Law / Cybersecurity

Cybersecurity law, instrument by instrument

Every cybersecurity law instrument LexLint holds, grouped by the place that made it. Choose which stages of law to show: the map, the counts and the tables all answer to that choice. To see every area of law, follow Law in the breadcrumb above.

Where cybersecurity law applies, at the stages chosen below. A darker fill means more instruments at those stages. Point at, click, or tab to a place for the cybersecurity law that applies there.
  • 1
  • 5
  • 10
  • 20+
  • instruments shown
  • law on file, none at these stages
  • tracked, no law on file
  • not tracked
The United States is drawn as its states; its federal instruments are a row group in Countries below.

Stages of law

Stages of law to show

166 instruments in 98 places.

No commencement date on file for 15.

Unions4 in 1 place

Law made above the state, binding its members.

Stage Instrument In force from
European Union eu 4 instruments
Cyber Resilience Act, Essential Requirements and Manufacturer ObligationsRegulation (EU) 2024/2847, Art. 13 and Annex I 2027-12-11[future]
Cyber Resilience Act, Manufacturer Reporting ObligationsRegulation (EU) 2024/2847, Art. 14 2026-09-11
NIS2 Directive, Cybersecurity Risk-Management MeasuresDirective (EU) 2022/2555, Art. 21 2024-10-18
NIS2 Directive, Reporting ObligationsDirective (EU) 2022/2555, Art. 23 2024-10-18

Countries121 in 65 places

One row group per country, alphabetically.

