Law / Cybersecurity
Cybersecurity law, instrument by instrument
Every cybersecurity law instrument LexLint holds, grouped by the place that made it. Choose which stages of law to show: the map, the counts and the tables all answer to that choice. To see every area of law, follow Law in the breadcrumb above.
- 1
- 5
- 10
- 20+
- instruments shown
- law on file, none at these stages
- tracked, no law on file
- not tracked
Unions4 in 1 place
Law made above the state, binding its members.
| Stage | Instrument | In force from |
|---|---|---|
| European Union eu 4 instruments | ||
| Cyber Resilience Act, Essential Requirements and Manufacturer ObligationsRegulation (EU) 2024/2847, Art. 13 and Annex I | 2027-12-11[future] | |
| Cyber Resilience Act, Manufacturer Reporting ObligationsRegulation (EU) 2024/2847, Art. 14 | 2026-09-11 | |
| NIS2 Directive, Cybersecurity Risk-Management MeasuresDirective (EU) 2022/2555, Art. 21 | 2024-10-18 | |
| NIS2 Directive, Reporting ObligationsDirective (EU) 2022/2555, Art. 23 | 2024-10-18 | |
Countries121 in 65 places
One row group per country, alphabetically.
| Stage | Instrument | In force from |
|---|---|---|
| Albania al 1 instrument | ||
| Law No. 25/2024, On CybersecurityLaw No. 25/2024 (Ligj Nr. 25/2024), 21 March 2024, "Për sigurinë kibernetike" ("On Cybersecurity"), Fletorja Zyrtare No. 67/2024, p. 7767 | 2024-05-03 | |
| Andorra ad 2 instruments | ||
| Llei 22/2022, Cybersecurity Risk-Management ObligationsLlei 22/2022, del 9 de juny, arts. 12, 13, 17 i 18 | 2022-06-23 | |
| Llei 22/2022, Incident Handling and Notification ObligationLlei 22/2022, del 9 de juny, arts. 14 i 15 | 2022-06-23 | |
| Angola ao 2 instruments | ||
| Lei de Protecção das Redes e Sistemas Informáticos, Incident-Management Planning, Alert Dissemination and CERT Coordination DutiesLei n.º 7/17, Artigos 15.º, 16.º, 40.º e 41.º | not recorded | |
| Lei de Protecção das Redes e Sistemas Informáticos, Security Duties for Information-Society Systems, Computer Programs and DatabasesLei n.º 7/17, Artigos 12.º, 13.º, 14.º, 17.º, 18.º e 19.º | not recorded | |
| Australia au 1 instrument | ||
| Security Standards for Smart DevicesCyber Security Act 2024 (Cth), No. 98, 2024, Part 2, ss. 13-24; Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276), Schedule 1 | 2026-03-04 | |
| Austria at 4 instruments | ||
| Netz- und Informationssystemsicherheitsgesetz (NISG), Incident Notification ObligationsNISG, BGBl. I Nr. 111/2018, §§ 19 und 21 | 2018-12-28 | |
| Netz- und Informationssystemsicherheitsgesetz (NISG), Security Measures for Operators of Essential Services and Digital Service ProvidersNISG, BGBl. I Nr. 111/2018, §§ 17 und 21 | 2018-12-28 | |
| Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management MeasuresNISG 2026, BGBl. I Nr. 94/2025, §§ 24, 25, 28 und 32 | 2026-10-01[future] | |
| Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting ObligationsNISG 2026, BGBl. I Nr. 94/2025, §§ 34 und 35 | 2026-10-01[future] | |
| Bangladesh bd 1 instrument | ||
| Cyber Security Act, Computer Emergency Response Team, Duty to Report a Cyber IncidentCyber Security Act, 2026 (Act No. 81 of 2026), s. 9 | 2025-05-21 | |
| Belgium be 2 instruments | ||
| Loi du 26 avril 2024, Cybersecurity Risk-Management Measures and GovernanceLoi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la sécurité publique, Artt. 30-33 | 2024-10-18 | |
| Loi du 26 avril 2024, Significant-Incident Notification ObligationsLoi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la sécurité publique, Artt. 34-37 | 2024-10-18 | |
| Benin bj 1 instrument | ||
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre VI (cybersécurité), sécurité des réseaux et essai de vulnérabilité des produitsLoi n°2017-20 du 20 avril 2018, Livre VI, Titre I, Chapitre XIII, Article 598, portant Code du Numérique en République du Bénin | 2018-04-20 | |
| Brazil br 1 instrument | ||
| Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment)Ato nº 2.436, de 7 de março de 2023 (Superintendência de Outorga e Recursos à Prestação, Agência Nacional de Telecomunicações), as amended by Ato nº 7.344, de 15 de junho de 2023; issued under the Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações, approved by Resolução nº 740, de 21 de dezembro de 2020, and the Regulamento de Avaliação da Conformidade e de Homologação de Produtos para Telecomunicações, approved by Resolução nº 715, de 23 de outubro de 2019 | 2024-03-10 | |
| Bulgaria bg 2 instruments | ||
| Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS)Закон за киберсигурност (ЗКС), чл. 23, изм. с § 27 от Закона за изменение и допълнение на ЗКС, обн. ДВ, бр. 17 от 13.02.2026 г. (English: Cybersecurity Act, Art. 23, as substituted by § 27 of the Act Amending and Supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026) | 2026-02-17 | |
| Cybersecurity Act, Risk-Management Measures and Governance (Zakon za kibersigurnost, ZKS)Закон за киберсигурност (ЗКС), чл. 21 и 22, изм. с §§ 25 и 26 от Закона за изменение и допълнение на ЗКС, обн. ДВ, бр. 17 от 13.02.2026 г. (English: Cybersecurity Act, Arts. 21 and 22, as substituted by §§ 25 and 26 of the Act Amending and Supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026) | 2026-02-17 | |
| Cameroon cm 1 instrument | ||
| Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, articles 6, 7, 13-14, 24, 26-30, 32, 61(3) (mesures de sécurité et audit de sécurité obligatoire par l'ANTIC)Loi n°2010/012 du 21 décembre 2010, art. 6-7, 13-14, 24, 26-30, 32, 61(3) | 2010-12-21 | |
| China cn 3 instruments | ||
| Cybersecurity Law, Network Product and Service Security DutiesCybersecurity Law of the People's Republic of China (as amended by the Decision of October 28, 2025, effective January 1, 2026), Art. 24 | 2026-01-01 | |
| Data Security Law, Data Security Protection ObligationsData Security Law of the People's Republic of China, Art. 27 | 2021-09-01 | |
| Data Security Law, Risk Monitoring and Incident Reporting DutyData Security Law of the People's Republic of China, Art. 29 | 2021-09-01 | |
| Croatia hr 2 instruments | ||
| Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting ObligationsZakon o kibernetičkoj sigurnosti, Narodne novine, broj 14/2024, čl. 37.-44.; Uredba o kibernetičkoj sigurnosti, Narodne novine, broj 135/2024, čl. 64.-71. i 85. | 2024-11-30 | |
| Zakon o kibernetičkoj sigurnosti, Risk-Management Measures and GovernanceZakon o kibernetičkoj sigurnosti, Narodne novine, broj 14/2024, čl. 29. i 30. | 2024-02-15 | |
| Cyprus cy 3 instruments | ||
| Security of Networks and Information Systems Law, Cybersecurity Risk-Management Measures and GovernanceArts. 35 and 35A of the Security of Networks and Information Systems Law of 2020, N. 89(I)/2020, as amended by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025 | 2025-04-25 | |
| Security of Networks and Information Systems Law, Incident Notification ObligationsArt. 35B of the Security of Networks and Information Systems Law of 2020, N. 89(I)/2020, as amended by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025 | 2025-04-25 | |
| Security of Networks and Information Systems Law, Radio Equipment Cybersecurity RequirementsArt. 42A of the Security of Networks and Information Systems Law of 2020, N. 89(I)/2020, as inserted by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025 | 2025-04-25 | |
| Czech Republic cz 2 instruments | ||
| Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident NotificationAct No. 264/2025 Coll., Cybersecurity Act, Sections 15-16 | 2025-11-01 | |
| Cybersecurity Act (Zákon o kybernetické bezpečnosti), Risk-Management Security MeasuresAct No. 264/2025 Coll., Cybersecurity Act, Sections 13-14 | 2025-11-01 | |
| Côte d'Ivoire ci 3 instruments | ||
| Mandatory Information Systems Security Audit and CertificationDécret n°2021-917 du 22 décembre 2021, Arts. 3-4, 19-21 | 2021-12-22 | |
| Mandatory Reporting of Attacks and Intrusions to ARTCIDécret n°2021-917 du 22 décembre 2021, Arts. 16-17 | 2021-12-22 | |
| RGSSI and PPIC Compliance DutyDécret n°2021-916 du 22 décembre 2021, Arts. 1-2 | 2021-12-22 | |
| Denmark dk 2 instruments | ||
| NIS 2-loven, Cybersecurity Risk-Management Measures and RegistrationNIS 2-loven, §§ 6-10 | 2025-07-01 | |
| NIS 2-loven, Significant-Incident Reporting and Recipient-Notice DutiesNIS 2-loven, §§ 12-13, 15 | 2025-07-01 | |
| Egypt eg 1 instrument | ||
| Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, System-Security Duty on a System ManagerLaw No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, Arts. 29, 42, 44 | 2018-08-15 | |
| Estonia ee 2 instruments | ||
| Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber IncidentKüberturvalisuse seadus (Cybersecurity Act), RT I, 30.12.2025, 4, §§ 8 and 8-1 | 2026-01-01 | |
| Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body DutiesKüberturvalisuse seadus (Cybersecurity Act), RT I, 30.12.2025, 4, §§ 6-1 and 7 | 2026-01-01 | |
| Finland fi 3 instruments | ||
