or reporting duty itself as a petty misdemeanor; whether that classification carries a penalty distinct from section 422's schedule, or section 422 supplies the penalty for the offense each section creates, was not resolved in the text located.
- Rule
- Fixed only
- As of
- 19 September 2026
- Currency
- USD
- Fixed cap
- 100,000
Who enforces it
Enforcement body
The Director of National Security (Office of National Security), which also transmits cybersecurity threat and incident information concerning critical information infrastructure to the Attorney General; the CSIRT-MH (Cyber Security Incident Response Team of the Marshall Islands) coordinates the technical response.
Settledness
- As of
- 19 September 2026
- Open questions
- Has the Director of National Security issued the initial critical-information-infrastructure and essential-service designation order that section 419 required within twelve months of the Act's effective date, and if so which computer systems or services does it name?
- Do sections 406(9) and 407(4)'s own petty-misdemeanor classification carry a penalty distinct from section 422's general non-compliance fine schedule, or does section 422 supply the penalty for the offense each section creates?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 406 requires the owner of a computer or computer system the Director of the Office of National Security has designated critical information infrastructure under section 405 to implement technical, operational, and organizational measures to manage the cybersecurity risks that may affect it, and measures to prevent and mitigate the impact of a cybersecurity incident or threat.
At minimum the owner must conduct rolling cybersecurity risk assessments at a frequency the Chief Information Security Officer prescribes and develop internal cybersecurity policies and procedures, an internal incident-reporting policy, and an internal cybersecurity awareness program. No later than thirty days after completing that risk assessment, the owner must transmit a copy of the resulting cybersecurity mitigation actions to the Director.
The Director may also order, at the owner's own cost and no more than once every two years, an audit of the critical information infrastructure where the Director has reason to believe the owner has not complied with the Act. A person who intentionally and without reasonable excuse fails to comply with this section's obligations commits a petty misdemeanor, and a corporation may separately be convicted of an offense under this Act.
When LexLint raises it
operates_essential_service
Read the law
Republic of the Marshall Islands Nitijela legislation portal (rmiparliament.org)
Cybersecurity Act 2025 (P.L. 2025-0027), Title 40 MIRC Chapter 4, accessed through the Internet Archive's Wayback Machine capture of the PDF, since the live rmiparliament.org copy of this PDF serves no extractable text.
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.rmiparliament.org/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0027/2025-0027_1.pdfEvery line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.