Stage Instrument In force from
Albania al 1 instrument
Law No. 25/2024, On CybersecurityLaw No. 25/2024 (Ligj Nr. 25/2024), 21 March 2024, "Për sigurinë kibernetike" ("On Cybersecurity"), Fletorja Zyrtare No. 67/2024, p. 7767 2024-05-03
Andorra ad 2 instruments
Llei 22/2022, Cybersecurity Risk-Management ObligationsLlei 22/2022, del 9 de juny, arts. 12, 13, 17 i 18 2022-06-23
Llei 22/2022, Incident Handling and Notification ObligationLlei 22/2022, del 9 de juny, arts. 14 i 15 2022-06-23
Angola ao 2 instruments
Lei de Protecção das Redes e Sistemas Informáticos, Incident-Management Planning, Alert Dissemination and CERT Coordination DutiesLei n.º 7/17, Artigos 15.º, 16.º, 40.º e 41.º not recorded
Lei de Protecção das Redes e Sistemas Informáticos, Security Duties for Information-Society Systems, Computer Programs and DatabasesLei n.º 7/17, Artigos 12.º, 13.º, 14.º, 17.º, 18.º e 19.º not recorded
Australia au 1 instrument
Security Standards for Smart DevicesCyber Security Act 2024 (Cth), No. 98, 2024, Part 2, ss. 13-24; Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276), Schedule 1 2026-03-04
Austria at 4 instruments
Netz- und Informationssystemsicherheitsgesetz (NISG), Incident Notification ObligationsNISG, BGBl. I Nr. 111/2018, §§ 19 und 21 2018-12-28
Netz- und Informationssystemsicherheitsgesetz (NISG), Security Measures for Operators of Essential Services and Digital Service ProvidersNISG, BGBl. I Nr. 111/2018, §§ 17 und 21 2018-12-28
Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management MeasuresNISG 2026, BGBl. I Nr. 94/2025, §§ 24, 25, 28 und 32 2026-10-01[future]
Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting ObligationsNISG 2026, BGBl. I Nr. 94/2025, §§ 34 und 35 2026-10-01[future]
Bangladesh bd 1 instrument
Cyber Security Act, Computer Emergency Response Team, Duty to Report a Cyber IncidentCyber Security Act, 2026 (Act No. 81 of 2026), s. 9 2025-05-21
Belgium be 2 instruments
Loi du 26 avril 2024, Cybersecurity Risk-Management Measures and GovernanceLoi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la sécurité publique, Artt. 30-33 2024-10-18
Loi du 26 avril 2024, Significant-Incident Notification ObligationsLoi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la sécurité publique, Artt. 34-37 2024-10-18
Benin bj 1 instrument
Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre VI (cybersécurité), sécurité des réseaux et essai de vulnérabilité des produitsLoi n°2017-20 du 20 avril 2018, Livre VI, Titre I, Chapitre XIII, Article 598, portant Code du Numérique en République du Bénin 2018-04-20
Brazil br 1 instrument
Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment)Ato nº 2.436, de 7 de março de 2023 (Superintendência de Outorga e Recursos à Prestação, Agência Nacional de Telecomunicações), as amended by Ato nº 7.344, de 15 de junho de 2023; issued under the Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações, approved by Resolução nº 740, de 21 de dezembro de 2020, and the Regulamento de Avaliação da Conformidade e de Homologação de Produtos para Telecomunicações, approved by Resolução nº 715, de 23 de outubro de 2019 2024-03-10
Bulgaria bg 2 instruments
Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS)Закон за киберсигурност (ЗКС), чл. 23, изм. с § 27 от Закона за изменение и допълнение на ЗКС, обн. ДВ, бр. 17 от 13.02.2026 г. (English: Cybersecurity Act, Art. 23, as substituted by § 27 of the Act Amending and Supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026) 2026-02-17
Cybersecurity Act, Risk-Management Measures and Governance (Zakon za kibersigurnost, ZKS)Закон за киберсигурност (ЗКС), чл. 21 и 22, изм. с §§ 25 и 26 от Закона за изменение и допълнение на ЗКС, обн. ДВ, бр. 17 от 13.02.2026 г. (English: Cybersecurity Act, Arts. 21 and 22, as substituted by §§ 25 and 26 of the Act Amending and Supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026) 2026-02-17
Cameroon cm 1 instrument
Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, articles 6, 7, 13-14, 24, 26-30, 32, 61(3) (mesures de sécurité et audit de sécurité obligatoire par l'ANTIC)Loi n°2010/012 du 21 décembre 2010, art. 6-7, 13-14, 24, 26-30, 32, 61(3) 2010-12-21
China cn 3 instruments
Cybersecurity Law, Network Product and Service Security DutiesCybersecurity Law of the People's Republic of China (as amended by the Decision of October 28, 2025, effective January 1, 2026), Art. 24 2026-01-01
Data Security Law, Data Security Protection ObligationsData Security Law of the People's Republic of China, Art. 27 2021-09-01
Data Security Law, Risk Monitoring and Incident Reporting DutyData Security Law of the People's Republic of China, Art. 29 2021-09-01