| Kyberkestävyyslaki, National Enforcement and Market Surveillance for the Cyber Resilience ActLaki eräiden tuotteiden kyberkestävyydestä sekä kyberturvallisuussertifioinnista (439/2026), 1, 7-9, 15-16 ja 31-38 § | 2026-06-01 | |
| Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and GovernanceKyberturvallisuuslaki (124/2025), 3 ja 7-10 § | 2025-04-08 | |
| Kyberturvallisuuslaki, Significant-Incident Reporting ObligationsKyberturvallisuuslaki (124/2025), 11-14 ja 22 § | 2025-04-08 | |
| France fr 3 instruments | ||
| Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Incident NotificationLoi n° 2018-133 du 26 février 2018, Titre Ier, art. 7 et 13 | 2018-05-10 | |
| Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security RequirementsLoi n° 2018-133 du 26 février 2018, Titre Ier, Chapitres II et III, art. 5, 6, 10, 11 et 12 | 2018-05-10 | |
| Loi n° 2022-309 du 3 mars 2022 (loi Cyberscore), Cybersecurity Audit and Disclosure DutyLoi n° 2022-309 du 3 mars 2022, art. 1 (Code de la consommation, art. L. 111-7-3) | 2023-10-01 | |
| Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Cybersecurity Risk-Management Measures (NIS2)Article 14, texte adopté n° 78 (2024-2025), Sénat, 12 mars 2025 (mesures de gestion des risques) | [proposed] | |
| Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Incident Notification (NIS2)Article 17, texte adopté n° 78 (2024-2025), Sénat, 12 mars 2025 (notification des incidents) | [proposed] | |
| Gabon ga 1 instrument | ||
| Sécurité des systèmes d'information (dispositions communes)Loi N° 027/2023 du 11 juillet 2023, Titre III, Chapitre III, Section 2, arts. 28-35 | 2023-07-15 | |
| Germany de 2 instruments | ||
| BSI-Gesetz (BSIG), Incident NotificationBSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), § 32 | 2025-12-06 | |
| BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important EntitiesBSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), §§ 28, 30, 38 | 2025-12-06 | |
| Ghana gh 3 instruments | ||
| Cybersecurity Act, Cybersecurity Standards and EnforcementCybersecurity Act, 2020 (Act 1038), s. 59, and Second Schedule item 59(4) | 2020-12-29 | |
| Cybersecurity Act, Duty to Report Cybersecurity IncidentCybersecurity Act, 2020 (Act 1038), ss. 47(2) and 47(5)-(6), and Second Schedule item 47(6) | 2020-12-29 | |
| Cybersecurity Act, Licensing of Cybersecurity Service ProvidersCybersecurity Act, 2020 (Act 1038), ss. 49-53, First Schedule, and Second Schedule items 49(2) and 51(5) | 2020-12-29 | |
| Greece gr 2 instruments | ||
| Law 5160/2024, Cybersecurity Risk-Management Measures and GovernanceLaw 5160/2024 (Ν. 5160/2024), Arts. 14-15 | 2024-11-27 | |
| Law 5160/2024, Significant-Incident Reporting ObligationsLaw 5160/2024 (Ν. 5160/2024), Art. 16 | 2024-11-27 | |
| Hungary hu 2 instruments | ||
| Cybersecurity Act, Incident Notification and Cybersecurity Fine2024. évi LXIX. törvény, 66. §; 418/2024. (XII. 23.) Korm. rendelet, 42. § és 77. § | 2025-01-01 | |
| Cybersecurity Act, Risk-Management Measures2024. évi LXIX. törvény (Magyarország kiberbiztonságáról), 6. § | 2025-01-01 | |
| Iceland is 2 instruments | ||
| Minimum Risk-Management and Preparedness Requirements for Critical InfrastructureLog nr. 78/2019, Art. 7 | 2020-09-01 | |
| Notification of Serious Incidents and Risk to the National Cybersecurity Incident-Response TeamLog nr. 78/2019, Art. 8 | 2020-09-01 | |
| India in 2 instruments | ||
| CERT-In Cyber Security Directions, Incident Reporting, Logging and Time SynchronisationDirections under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022) | 2022-06-27 | |
| Information Technology Act, Compensation for Failure to Protect Data, and Sensitive Personal Data or Information Rules, Reasonable Security PracticesInformation Technology Act, 2000 (No. 21 of 2000), s.43A; Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (G.S.R. 313(E), 11 April 2011), rr. 3, 4, 5, 6, 8 | 2011-04-11 | |
| Indonesia id 2 instruments | ||
| Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security dutyGovernment Regulation No. 71 of 2019 (PP PSTE), Pasal 3, 23, 24(1)-(2), 31, 32, 39, 40 | 2019-10-10 | |
| Government Regulation on the Operation of Electronic Systems and Transactions, security-incident reporting dutyGovernment Regulation No. 71 of 2019 (PP PSTE), Pasal 24(3) | 2019-10-10 | |
| Ireland ie 2 instruments | ||
| European Union (NIS) Regulations 2018, Incident NotificationS.I. No. 360/2018, Regs. 18 and 22 | 2018-09-18 | |
| European Union (NIS) Regulations 2018, Security RequirementsS.I. No. 360/2018, Regs. 17 and 21 | 2018-09-18 | |
