Law / Mongolia

Law on Cyber Security, Cyber-Attack Notification Duty for Other Legal Persons

Law of Mongolia on Cyber Security, adopted 17 December 2021, in force 1 May 2022, Art. 17.3

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 May 2022.

A vulnerability and incident reporting rule binding private bodies.

As of 15 September 2026.

What it requires

  • This binds every legal person other than one providing information technology processing, storage, distribution, computer-analytics or shared-information-system hosting services under Article 17.1, a narrower duty-bearer this profile records in the jurisdiction summary rather than flags on a declared activity; Article 3.2 extends this duty to a foreign or foreign-invested legal person operating through Mongolia's information systems and networks.
  • Abide by the Government's common procedure for ensuring, preventing, detecting and countering cyber-attacks once the Government adopts it under Article 7.1.
  • On a cyber-attack or violation against your systems, notify the relevant center against cyber-attacks and violations, the Public center for a legal person outside the state information network and outside critical information infrastructure, and obtain assistance where necessary; the text states no numeric clock for this notice.
  • Comply with the recommendations and requirements the relevant authorities issue to you in relation to ensuring cyber security.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Article 24.2 makes a violator, individual or legal person, liable under the Criminal Law or the Law on Violations; this Law's own text states neither a specific offense nor a maximum penalty for the Article 17.3 duty, and the Criminal Law and the Law on Violations are not described here to identify one. Mongolia's Criminal Code computer-crime provisions (Chapter 25/26) are already this jurisdiction's scraping row rather than restated here.

Who enforces it

Enforcement body

The Public center against cyber-attacks and violations, operating under the state central administrative organization in charge of digital development and communications, receives the Article 17.3 notification for a legal person outside the state information network and critical infrastructure (Arts. 22.1, 22.2.1); liability for a violation runs through the authorities administering the Criminal Law and the Law on Violations under Article 24.2.

Settledness

As of
15 September 2026
Open questions
Has the Government adopted the common procedure Article 7.1 requires for ensuring, preventing, detecting and responding to cyber-attacks, and if not, does the Article 17.3.1 duty to abide by it have any operative content yet?

What it reaches

Obligation class

Security, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 17.3 binds every legal person in Mongolia other than one providing information technology processing, storage, distribution, computer-analytics or shared-information-system hosting services under Article 17.1, a narrower duty-bearer this jurisdiction's summary records rather than flags here.

That legal person must abide by the Government's common procedure for ensuring cyber security once adopted, notify the relevant center against cyber-attacks and violations of a cyber-attack or violation against it and obtain assistance where necessary, and comply with the recommendations and requirements the relevant authorities issue.

The Law extends this duty, like the rest of the Law, to a foreign or foreign-invested legal person operating through Mongolia's information systems and networks unless the Law states otherwise. The Public center, which receives this notification for a legal person outside the state information network and critical infrastructure, operates under the state central administrative organization in charge of digital development and communications.

The text sets no numeric clock for this notice, unlike the immediate-notification duty Articles 16.1.3, 17.1.2 and 19.2.14 place on a state-owned legal person, an information-technology-service legal person, and a critical-information-infrastructure operator. A violator faces liability under the Criminal Law or the Law on Violations, on Article 24.2's own cross-reference; the Law's own text names neither statute's specific offense or maximum penalty.

When LexLint raises it

  • automated_outreach
  • crawls_web
  • deploys_chatbot
  • distributes_software_product
  • high_risk_decisions
  • operates_social_platform
  • processes_biometrics
  • processes_voice
  • serves_minors
  • ships_mobile_app
  • trains_models

Read the law

Unofficial English translation, legalinfo.mn (Mongolia's national legal-information portal, operated by the Legal Institute)

Back to the example  ·  Lint your app