Croatia hr 2 instruments
Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting ObligationsZakon o kibernetičkoj sigurnosti, Narodne novine, broj 14/2024, čl. 37.-44.; Uredba o kibernetičkoj sigurnosti, Narodne novine, broj 135/2024, čl. 64.-71. i 85. 2024-11-30
Zakon o kibernetičkoj sigurnosti, Risk-Management Measures and GovernanceZakon o kibernetičkoj sigurnosti, Narodne novine, broj 14/2024, čl. 29. i 30. 2024-02-15
Cyprus cy 3 instruments
Security of Networks and Information Systems Law, Cybersecurity Risk-Management Measures and GovernanceArts. 35 and 35A of the Security of Networks and Information Systems Law of 2020, N. 89(I)/2020, as amended by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025 2025-04-25
Security of Networks and Information Systems Law, Incident Notification ObligationsArt. 35B of the Security of Networks and Information Systems Law of 2020, N. 89(I)/2020, as amended by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025 2025-04-25
Security of Networks and Information Systems Law, Radio Equipment Cybersecurity RequirementsArt. 42A of the Security of Networks and Information Systems Law of 2020, N. 89(I)/2020, as inserted by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025 2025-04-25
Czech Republic cz 2 instruments
Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident NotificationAct No. 264/2025 Coll., Cybersecurity Act, Sections 15-16 2025-11-01
Cybersecurity Act (Zákon o kybernetické bezpečnosti), Risk-Management Security MeasuresAct No. 264/2025 Coll., Cybersecurity Act, Sections 13-14 2025-11-01
Côte d'Ivoire ci 3 instruments
Mandatory Information Systems Security Audit and CertificationDécret n°2021-917 du 22 décembre 2021, Arts. 3-4, 19-21 2021-12-22
Mandatory Reporting of Attacks and Intrusions to ARTCIDécret n°2021-917 du 22 décembre 2021, Arts. 16-17 2021-12-22
RGSSI and PPIC Compliance DutyDécret n°2021-916 du 22 décembre 2021, Arts. 1-2 2021-12-22
Denmark dk 2 instruments
NIS 2-loven, Cybersecurity Risk-Management Measures and RegistrationNIS 2-loven, §§ 6-10 2025-07-01
NIS 2-loven, Significant-Incident Reporting and Recipient-Notice DutiesNIS 2-loven, §§ 12-13, 15 2025-07-01
Egypt eg 1 instrument
Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, System-Security Duty on a System ManagerLaw No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, Arts. 29, 42, 44 2018-08-15
Estonia ee 2 instruments
Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber IncidentKüberturvalisuse seadus (Cybersecurity Act), RT I, 30.12.2025, 4, §§ 8 and 8-1 2026-01-01
Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body DutiesKüberturvalisuse seadus (Cybersecurity Act), RT I, 30.12.2025, 4, §§ 6-1 and 7 2026-01-01
Finland fi 3 instruments
Kyberkestävyyslaki, National Enforcement and Market Surveillance for the Cyber Resilience ActLaki eräiden tuotteiden kyberkestävyydestä sekä kyberturvallisuussertifioinnista (439/2026), 1, 7-9, 15-16 ja 31-38 § 2026-06-01
Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and GovernanceKyberturvallisuuslaki (124/2025), 3 ja 7-10 § 2025-04-08
Kyberturvallisuuslaki, Significant-Incident Reporting ObligationsKyberturvallisuuslaki (124/2025), 11-14 ja 22 § 2025-04-08
France fr 3 instruments
Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Incident NotificationLoi n° 2018-133 du 26 février 2018, Titre Ier, art. 7 et 13 2018-05-10
Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security RequirementsLoi n° 2018-133 du 26 février 2018, Titre Ier, Chapitres II et III, art. 5, 6, 10, 11 et 12 2018-05-10
Loi n° 2022-309 du 3 mars 2022 (loi Cyberscore), Cybersecurity Audit and Disclosure DutyLoi n° 2022-309 du 3 mars 2022, art. 1 (Code de la consommation, art. L. 111-7-3) 2023-10-01
Gabon ga 1 instrument
Sécurité des systèmes d'information (dispositions communes)Loi N° 027/2023 du 11 juillet 2023, Titre III, Chapitre III, Section 2, arts. 28-35 2023-07-15
Germany de 2 instruments
BSI-Gesetz (BSIG), Incident NotificationBSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), § 32 2025-12-06
BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important EntitiesBSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), §§ 28, 30, 38 2025-12-06
Ghana gh 3 instruments
Cybersecurity Act, Cybersecurity Standards and EnforcementCybersecurity Act, 2020 (Act 1038), s. 59, and Second Schedule item 59(4) 2020-12-29
Cybersecurity Act, Duty to Report Cybersecurity IncidentCybersecurity Act, 2020 (Act 1038), ss. 47(2) and 47(5)-(6), and Second Schedule item 47(6) 2020-12-29