| National Cyber Security Bill, Cybersecurity Risk-Management MeasuresHead 29, General Scheme, National Cyber Security Bill 2024 | [proposed] | |
| National Cyber Security Bill, Incident Response Powers and Reporting ObligationsHead 15, General Scheme, National Cyber Security Bill 2024 | [proposed] | |
| Israel il 1 instrument | ||
| Privacy Protection Regulations (Data Security), information security programmePrivacy Protection Regulations (Data Security), 5777-2017, Regs. 1-10, 11(a)-(c), 12-20, 22; Protection of Privacy Law, 5741-1981, Art. 23KF and Third Schedule (enforcement) | 2018-05-08 | |
| Italy it 2 instruments | ||
| Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident NotificationD.Lgs. 4 settembre 2024, n. 138, Art. 25 | 2024-10-16 | |
| Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Risk-Management MeasuresD.Lgs. 4 settembre 2024, n. 138, Artt. 23 e 24 | 2024-10-16 | |
| Jordan jo 1 instrument | ||
| Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation dutyCyber Security Law No. (16) of 2019, Article 8(b) | not recorded | |
| Kazakhstan kz 1 instrument | ||
| Digital Code, general cybersecurity duty on digital-object owners and holdersDigital Code No. 255-VIII (9 January 2026), Arts. 20, 97-98 | 2026-07-10 | |
| Kenya ke 1 instrument | ||
| Computer Misuse and Cybercrimes Act, Reporting of Cyber ThreatComputer Misuse and Cybercrimes Act (No. 5 of 2018), s. 40 | 2018-05-30 | |
| Kosovo xk 2 instruments | ||
| Law No. 08/L-173 on Cyber Security, Incident Reporting and EnforcementLaw No. 08/L-173 on Cyber Security, Arts. 6, 8 and 24 | 2023-03-14 | |
| Law No. 08/L-173 on Cyber Security, Security MeasuresLaw No. 08/L-173 on Cyber Security, Arts. 2, 3, 5 and 7 | 2023-03-14 | |
| Kuwait kw 1 instrument | ||
| Data Classification PolicyData Classification Policy, version 2.3 (Communication and Information Technology Regulatory Authority, listed 16 June 2022) | 2022-06-16 | |
| Kyrgyzstan kg 2 instruments | ||
| Digital Code, digital resilience baseline security measuresDigital Code, Law No. 178, Art. 63(1)-(4) | 2026-02-06 | |
| Digital Code, digital resilience incident notificationDigital Code, Law No. 178, Art. 63 | 2026-02-06 | |
| Latvia lv 3 instruments | ||
| Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and RemediationNacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024), 39.-40. panti | 2024-09-01 | |
| Nacionālās kiberdrošības likums, Cybersecurity Risk-Management MeasuresNacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024, redakcija uz 18.06.2026), 25.-28. panti | 2024-09-01 | |
| Nacionālās kiberdrošības likums, Incident NotificationNacionālās kiberdrošības likums (adopted 20.06.2024, notification clock applying from 01.07.2025), 34. pants | 2025-07-01 | |
| Liechtenstein li 2 instruments | ||
| Cyber-Sicherheitsgesetz (CSG), Incident NotificationCyber-Sicherheitsgesetz (CSG) vom 5. Dezember 2024, LGBl. 2025 Nr. 111, Art. 6 | 2025-02-01 | |
| Cyber-Sicherheitsgesetz (CSG), Risk-Management Measures for Essential and Important EntitiesCyber-Sicherheitsgesetz (CSG) vom 5. Dezember 2024, LGBl. 2025 Nr. 111, Art. 1, 3, 4, 5 | 2025-02-01 | |
| Lithuania lt 2 instruments | ||
| Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident NotificationLietuvos Respublikos kibernetinio saugumo įstatymas Nr. XII-1428, as restated by Įstatymo Nr. XIV-2902 pakeitimo įstatymas of 11 July 2024, in force since 18 October 2024, Art. 18 | 2024-10-18 | |
| Kibernetinio saugumo įstatymas (Law on Cyber Security), Risk-Management MeasuresLietuvos Respublikos kibernetinio saugumo įstatymas Nr. XII-1428, as restated by Įstatymo Nr. XIV-2902 pakeitimo įstatymas of 11 July 2024, in force since 18 October 2024, Art. 14 | 2024-10-18 | |
| Luxembourg lu 2 instruments | ||
| Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident NotificationLoi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité, Art. 14 | 2026-05-10 | |
| Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important EntitiesLoi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité, Art. 11, 12, 13 | 2026-05-10 | |
| Malta mt 1 instrument | ||
| Cyber Resilience Regulations, MDIA Designation under the Cyber Resilience ActS.L. 591.6, Cyber Resilience Regulations, made under Chapter 591 (Malta Digital Innovation Authority Act) | 2026-09-11[future] | |
| Mexico mx 1 instrument | ||
