Cybersecurity Act 2025, Cybersecurity Incident Reporting Obligations
Cybersecurity Act 2025, 40 MIRC Ch. 4 § 407 (P.L. 2025-0027)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 21 April 2025.
A vulnerability and incident reporting rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Binds the same designated owner of critical information infrastructure as the risk-management duty above (sections 405 and 406).
- Immediately notify the Director and the CSIRT-MH (the Cyber Security Incident Response Team of the Marshall Islands) of a significant cybersecurity incident affecting your critical information infrastructure, of a significant incident on any interconnected computer system under your control, or of any other incident type the Director specifies by written order.
- Submit an early warning within twenty-four hours of becoming aware of the incident, a fuller notification with an initial severity and impact assessment within seventy-two hours, and a final report within thirty days of that notification, or, for an ongoing incident, a thirty-day progress report followed by a final report within thirty days of the incident's resolution.
- Establish mechanisms and processes to promptly detect a cybersecurity threat, vulnerability, or incident affecting your critical information infrastructure.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Section 407(4) makes intentionally and without reasonable excuse failing to make a required notification a petty misdemeanor. Section 420 separately allows a corporation to be convicted of an offense under this Act under the Criminal Code's corporate-liability provision (section 2.07(1)), and section 422's general non-compliance schedule attaches a fine, and for an individual potential imprisonment, to a violation of any obligation under the Act.
Penalty structure
Section 422's general non-compliance penalty for failing to comply with any obligation this Act imposes: an individual faces a fine not exceeding $10,000, imprisonment not exceeding two years, or both, and a corporation faces a fine not exceeding $100,000, or suspension or revocation of its cybersecurity accreditations where applicable. fixed_cap here records the higher corporate figure. Sections 406(9) and 407(4) separately classify a violation of the risk-management or reporting duty itself as a petty misdemeanor; whether that classification carries a penalty distinct from section 422's schedule, or section 422 supplies the penalty for the offense each section creates, was not resolved in the text located.
- Rule
- Fixed only
- As of
- 19 September 2026
- Currency
- USD
- Fixed cap
- 100,000
Who enforces it
Enforcement body
The Director of National Security (Office of National Security) and the CSIRT-MH (Cyber Security Incident Response Team of the Marshall Islands), which the Director establishes and which receives and coordinates the response to a reported incident.
Settledness
- As of
- 19 September 2026
- Open questions
- Has the Director of National Security issued the initial critical-information-infrastructure designation order required by section 419, so that any owner is yet bound to file the twenty-four-hour early warning or seventy-two-hour notification section 407 requires?
- Do sections 406(9) and 407(4)'s own petty-misdemeanor classification carry a penalty distinct from section 422's general non-compliance fine schedule, or does section 422 supply the penalty for the offense each section creates?
What it reaches
Obligation class
Security, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 407 requires the same designated owner of critical information infrastructure to immediately notify the Director of the Office of National Security and the CSIRT-MH of a significant cybersecurity incident affecting the critical information infrastructure, of a significant incident on any interconnected computer system under the owner's control, or of any other incident type the Director specifies by written order.
To comply, the owner must submit an early warning within twenty-four hours of becoming aware of the incident, a fuller notification with an initial severity and impact assessment within seventy-two hours, and a final report within thirty days of that notification, or, for an ongoing incident, a thirty-day progress report followed by a final report within thirty days of the incident's resolution.
The owner must also establish mechanisms and processes to promptly detect a cybersecurity threat, vulnerability, or incident affecting the critical information infrastructure. A person who intentionally and without reasonable excuse fails to make a notification under this section commits a petty misdemeanor.
When LexLint raises it
operates_essential_service
Read the law
Republic of the Marshall Islands Nitijela legislation portal (rmiparliament.org)
Cybersecurity Act 2025 (P.L. 2025-0027), Title 40 MIRC Chapter 4, accessed through the Internet Archive's Wayback Machine capture of the PDF, since the live rmiparliament.org copy of this PDF serves no extractable text.
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.rmiparliament.org/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0027/2025-0027_1.pdfEvery line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.