Cybersecurity Act, Licensing of Cybersecurity Service ProvidersCybersecurity Act, 2020 (Act 1038), ss. 49-53, First Schedule, and Second Schedule items 49(2) and 51(5) 2020-12-29
Greece gr 2 instruments
Law 5160/2024, Cybersecurity Risk-Management Measures and GovernanceLaw 5160/2024 (Ν. 5160/2024), Arts. 14-15 2024-11-27
Law 5160/2024, Significant-Incident Reporting ObligationsLaw 5160/2024 (Ν. 5160/2024), Art. 16 2024-11-27
Hungary hu 2 instruments
Cybersecurity Act, Incident Notification and Cybersecurity Fine2024. évi LXIX. törvény, 66. §; 418/2024. (XII. 23.) Korm. rendelet, 42. § és 77. § 2025-01-01
Cybersecurity Act, Risk-Management Measures2024. évi LXIX. törvény (Magyarország kiberbiztonságáról), 6. § 2025-01-01
Iceland is 2 instruments
Minimum Risk-Management and Preparedness Requirements for Critical InfrastructureLog nr. 78/2019, Art. 7 2020-09-01
Notification of Serious Incidents and Risk to the National Cybersecurity Incident-Response TeamLog nr. 78/2019, Art. 8 2020-09-01
India in 2 instruments
CERT-In Cyber Security Directions, Incident Reporting, Logging and Time SynchronisationDirections under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022) 2022-06-27
Information Technology Act, Compensation for Failure to Protect Data, and Sensitive Personal Data or Information Rules, Reasonable Security PracticesInformation Technology Act, 2000 (No. 21 of 2000), s.43A; Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (G.S.R. 313(E), 11 April 2011), rr. 3, 4, 5, 6, 8 2011-04-11
Indonesia id 2 instruments
Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security dutyGovernment Regulation No. 71 of 2019 (PP PSTE), Pasal 3, 23, 24(1)-(2), 31, 32, 39, 40 2019-10-10
Government Regulation on the Operation of Electronic Systems and Transactions, security-incident reporting dutyGovernment Regulation No. 71 of 2019 (PP PSTE), Pasal 24(3) 2019-10-10
Ireland ie 2 instruments
European Union (NIS) Regulations 2018, Incident NotificationS.I. No. 360/2018, Regs. 18 and 22 2018-09-18
European Union (NIS) Regulations 2018, Security RequirementsS.I. No. 360/2018, Regs. 17 and 21 2018-09-18
Israel il 1 instrument
Privacy Protection Regulations (Data Security), information security programmePrivacy Protection Regulations (Data Security), 5777-2017, Regs. 1-10, 11(a)-(c), 12-20, 22; Protection of Privacy Law, 5741-1981, Art. 23KF and Third Schedule (enforcement) 2018-05-08
Italy it 2 instruments
Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident NotificationD.Lgs. 4 settembre 2024, n. 138, Art. 25 2024-10-16
Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Risk-Management MeasuresD.Lgs. 4 settembre 2024, n. 138, Artt. 23 e 24 2024-10-16
Jordan jo 1 instrument
Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation dutyCyber Security Law No. (16) of 2019, Article 8(b) not recorded
Kazakhstan kz 1 instrument
Digital Code, general cybersecurity duty on digital-object owners and holdersDigital Code No. 255-VIII (9 January 2026), Arts. 20, 97-98 2026-07-10
Kenya ke 1 instrument
Computer Misuse and Cybercrimes Act, Reporting of Cyber ThreatComputer Misuse and Cybercrimes Act (No. 5 of 2018), s. 40 2018-05-30
Kosovo xk 2 instruments
Law No. 08/L-173 on Cyber Security, Incident Reporting and EnforcementLaw No. 08/L-173 on Cyber Security, Arts. 6, 8 and 24 2023-03-14
Law No. 08/L-173 on Cyber Security, Security MeasuresLaw No. 08/L-173 on Cyber Security, Arts. 2, 3, 5 and 7 2023-03-14
Kuwait kw 1 instrument
Data Classification PolicyData Classification Policy, version 2.3 (Communication and Information Technology Regulatory Authority, listed 16 June 2022) 2022-06-16
Kyrgyzstan kg 2 instruments
Digital Code, digital resilience baseline security measuresDigital Code, Law No. 178, Art. 63(1)-(4) 2026-02-06
Digital Code, digital resilience incident notificationDigital Code, Law No. 178, Art. 63 2026-02-06
Latvia lv 3 instruments
Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and RemediationNacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024), 39.-40. panti 2024-09-01
Nacionālās kiberdrošības likums, Cybersecurity Risk-Management MeasuresNacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024, redakcija uz 18.06.2026), 25.-28. panti 2024-09-01
Nacionālās kiberdrošības likums, Incident NotificationNacionālās kiberdrošības likums (adopted 20.06.2024, notification clock applying from 01.07.2025), 34. pants 2025-07-01
Liechtenstein li 2 instruments
Cyber-Sicherheitsgesetz (CSG), Incident NotificationCyber-Sicherheitsgesetz (CSG) vom 5. Dezember 2024, LGBl. 2025 Nr. 111, Art. 6 2025-02-01