| Ley Federal de Proteccion al Consumidor, Electronic Transaction Security Duty (Arts. 76 Bis, 76 Bis 1)Ley Federal de Proteccion al Consumidor (LFPC), Capitulo VIII Bis "De los Derechos de los Consumidores en las Transacciones Efectuadas a traves del Uso de Medios Electronicos, Opticos o de Cualquier Otra Tecnologia", Arts. 76 Bis y 76 Bis 1, capitulo adicionado por decreto publicado en el Diario Oficial de la Federacion el 29 de mayo de 2000, texto vigente con ultima reforma DOF 14-11-2025 | 2000-05-29 | |
| Mongolia mn 1 instrument | ||
| Law on Cyber Security, Cyber-Attack Notification Duty for Other Legal PersonsLaw of Mongolia on Cyber Security, adopted 17 December 2021, in force 1 May 2022, Art. 17.3 | 2022-05-01 | |
| Montenegro me 3 instruments | ||
| Law on Information Security, Cyber Threat and Incident ReportingLaw on Information Security, Arts. 28 to 37 | 2024-12-05 | |
| Law on Information Security, Essential and Important EntitiesLaw on Information Security, Arts. 4, 16, 18(4) to (6), and 19 to 27 | 2024-12-05 | |
| Law on Information Security, General Security MeasuresLaw on Information Security, Arts. 1 to 3, 7 to 15 and 18(1) to (3) | 2024-12-05 | |
| Morocco ma 2 instruments | ||
| Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Incident and Vulnerability Notification DutiesLoi n° 05-20 relative à la cybersécurité, Chapitre II, Section 3, Arts. 27, 30 et 33, promulguée par le Dahir n° 1-20-69 du 4 hija 1441 (25 juillet 2020), Bulletin Officiel n° 6906 du 16 hija 1441 (6 août 2020) | not recorded | |
| Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security DutiesLoi n° 05-20 relative à la cybersécurité, Chapitre II, Section 3, Arts. 26, 29, 32 et 34, promulguée par le Dahir n° 1-20-69 du 4 hija 1441 (25 juillet 2020), Bulletin Officiel n° 6906 du 16 hija 1441 (6 août 2020) | not recorded | |
| Mozambique mz 3 instruments | ||
| Cybersecurity Law, General Security Requirements for the Public Administration and the Private SectorLei n.º 13/2026, arts. 47 a 50 | 2026-09-29[future] | |
| Cybersecurity Law, Incident Notification and Responsible Vulnerability DisclosureLei n.º 13/2026, arts. 57 a 66 | 2026-09-29[future] | |
| Cybersecurity Law, Sector-Specific Security Requirements for Critical Infrastructure, Essential Services and Digital ProvidersLei n.º 13/2026, arts. 51 a 56 | 2026-09-29[future] | |
| Netherlands nl 2 instruments | ||
| Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and GovernanceCyberbeveiligingswet, Artt. 21 en 24 | 2026-08-15 | |
| Cyberbeveiligingswet, Significant-Incident Reporting ObligationsCyberbeveiligingswet, Artt. 25-29 | 2026-08-15 | |
| Nigeria ng 1 instrument | ||
| Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, Reporting of Cyber Threats to the National CERTCybercrimes (Prohibition, Prevention, etc.) Act, 2015, section 21, Reporting of Cyber Threats | not recorded | |
| Peru pe 0 instruments | ||
| Proyecto de Ley 9906/2024-CR, Ley de Seguridad Digital o CiberseguridadProyecto de Ley 9906/2024-CR, introduced before the Congreso de la Republica on 10 January 2025 | [proposed] | |
| Poland pl 2 instruments | ||
| Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), System Zarządzania Bezpieczeństwem InformacjiArt. 8 ustawy z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (Dz.U. 2026 poz. 20), w brzmieniu nadanym ustawą z dnia 23 stycznia 2026 r. (Dz.U. 2026 poz. 252) | 2027-04-03[future] | |
| Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów PoważnychArt. 11 ustawy z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (Dz.U. 2026 poz. 20), w brzmieniu nadanym ustawą z dnia 23 stycznia 2026 r. (Dz.U. 2026 poz. 252) | 2027-04-03[future] | |
| Portugal pt 2 instruments | ||
| Regime Jurídico da Cibersegurança, Cybersecurity Risk-Management Measures and GovernanceDecreto-Lei n.º 125/2025, de 4 de dezembro, Artigos 25.º a 29.º | 2026-04-03 | |
| Regime Jurídico da Cibersegurança, Significant-Incident Reporting ObligationsDecreto-Lei n.º 125/2025, de 4 de dezembro, Artigos 40.º a 44.º | 2026-04-03 | |
| Romania ro 2 instruments | ||
| Ordonanța de urgență nr. 155/2024, Cybersecurity Risk-Management MeasuresOrdonanța de urgență a Guvernului nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor informatice din spațiul cibernetic național civil, reportedly approved by Legea nr. 124/2025, art. 11-14 | 2024-12-31 | |
| Ordonanța de urgență nr. 155/2024, Incident NotificationOrdonanța de urgență a Guvernului nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor informatice din spațiul cibernetic național civil, reportedly approved by Legea nr. 124/2025, art. 15-17 | 2024-12-31 | |
| Serbia rs 2 instruments | ||
| Law on Information Security, ICT Systems of Special Importance and Security MeasuresZakon o informacionoj bezbednosti ("Sl. glasnik RS", br. 91/2025), čl. 5-12 | 2026-01-01 | |
