Law on Cyber Security, Cyber-Attack Notification Duty for Other Legal Persons
Law of Mongolia on Cyber Security, adopted 17 December 2021, in force 1 May 2022, Art. 17.3
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 May 2022.
A vulnerability and incident reporting rule binding private bodies.
As of 15 September 2026.
What it requires
- This binds every legal person other than one providing information technology processing, storage, distribution, computer-analytics or shared-information-system hosting services under Article 17.1, a narrower duty-bearer this profile records in the jurisdiction summary rather than flags on a declared activity; Article 3.2 extends this duty to a foreign or foreign-invested legal person operating through Mongolia's information systems and networks.
- Abide by the Government's common procedure for ensuring, preventing, detecting and countering cyber-attacks once the Government adopts it under Article 7.1.
- On a cyber-attack or violation against your systems, notify the relevant center against cyber-attacks and violations, the Public center for a legal person outside the state information network and outside critical information infrastructure, and obtain assistance where necessary; the text states no numeric clock for this notice.
- Comply with the recommendations and requirements the relevant authorities issue to you in relation to ensuring cyber security.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Article 24.2 makes a violator, individual or legal person, liable under the Criminal Law or the Law on Violations; this Law's own text states neither a specific offense nor a maximum penalty for the Article 17.3 duty, and the Criminal Law and the Law on Violations are not described here to identify one. Mongolia's Criminal Code computer-crime provisions (Chapter 25/26) are already this jurisdiction's scraping row rather than restated here.
Who enforces it
Enforcement body
The Public center against cyber-attacks and violations, operating under the state central administrative organization in charge of digital development and communications, receives the Article 17.3 notification for a legal person outside the state information network and critical infrastructure (Arts. 22.1, 22.2.1); liability for a violation runs through the authorities administering the Criminal Law and the Law on Violations under Article 24.2.
Settledness
- As of
- 15 September 2026
- Open questions
- Has the Government adopted the common procedure Article 7.1 requires for ensuring, preventing, detecting and responding to cyber-attacks, and if not, does the Article 17.3.1 duty to abide by it have any operative content yet?
What it reaches
Obligation class
Security, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 17.3 binds every legal person in Mongolia other than one providing information technology processing, storage, distribution, computer-analytics or shared-information-system hosting services under Article 17.1, a narrower duty-bearer this jurisdiction's summary records rather than flags here.
That legal person must abide by the Government's common procedure for ensuring cyber security once adopted, notify the relevant center against cyber-attacks and violations of a cyber-attack or violation against it and obtain assistance where necessary, and comply with the recommendations and requirements the relevant authorities issue.
The Law extends this duty, like the rest of the Law, to a foreign or foreign-invested legal person operating through Mongolia's information systems and networks unless the Law states otherwise. The Public center, which receives this notification for a legal person outside the state information network and critical infrastructure, operates under the state central administrative organization in charge of digital development and communications.
The text sets no numeric clock for this notice, unlike the immediate-notification duty Articles 16.1.3, 17.1.2 and 19.2.14 place on a state-owned legal person, an information-technology-service legal person, and a critical-information-infrastructure operator. A violator faces liability under the Criminal Law or the Law on Violations, on Article 24.2's own cross-reference; the Law's own text names neither statute's specific offense or maximum penalty.
When LexLint raises it
automated_outreachcrawls_webdeploys_chatbotdistributes_software_producthigh_risk_decisionsoperates_social_platformprocesses_biometricsprocesses_voiceserves_minorsships_mobile_apptrains_models