Cyber-Sicherheitsgesetz (CSG), Risk-Management Measures for Essential and Important EntitiesCyber-Sicherheitsgesetz (CSG) vom 5. Dezember 2024, LGBl. 2025 Nr. 111, Art. 1, 3, 4, 5 2025-02-01
Lithuania lt 2 instruments
Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident NotificationLietuvos Respublikos kibernetinio saugumo įstatymas Nr. XII-1428, as restated by Įstatymo Nr. XIV-2902 pakeitimo įstatymas of 11 July 2024, in force since 18 October 2024, Art. 18 2024-10-18
Kibernetinio saugumo įstatymas (Law on Cyber Security), Risk-Management MeasuresLietuvos Respublikos kibernetinio saugumo įstatymas Nr. XII-1428, as restated by Įstatymo Nr. XIV-2902 pakeitimo įstatymas of 11 July 2024, in force since 18 October 2024, Art. 14 2024-10-18
Luxembourg lu 2 instruments
Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident NotificationLoi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité, Art. 14 2026-05-10
Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important EntitiesLoi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité, Art. 11, 12, 13 2026-05-10
Malta mt 1 instrument
Cyber Resilience Regulations, MDIA Designation under the Cyber Resilience ActS.L. 591.6, Cyber Resilience Regulations, made under Chapter 591 (Malta Digital Innovation Authority Act) 2026-09-11[future]
Mexico mx 1 instrument
Ley Federal de Proteccion al Consumidor, Electronic Transaction Security Duty (Arts. 76 Bis, 76 Bis 1)Ley Federal de Proteccion al Consumidor (LFPC), Capitulo VIII Bis "De los Derechos de los Consumidores en las Transacciones Efectuadas a traves del Uso de Medios Electronicos, Opticos o de Cualquier Otra Tecnologia", Arts. 76 Bis y 76 Bis 1, capitulo adicionado por decreto publicado en el Diario Oficial de la Federacion el 29 de mayo de 2000, texto vigente con ultima reforma DOF 14-11-2025 2000-05-29
Mongolia mn 1 instrument
Law on Cyber Security, Cyber-Attack Notification Duty for Other Legal PersonsLaw of Mongolia on Cyber Security, adopted 17 December 2021, in force 1 May 2022, Art. 17.3 2022-05-01
Montenegro me 3 instruments
Law on Information Security, Cyber Threat and Incident ReportingLaw on Information Security, Arts. 28 to 37 2024-12-05
Law on Information Security, Essential and Important EntitiesLaw on Information Security, Arts. 4, 16, 18(4) to (6), and 19 to 27 2024-12-05
Law on Information Security, General Security MeasuresLaw on Information Security, Arts. 1 to 3, 7 to 15 and 18(1) to (3) 2024-12-05
Morocco ma 2 instruments
Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Incident and Vulnerability Notification DutiesLoi n° 05-20 relative à la cybersécurité, Chapitre II, Section 3, Arts. 27, 30 et 33, promulguée par le Dahir n° 1-20-69 du 4 hija 1441 (25 juillet 2020), Bulletin Officiel n° 6906 du 16 hija 1441 (6 août 2020) not recorded
Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security DutiesLoi n° 05-20 relative à la cybersécurité, Chapitre II, Section 3, Arts. 26, 29, 32 et 34, promulguée par le Dahir n° 1-20-69 du 4 hija 1441 (25 juillet 2020), Bulletin Officiel n° 6906 du 16 hija 1441 (6 août 2020) not recorded
Mozambique mz 3 instruments
Cybersecurity Law, General Security Requirements for the Public Administration and the Private SectorLei n.º 13/2026, arts. 47 a 50 2026-09-29[future]
Cybersecurity Law, Incident Notification and Responsible Vulnerability DisclosureLei n.º 13/2026, arts. 57 a 66 2026-09-29[future]
Cybersecurity Law, Sector-Specific Security Requirements for Critical Infrastructure, Essential Services and Digital ProvidersLei n.º 13/2026, arts. 51 a 56 2026-09-29[future]
Netherlands nl 2 instruments
Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and GovernanceCyberbeveiligingswet, Artt. 21 en 24 2026-08-15
Cyberbeveiligingswet, Significant-Incident Reporting ObligationsCyberbeveiligingswet, Artt. 25-29 2026-08-15
Nigeria ng 1 instrument
Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, Reporting of Cyber Threats to the National CERTCybercrimes (Prohibition, Prevention, etc.) Act, 2015, section 21, Reporting of Cyber Threats not recorded
Poland pl 2 instruments
Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), System Zarządzania Bezpieczeństwem InformacjiArt. 8 ustawy z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (Dz.U. 2026 poz. 20), w brzmieniu nadanym ustawą z dnia 23 stycznia 2026 r. (Dz.U. 2026 poz. 252) 2027-04-03[future]
Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów PoważnychArt. 11 ustawy z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (Dz.U. 2026 poz. 20), w brzmieniu nadanym ustawą z dnia 23 stycznia 2026 r. (Dz.U. 2026 poz. 252) 2027-04-03[future]
Portugal pt 2 instruments