| Law on Information Security, Incident Reporting ObligationsZakon o informacionoj bezbednosti ("Sl. glasnik RS", br. 91/2025), čl. 13-14, 24-25 | 2026-01-01 | |
| Slovakia sk 2 instruments | ||
| Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability NotificationZákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplní niektorých zákonov, v znení zákona č. 366/2024 Z. z., § 24 a § 5 ods. 5 | 2025-01-01 | |
| Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Risk-Management MeasuresZákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplní niektorých zákonov, v znení zákona č. 366/2024 Z. z., §§ 17 až 20 | 2025-01-01 | |
| Slovenia si 2 instruments | ||
| Zakon o informacijski varnosti (ZInfV-1), Cybersecurity Risk-Management Measures and GovernanceZakon o informacijski varnosti (ZInfV-1), Uradni list RS, št. 40/25, čl. 20-22 | 2026-12-18[future] | |
| Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification ObligationsZakon o informacijski varnosti (ZInfV-1), Uradni list RS, št. 40/25, čl. 29-30 | 2025-06-18 | |
| South Korea kr 1 instrument | ||
| Information and Communications Network Act, Report on Computer Security IncidentsArts. 48-3 and 48-4 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (Act No. 20069, Jan. 23, 2024) | 2022-06-10 | |
| Spain es 2 instruments | ||
| Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad, Cybersecurity Risk-Management MeasuresAnteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad, text approved by the Consejo de Ministros on 14 January 2025 (transposing Directive (EU) 2022/2555) | [proposed] | |
| Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad, Incident Reporting ObligationsAnteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad, text approved by the Consejo de Ministros on 14 January 2025 (transposing Directive (EU) 2022/2555) | [proposed] | |
| Real Decreto-ley 12/2018, Incident Notification ObligationReal Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de informacion, arts. 19, 21 y 22, developed by Real Decreto 43/2021, de 26 de enero | 2018-09-09 | |
| Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service ProvidersReal Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de informacion, art. 16, developed by Real Decreto 43/2021, de 26 de enero | 2018-09-09 | |
| Sweden se 2 instruments | ||
| Cybersäkerhetslag, Cybersecurity Risk-Management MeasuresCybersäkerhetslag (2025:1506), 2 kap. 3-4 §§ | 2026-01-15 | |
| Cybersäkerhetslag, Incident NotificationCybersäkerhetslag (2025:1506), 2 kap. 5-10 §§ | 2026-01-15 | |
| Tunisia tn 2 instruments | ||
| Cybersecurity Incident Reporting and Emergency ResponseDécret-loi n° 2023-17 du 11 mars 2023, relatif à la cybersécurité, Arts. 17-20, 24-25 | 2023-09-11 | |
| Mandatory Security Audit and Digital-Trust ClassificationDécret-loi n° 2023-17 du 11 mars 2023, relatif à la cybersécurité, Arts. 6-9, 14-16, 24-25 | 2023-09-11 | |
| Turkey tr 1 instrument | ||
| Cybersecurity Law, Reporting and Cooperation DutiesLaw No. 7545 (12 March 2025), Art. 7 | 2025-03-19 | |
| United Kingdom gb 1 instrument | ||
| Product Security Requirements for Connectable ProductsProduct Security and Telecommunications Infrastructure Act 2022, c. 46, Part 1; Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, SI 2023/1007 | 2024-04-29 | |
| United States us 1 instrument | ||
| SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05)17 CFR 229.106; 17 CFR 249.308 (Form 8-K Item 1.05) | 2023-12-18 | |
| Uzbekistan uz 3 instruments | ||
| Law on Cybersecurity, cybersecurity incident notification dutyLaw No. O'RQ-764 (15 April 2022) "On Cybersecurity," Arts. 3, 16, 22-24 | 2022-07-17 | |
| Law on Cybersecurity, general cybersecurity duties on cybersecurity subjectsLaw No. O'RQ-764 (15 April 2022) "On Cybersecurity," Arts. 3, 16, 37 | 2022-07-17 | |
| Law on Informatization, information security duty for information resource and system ownersLaw No. 560-II (11 December 2003) "On Informatization," Arts. 19-20 | 2004-02-11 | |
| Vietnam vn 2 instruments | ||
| Cybersecurity Law, Incident Response and Reporting DutiesLaw No. 116/2025/QH15 (Law on Cybersecurity), arts. 40(1)(c), 41(2)-(4) | 2026-07-01 | |
| Cybersecurity Law, Information System Classification and Protection MeasuresLaw No. 116/2025/QH15 (Law on Cybersecurity), arts. 8, 10 | 2026-07-01 | |
United States: states41 in 32 places
Law made below the national level, binding inside it. The slug beside each name says which tier it is.