Regime Jurídico da Cibersegurança, Cybersecurity Risk-Management Measures and GovernanceDecreto-Lei n.º 125/2025, de 4 de dezembro, Artigos 25.º a 29.º 2026-04-03
Regime Jurídico da Cibersegurança, Significant-Incident Reporting ObligationsDecreto-Lei n.º 125/2025, de 4 de dezembro, Artigos 40.º a 44.º 2026-04-03
Romania ro 2 instruments
Ordonanța de urgență nr. 155/2024, Cybersecurity Risk-Management MeasuresOrdonanța de urgență a Guvernului nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor informatice din spațiul cibernetic național civil, reportedly approved by Legea nr. 124/2025, art. 11-14 2024-12-31
Ordonanța de urgență nr. 155/2024, Incident NotificationOrdonanța de urgență a Guvernului nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor informatice din spațiul cibernetic național civil, reportedly approved by Legea nr. 124/2025, art. 15-17 2024-12-31
Serbia rs 2 instruments
Law on Information Security, ICT Systems of Special Importance and Security MeasuresZakon o informacionoj bezbednosti ("Sl. glasnik RS", br. 91/2025), čl. 5-12 2026-01-01
Law on Information Security, Incident Reporting ObligationsZakon o informacionoj bezbednosti ("Sl. glasnik RS", br. 91/2025), čl. 13-14, 24-25 2026-01-01
Slovakia sk 2 instruments
Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability NotificationZákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplní niektorých zákonov, v znení zákona č. 366/2024 Z. z., § 24 a § 5 ods. 5 2025-01-01
Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Risk-Management MeasuresZákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplní niektorých zákonov, v znení zákona č. 366/2024 Z. z., §§ 17 až 20 2025-01-01
Slovenia si 2 instruments
Zakon o informacijski varnosti (ZInfV-1), Cybersecurity Risk-Management Measures and GovernanceZakon o informacijski varnosti (ZInfV-1), Uradni list RS, št. 40/25, čl. 20-22 2026-12-18[future]
Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification ObligationsZakon o informacijski varnosti (ZInfV-1), Uradni list RS, št. 40/25, čl. 29-30 2025-06-18
South Korea kr 1 instrument
Information and Communications Network Act, Report on Computer Security IncidentsArts. 48-3 and 48-4 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (Act No. 20069, Jan. 23, 2024) 2022-06-10
Spain es 2 instruments
Real Decreto-ley 12/2018, Incident Notification ObligationReal Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de informacion, arts. 19, 21 y 22, developed by Real Decreto 43/2021, de 26 de enero 2018-09-09
Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service ProvidersReal Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de informacion, art. 16, developed by Real Decreto 43/2021, de 26 de enero 2018-09-09
Sweden se 2 instruments
Cybersäkerhetslag, Cybersecurity Risk-Management MeasuresCybersäkerhetslag (2025:1506), 2 kap. 3-4 §§ 2026-01-15
Cybersäkerhetslag, Incident NotificationCybersäkerhetslag (2025:1506), 2 kap. 5-10 §§ 2026-01-15
Tunisia tn 2 instruments
Cybersecurity Incident Reporting and Emergency ResponseDécret-loi n° 2023-17 du 11 mars 2023, relatif à la cybersécurité, Arts. 17-20, 24-25 2023-09-11
Mandatory Security Audit and Digital-Trust ClassificationDécret-loi n° 2023-17 du 11 mars 2023, relatif à la cybersécurité, Arts. 6-9, 14-16, 24-25 2023-09-11
Turkey tr 1 instrument
Cybersecurity Law, Reporting and Cooperation DutiesLaw No. 7545 (12 March 2025), Art. 7 2025-03-19
United Kingdom gb 1 instrument
Product Security Requirements for Connectable ProductsProduct Security and Telecommunications Infrastructure Act 2022, c. 46, Part 1; Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, SI 2023/1007 2024-04-29
United States us 1 instrument
SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05)17 CFR 229.106; 17 CFR 249.308 (Form 8-K Item 1.05) 2023-12-18
Uzbekistan uz 3 instruments
Law on Cybersecurity, cybersecurity incident notification dutyLaw No. O'RQ-764 (15 April 2022) "On Cybersecurity," Arts. 3, 16, 22-24 2022-07-17
Law on Cybersecurity, general cybersecurity duties on cybersecurity subjectsLaw No. O'RQ-764 (15 April 2022) "On Cybersecurity," Arts. 3, 16, 37 2022-07-17
Law on Informatization, information security duty for information resource and system ownersLaw No. 560-II (11 December 2003) "On Informatization," Arts. 19-20 2004-02-11
Vietnam vn 2 instruments
Cybersecurity Law, Incident Response and Reporting DutiesLaw No. 116/2025/QH15 (Law on Cybersecurity), arts. 40(1)(c), 41(2)-(4) 2026-07-01
Cybersecurity Law, Information System Classification and Protection MeasuresLaw No. 116/2025/QH15 (Law on Cybersecurity), arts. 8, 10 2026-07-01