| Stage | Instrument | In force from |
|---|---|---|
| Alabama us/al 1 instrument | ||
| Data Breach Notification Act, reasonable security measures and disposal of recordsAla. Code secs. 8-38-3, 8-38-10 | 2018-06-01 | |
| Alaska us/ak 1 instrument | ||
| Alaska Personal Information Protection Act, disposal of records dutyAlaska Stat. Secs. 45.48.500-45.48.590 | 2009-07-01 | |
| Arizona us/az 1 instrument | ||
| Discarding and disposing of records containing personal identifying informationA.R.S. sec. 44-7601 | 2005-01-01 | |
| Arkansas us/ar 1 instrument | ||
| Arkansas Personal Information Protection Act, reasonable security proceduresArk. Code Ann. section 4-110-104(b) | not recorded | |
| California us/ca 2 instruments | ||
| Customer Records Act, Reasonable Security ProceduresCal. Civ. Code section 1798.81.5, as amended by AB 825 (2021, Ch. 527) | 2022-01-01 | |
| Security of Connected DevicesCal. Civ. Code sections 1798.91.04-1798.91.06 (Title 1.81.26, added by Stats. 2018, Ch. 860 (AB 1906) and Ch. 886 (SB 327); sections 1798.91.04 and 1798.91.05 amended by Stats. 2022, Ch. 785 (AB 2392)) | 2023-01-01 | |
| Colorado us/co 2 instruments | ||
| Disposal of personal identifying information, written policy dutyC.R.S. 6-1-713 (amended by HB 18-1128, 2018 Colo. Sess. Laws ch. 266, section 1) | 2018-09-01 | |
| Protection of personal identifying information, reasonable security procedures dutyC.R.S. 6-1-713.5 (added by HB 18-1128, 2018 Colo. Sess. Laws ch. 266, section 2) | 2018-09-01 | |
| Connecticut us/ct 3 instruments | ||
| Adoption of cybersecurity controls by businesses, exemption from punitive damagesConn. Gen. Stat. sec. 42-901 | 2021-10-01 | |
| Connected device provider's duty to protect recorded personal information with reasonable security measuresPublic Act No. 25-44, Sec. 2(c) (2025) | 2026-07-01 | |
| Protection of Social Security Numbers and Personal Information Act, safeguarding and destruction dutyConn. Gen. Stat. sec. 42-471 | 2008-10-01 | |
| Delaware us/de 1 instrument | ||
| Computer Security Breaches, protection of personal informationDel. Code Ann. tit. 6, section 12B-100 | 2018-04-14 | |
| District of Columbia us/dc 1 instrument | ||
| Security requirements for personal information (Security Breach Protection Amendment Act of 2020)D.C. Code § [28-3852.01] (Title 28, Chapter 38, Subchapter II, "Security requirements," added by the Security Breach Protection Amendment Act of 2020, D.C. Law 23-98, § 2(a)(5), 67 DCR 3923) | 2020-06-17 | |
| Florida us/fl 1 instrument | ||
| Florida Information Protection Act, data security and disposal dutyFla. Stat. § 501.171(2), (8) | 2014-07-01 | |
| Georgia us/ga 1 instrument | ||
| Disposal of records containing personal informationO.C.G.A. Sec. 10-15-2 | not recorded | |
| Hawaii us/hi 1 instrument | ||
| Destruction of Personal Information RecordsHaw. Rev. Stat. Secs. 487R-1 to 487R-3 | 2007-01-01 | |
| Illinois us/il 2 instruments | ||
| Personal Information Protection Act, data security duty815 ILCS 530/45 (P.A. 99-503, eff. 2017-01-01) | 2017-01-01 | |
| Personal Information Protection Act, safe disposal of personal information815 ILCS 530/40 (P.A. 97-483, eff. 2012-01-01) | 2012-01-01 | |
| Indiana us/in 1 instrument | ||
| Disclosure of Security Breach Act, data base owner's duty to maintain reasonable security procedures and dispose of recordsInd. Code sec. 24-4.9-3-3.5 | [future] | |
| Iowa us/ia 1 instrument | ||
| Tort Liability for Cybersecurity Programs, affirmative defense for a reasonable security programIowa Code ch. 554G (554G.1 to 554G.4, added by 2023 Acts, ch. 63 (H.F. 553)) | 2023-07-01 | |
| Kansas us/ks 1 instrument | ||
| Kansas Consumer Protection Act, reasonable security and records-destruction duty for holders of personal informationK.S.A. 50-6,139b | 2016-07-01 | |
| Louisiana us/la 1 instrument | ||
| Database Security Breach Notification Law, reasonable security procedures and destruction dutyLa. R.S. 51:3074(A), (B) | 2006-01-01 | |
| Maryland us/md 1 instrument | ||
| Maryland Personal Information Protection Act (MPIPA), safeguards and secure-disposal dutyMd. Code Ann., Com. Law sections 14-3502, 14-3503 (Maryland Personal Information Protection Act, Title 14, Subtitle 35, added by 2007 Md. Laws ch. 531 (S.B. 194)) | 2008-01-01 | |
| Massachusetts us/ma 1 instrument | ||
| Standards for the Protection of Personal Information of Residents of the Commonwealth201 CMR 17.01-17.05 | 2010-03-01 | |
| Michigan us/mi 1 instrument | ||
| Identity Theft Protection Act, destruction of data no longer neededMCL 445.72a (Sec. 12a of Act 452 of 2004, added by 2006 PA 566) | 2007-07-02 | |
| Senate Bill 360 (2025-2026), Identity Theft Protection Act reasonable security procedures duty2025 S.B. 360, proposed MCL 445.71a and 445.85c (secs. 11a and 20c), as passed by the Senate | [proposed] | |
| Nebraska us/ne 1 instrument | ||
| Financial Data Protection and Consumer Notification of Data Security Breach Act, security procedures and practices dutyNeb. Rev. Stat. section 87-808 (added by Laws 2018, LB757, section 7) | 2018-07-19 | |
| Nevada us/nv 2 instruments | ||
| Security measures for a data collector accepting payment cards, encryption duty, and conditioned liability shieldNRS 603A.215 | [future] | |
| Security measures for data collectors maintaining personal informationNRS 603A.210 | [future] | |
| New Jersey us/nj 1 instrument | ||
| Identity Theft Prevention Act, methods of destruction of customer recordsN.J. Stat. Ann. § 56:8-162 (L. 2005, c.226, s.11) | 2006-01-01 | |
| New Mexico us/nm 1 instrument | ||
| Data Breach Notification Act, security and disposal dutiesNMSA 1978 Secs. 57-12C-3 to 57-12C-5 | [future] | |
| New York us/ny 1 instrument | ||
| Stop Hacks and Improve Electronic Data Security (SHIELD) Act, data security program dutyN.Y. Gen. Bus. Law section 899-bb (Article 39-F, added by L. 2019, ch. 117 (S5575-B/A5635-B), section 4) | 2020-03-21 | |
| North Carolina us/nc 1 instrument | ||
| Identity Theft Protection Act, destruction of personal information recordsN.C. Gen. Stat. section 75-64 (Chapter 75, Article 2A, added by S.L. 2005-414, s. 1) | 2005-12-01 | |
| Ohio us/oh 1 instrument | ||
| Ohio Data Protection Act, cybersecurity program safe harborOhio Rev. Code sections 1354.01 to 1354.05 (enacted by Senate Bill 220, 132nd General Assembly, effective November 2, 2018; section 1354.01 last amended by House Bill 66, 132nd General Assembly, effective April 5, 2019) | 2018-11-02 | |
| Oregon us/or 2 instruments | ||
| Oregon Consumer Information Protection Act, requirement to develop safeguards for personal informationORS 646A.622 (2007 c.759 sec. 12; amended 2015 c.357 sec. 3; 2018 c.10 sec. 6; 2019 c.180 sec. 4) | not recorded | |
| Security requirements for Internet-connected devicesORS 646A.813 (added by 2019 c.193 (H.B. 2395-A) sec. 1; amending ORS 646.607) | not recorded | |
| Rhode Island us/ri 1 instrument | ||
| Identity Theft Protection Act of 2015, risk-based information security programR.I. Gen. Laws secs. 11-49.3-2, 11-49.3-5 | [future] | |
| Texas us/tx 2 instruments | ||
| Cybersecurity Program safe harbor from exemplary damages (S.B. 2610)Tex. Bus. & Com. Code ch. 542 (secs. 542.001-542.004) | 2025-09-01 | |
| Identity Theft Enforcement and Protection Act, business duty to protect sensitive personal informationTex. Bus. & Com. Code sec. 521.052 | 2009-04-01 | |
| Utah us/ut 2 instruments | ||
| Cybersecurity Affirmative Defense ActUtah Code 78B-4-701 to 78B-4-704 | 2021-05-05 | |
| Protection of Personal Information Act, reasonable procedures and records-destruction dutyUtah Code 13-44-201 | 2019-05-14 | |
| Vermont us/vt 1 instrument | ||
| Document Safe Destruction Act, safe destruction of records containing personal information9 V.S.A. § 2445 (Added 2005, No. 162 (Adj. Sess.), § 1, eff. Jan. 1, 2007) | 2007-01-01 | |
What this page claims, and what it does not
The stages are LexLint's own vocabulary. Four of the five boxes are
the binding classes the /law/<jurisdiction> docket already
draws (In force, Enacted but not yet in force, Proposed, and Repealed,
withdrawn or blocked), so a square here and a square there mean the same
thing. A struck-down instrument is spent on both readings.
Enjoined has its own box. Inside "Repealed, withdrawn or blocked" it would sit beside a mark that is a false description of a law a court has paused, and it would pool away a count that reads as a signal: how contested a jurisdictional hook is. The certainty ladder files enjoined as present law and the docket draws it spent; splitting it out here makes that disagreement the reader's choice instead of our silent one. It is off by default, which follows the docket.
One date column, and where a bare date would mislead it says what kind
of date it is. "In force from" is commencement: the earlier of a
published commencement event and the instrument's own effective date, the
same choice lifecycle_band() makes and for the same reason,
neither source is reliably the commencement, and the earlier one cannot make
a law look newer than it is. A bracket qualifies the date where a bare one
would mislead ([future] for a start date still ahead,
[proposed] for a bill with no commencement to show,
[enjoined], [struck down], [repealed],
[superseded] or [withdrawn] for a spent
instrument). Nothing is inferred from our own review date: a row with
neither a date nor a status to explain the gap says "not recorded" instead.
The map is the table. Its fill is the count of instruments at the
stages you chose, binned on the same RAMP_BINS edges
/law/map uses, and it redraws on
every change. Point at, click, or tab to a place for what applies there,
every stage it holds shown even when your filter is excluding it.
Three ways of showing nothing, and they are different claims. A place washed pale holds cybersecurity law your filter is excluding, so widening the filter brings it back. A hatched place is one we track and hold no cybersecurity law for at all: that is a statement about our research, not about the law. A white place has no jurisdiction record for this topic at all. Only the first of the three moves when you change the filter; the other two are facts about us and hold still.
Nothing here needs the script. The default resultset is in the
HTML: counts, tally, map fills and the hidden rows are all rendered at
build. The script recomputes them when a box changes and does nothing else,
which is what lets this page ship under script-src 'self' and
be read whole by a crawler.