United States: states41 in 32 places

Law made below the national level, binding inside it. The slug beside each name says which tier it is.

Stage Instrument In force from
Alabama us/al 1 instrument
Data Breach Notification Act, reasonable security measures and disposal of recordsAla. Code secs. 8-38-3, 8-38-10 2018-06-01
Alaska us/ak 1 instrument
Alaska Personal Information Protection Act, disposal of records dutyAlaska Stat. Secs. 45.48.500-45.48.590 2009-07-01
Arizona us/az 1 instrument
Discarding and disposing of records containing personal identifying informationA.R.S. sec. 44-7601 2005-01-01
Arkansas us/ar 1 instrument
Arkansas Personal Information Protection Act, reasonable security proceduresArk. Code Ann. section 4-110-104(b) not recorded
California us/ca 2 instruments
Customer Records Act, Reasonable Security ProceduresCal. Civ. Code section 1798.81.5, as amended by AB 825 (2021, Ch. 527) 2022-01-01
Security of Connected DevicesCal. Civ. Code sections 1798.91.04-1798.91.06 (Title 1.81.26, added by Stats. 2018, Ch. 860 (AB 1906) and Ch. 886 (SB 327); sections 1798.91.04 and 1798.91.05 amended by Stats. 2022, Ch. 785 (AB 2392)) 2023-01-01
Colorado us/co 2 instruments
Disposal of personal identifying information, written policy dutyC.R.S. 6-1-713 (amended by HB 18-1128, 2018 Colo. Sess. Laws ch. 266, section 1) 2018-09-01
Protection of personal identifying information, reasonable security procedures dutyC.R.S. 6-1-713.5 (added by HB 18-1128, 2018 Colo. Sess. Laws ch. 266, section 2) 2018-09-01
Connecticut us/ct 3 instruments
Adoption of cybersecurity controls by businesses, exemption from punitive damagesConn. Gen. Stat. sec. 42-901 2021-10-01
Connected device provider's duty to protect recorded personal information with reasonable security measuresPublic Act No. 25-44, Sec. 2(c) (2025) 2026-07-01
Protection of Social Security Numbers and Personal Information Act, safeguarding and destruction dutyConn. Gen. Stat. sec. 42-471 2008-10-01
Delaware us/de 1 instrument
Computer Security Breaches, protection of personal informationDel. Code Ann. tit. 6, section 12B-100 2018-04-14
District of Columbia us/dc 1 instrument
Security requirements for personal information (Security Breach Protection Amendment Act of 2020)D.C. Code § [28-3852.01] (Title 28, Chapter 38, Subchapter II, "Security requirements," added by the Security Breach Protection Amendment Act of 2020, D.C. Law 23-98, § 2(a)(5), 67 DCR 3923) 2020-06-17
Florida us/fl 1 instrument
Florida Information Protection Act, data security and disposal dutyFla. Stat. § 501.171(2), (8) 2014-07-01
Georgia us/ga 1 instrument
Disposal of records containing personal informationO.C.G.A. Sec. 10-15-2 not recorded
Hawaii us/hi 1 instrument
Destruction of Personal Information RecordsHaw. Rev. Stat. Secs. 487R-1 to 487R-3 2007-01-01
Illinois us/il 2 instruments
Personal Information Protection Act, data security duty815 ILCS 530/45 (P.A. 99-503, eff. 2017-01-01) 2017-01-01
Personal Information Protection Act, safe disposal of personal information815 ILCS 530/40 (P.A. 97-483, eff. 2012-01-01) 2012-01-01
Indiana us/in 1 instrument
Disclosure of Security Breach Act, data base owner's duty to maintain reasonable security procedures and dispose of recordsInd. Code sec. 24-4.9-3-3.5 [future]
Iowa us/ia 1 instrument
Tort Liability for Cybersecurity Programs, affirmative defense for a reasonable security programIowa Code ch. 554G (554G.1 to 554G.4, added by 2023 Acts, ch. 63 (H.F. 553)) 2023-07-01
Kansas us/ks 1 instrument
Kansas Consumer Protection Act, reasonable security and records-destruction duty for holders of personal informationK.S.A. 50-6,139b 2016-07-01
Louisiana us/la 1 instrument
Database Security Breach Notification Law, reasonable security procedures and destruction dutyLa. R.S. 51:3074(A), (B) 2006-01-01
Maryland us/md 1 instrument
Maryland Personal Information Protection Act (MPIPA), safeguards and secure-disposal dutyMd. Code Ann., Com. Law sections 14-3502, 14-3503 (Maryland Personal Information Protection Act, Title 14, Subtitle 35, added by 2007 Md. Laws ch. 531 (S.B. 194)) 2008-01-01
Massachusetts us/ma 1 instrument
Standards for the Protection of Personal Information of Residents of the Commonwealth201 CMR 17.01-17.05 2010-03-01
Michigan us/mi 1 instrument
Identity Theft Protection Act, destruction of data no longer neededMCL 445.72a (Sec. 12a of Act 452 of 2004, added by 2006 PA 566) 2007-07-02
Nebraska us/ne 1 instrument
Financial Data Protection and Consumer Notification of Data Security Breach Act, security procedures and practices dutyNeb. Rev. Stat. section 87-808 (added by Laws 2018, LB757, section 7) 2018-07-19
Nevada us/nv 2 instruments
Security measures for a data collector accepting payment cards, encryption duty, and conditioned liability shieldNRS 603A.215 [future]
Security measures for data collectors maintaining personal informationNRS 603A.210 [future]
New Jersey us/nj 1 instrument
Identity Theft Prevention Act, methods of destruction of customer recordsN.J. Stat. Ann. § 56:8-162 (L. 2005, c.226, s.11) 2006-01-01
New Mexico us/nm 1 instrument
Data Breach Notification Act, security and disposal dutiesNMSA 1978 Secs. 57-12C-3 to 57-12C-5 [future]
New York us/ny 1 instrument
Stop Hacks and Improve Electronic Data Security (SHIELD) Act, data security program dutyN.Y. Gen. Bus. Law section 899-bb (Article 39-F, added by L. 2019, ch. 117 (S5575-B/A5635-B), section 4) 2020-03-21
North Carolina us/nc 1 instrument
Identity Theft Protection Act, destruction of personal information recordsN.C. Gen. Stat. section 75-64 (Chapter 75, Article 2A, added by S.L. 2005-414, s. 1) 2005-12-01
Ohio us/oh 1 instrument
Ohio Data Protection Act, cybersecurity program safe harborOhio Rev. Code sections 1354.01 to 1354.05 (enacted by Senate Bill 220, 132nd General Assembly, effective November 2, 2018; section 1354.01 last amended by House Bill 66, 132nd General Assembly, effective April 5, 2019) 2018-11-02
Oregon us/or 2 instruments
Oregon Consumer Information Protection Act, requirement to develop safeguards for personal informationORS 646A.622 (2007 c.759 sec. 12; amended 2015 c.357 sec. 3; 2018 c.10 sec. 6; 2019 c.180 sec. 4) not recorded
Security requirements for Internet-connected devicesORS 646A.813 (added by 2019 c.193 (H.B. 2395-A) sec. 1; amending ORS 646.607) not recorded
Rhode Island us/ri 1 instrument
Identity Theft Protection Act of 2015, risk-based information security programR.I. Gen. Laws secs. 11-49.3-2, 11-49.3-5 [future]
Texas us/tx 2 instruments
Cybersecurity Program safe harbor from exemplary damages (S.B. 2610)Tex. Bus. & Com. Code ch. 542 (secs. 542.001-542.004) 2025-09-01
Identity Theft Enforcement and Protection Act, business duty to protect sensitive personal informationTex. Bus. & Com. Code sec. 521.052 2009-04-01
Utah us/ut 2 instruments
Cybersecurity Affirmative Defense ActUtah Code 78B-4-701 to 78B-4-704 2021-05-05
Protection of Personal Information Act, reasonable procedures and records-destruction dutyUtah Code 13-44-201 2019-05-14
Vermont us/vt 1 instrument
Document Safe Destruction Act, safe destruction of records containing personal information9 V.S.A. § 2445 (Added 2005, No. 162 (Adj. Sess.), § 1, eff. Jan. 1, 2007) 2007-01-01

What this page claims, and what it does not

The stages are LexLint's own vocabulary. Four of the five boxes are the binding classes the /law/<jurisdiction> docket already draws (In force, Enacted but not yet in force, Proposed, and Repealed, withdrawn or blocked), so a square here and a square there mean the same thing. A struck-down instrument is spent on both readings.

Enjoined has its own box. Inside "Repealed, withdrawn or blocked" it would sit beside a mark that is a false description of a law a court has paused, and it would pool away a count that reads as a signal: how contested a jurisdictional hook is. The certainty ladder files enjoined as present law and the docket draws it spent; splitting it out here makes that disagreement the reader's choice instead of our silent one. It is off by default, which follows the docket.

One date column, and where a bare date would mislead it says what kind of date it is. "In force from" is commencement: the earlier of a published commencement event and the instrument's own effective date, the same choice lifecycle_band() makes and for the same reason, neither source is reliably the commencement, and the earlier one cannot make a law look newer than it is. A bracket qualifies the date where a bare one would mislead ([future] for a start date still ahead, [proposed] for a bill with no commencement to show, [enjoined], [struck down], [repealed], [superseded] or [withdrawn] for a spent instrument). Nothing is inferred from our own review date: a row with neither a date nor a status to explain the gap says "not recorded" instead.

The map is the table. Its fill is the count of instruments at the stages you chose, binned on the same RAMP_BINS edges /law/map uses, and it redraws on every change. Point at, click, or tab to a place for what applies there, every stage it holds shown even when your filter is excluding it.

Three ways of showing nothing, and they are different claims. A place washed pale holds cybersecurity law your filter is excluding, so widening the filter brings it back. A hatched place is one we track and hold no cybersecurity law for at all: that is a statement about our research, not about the law. A white place has no jurisdiction record for this topic at all. Only the first of the three moves when you change the filter; the other two are facts about us and hold still.

Nothing here needs the script. The default resultset is in the HTML: counts, tally, map fills and the hidden rows are all rendered at build. The script recomputes them when a box changes and does nothing else, which is what lets this page ship under script-src 'self' and be read whole by a crawler.