Bangladesh - Cyber Security Act (2023)
Cyber Security Act, 2023
সাইবার নিরাপত্তা আইন, ২০২৩
Bangladesh
RAI-BD-NA-CYBSE20-2023The Cyber Security Act, 2023 (Act No. 46 of 2023) is a comprehensive national law enacted by the Jatiya Sangsad to replace and consolidate provisions of the Digital Security Act, 2018 and related ICT provisions. It establishes institutional governance for cyber security, defines offences relating to cybercrime and critical information infrastructure, and sets out reporting, prevention, enforcement and penalty regimes.
Summary
The Cyber Security Act, 2023 (CSA) was enacted by the Parliament of Bangladesh on 13 September 2023 with the declared objective of ensuring digital security, identifying and protecting critical information infrastructure, preventing cyber offences, and prosecuting crimes committed through digital devices and networks. The Act renames and reforms the existing Digital Security Agency into a Cyber Security Agency (or equivalent body), creates or formalizes powers for a national regulator/competent authority responsible for implementing cyberspace protections, and provides a legal framework for the designation and protection of Critical Information Infrastructure (CII).
Key features include: a broad set of defined offences addressing illegal access, unauthorized interference, malware/hacking, cyber terrorism, interference with critical systems and services, and certain categories of harmful online content; obligations on public bodies and private operators to adopt cybersecurity measures, report incidents, and cooperate with the competent authority; provisions for registration, conformity assessment or certification of certain service providers or digital products where required; and rules on investigatory powers, takedown/cooperation orders and cross-institutional coordination. The Act includes enforcement mechanisms, administrative powers to issue directions, and criminal and civil penalties — including fines and, for a subset of serious offences, non-bailable provisions — aimed at deterring attacks on national infrastructure and maintaining public order in cyberspace.
The CSA drew substantial national and international attention: human rights and press freedom organizations raised concerns about broad or vague speech-related offences and the potential for misuse, while industry groups and cybersecurity stakeholders emphasized the need for clearer operational rules, incident reporting standards, and capacity building. The law also addresses emerging domain issues: it contemplates specific coverage for offences that use or abuse artificial intelligence tools, as well as requirements to protect personal data in the course of investigative and security operations, linking to the Data Protection and Digital Security policy space.
Following enactment, the CSA required implementing rules, administrative orders and standards to operationalize incident reporting, CII designation, and agency procedures. Government sources, legal trackers and the official legislation portal provide the full text and section-level detail. The law has been the subject of ongoing policy debate, proposed amendments and subsequent government action, and should be reviewed alongside any later ordinances, regulations or judicial decisions that affect interpretation and application.
Full article
Read full text ↗Overview
The Cyber Security Act, 2023 (Act No. 46 of 2023) was enacted by the Jatiya Sangsad on 13 September 2023 as part of a legislative overhaul of Bangladesh’s digital security framework. It replaces many operative provisions of the Digital Security Act, 2018 and consolidates cybercrime, critical information infrastructure protection and agency governance under a single statutory instrument. The Act establishes a national competent authority for cyber security (often referenced as the Cyber Security Agency) with investigatory, supervisory and directive powers and sets out offences, penalties and compliance duties for public and private entities. The full official text and consolidated copy are available on government legal repositories such as the national legislation portal and the laws database; see the official law text and legislative citation at legislative division PDF of the Cyber Security Act, 2023 and the laws portal entry at Laws of Bangladesh – Cyber Security Act (Act No. 46 of 2023).
Definitions
The Act defines core terms used throughout the text, including "critical information infrastructure" (CII), "cyber security incident", "service provider", "computer system" and "unauthorised access." Definitions are broad and purpose-driven: CII is described by reference to sectors and services essential to national functions (energy, communications, finance, health, utilities), and an incident is defined to include theft, modification, deletion, denial-of-service, and other unauthorized acts affecting confidentiality, integrity and availability. The Act also adopts an expansive definition of digital devices and networks to capture cloud, IoT, and infrastructure providers.
Governance and Institutional Framework
The CSA creates or reconstitutes a central supervisory body—referred to in the Act as the Cyber Security Agency—and empowers it to identify CII, issue mandatory directions, coordinate incident response, conduct audits, and prescribe standards. The Agency’s remit includes issuing guidance to public sector departments and private operators, maintaining a national incident response capability, and liaising with law enforcement and intelligence agencies. The law sets out appointment and oversight mechanisms for agency leadership, and contemplates inter-ministerial coordination with the Ministry of Posts, Telecommunications and Information Technology and the Ministry of Law, Justice and Parliamentary Affairs. Implementation duties include capacity-building, national exercises, and maintenance of a CIRT (computer incident response team) function; see the Agency’s public pages for operational updates: National Cyber Security Agency (NCSA).
Key Focus Areas
The Act concentrates on five key policy areas: (1) Protection of Critical Information Infrastructure (CII) – designation processes, mandatory resilience measures, and recovery planning; (2) Cybercrime – criminalizing unauthorized access, sabotage, data breaches, malware distribution, hacking, identity-related offences and cyberterrorism; (3) Incident reporting and mandatory cooperation – timelines for reporting breaches to the Agency and CIRT and duties to preserve forensic evidence; (4) Regulation of service providers and conformity assessment – powers to require registration, certification and technical audits for specific classes of providers and digital products; and (5) Safeguards and rights – procedural protections for suspects and limits on agency powers, together with limited provisions addressing data protection and judicial oversight. The law also touches on content offences where digital acts intersect with national security and public order, drawing criticism from rights groups for perceived breadth.
Implementation Framework
Operationalizing the CSA requires secondary legislation, agency rules, standards and technical guidelines. The Act authorizes the Agency to issue rules on incident reporting forms and timelines, classification criteria for CII, minimum security controls (patching, logging, encryption, access control), and standards for forensic evidence preservation. The law envisages a mixture of administrative orders, binding directions and sector-specific codes developed with relevant ministries, regulators (like the Bangladesh Telecommunication Regulatory Commission and Bangladesh Bank for the financial sector) and private stakeholders. Implementation priorities typically include (a) CII mapping, (b) baseline technical security standards, (c) incident reporting channels and SLAs, and (d) compliance timelines for different classes of entities.
Monitoring and Evaluation
The Act mandates periodic reviews, reporting and audits. The Agency must maintain an incident registry, publish summary reports on national cyber threats and compliance activities, and conduct audits of designated CII operators. There are requirements for internal oversight and external review mechanisms to ensure the Agency’s actions align with legal limits; the law also contemplates cooperation with international partners and information-sharing arrangements to enhance threat intelligence and to benchmark national metrics against global best practice.
Penalties, Liability, and Appeals
The CSA sets a range of administrative, civil and criminal penalties: fines, orders to remediate, suspension of services, and imprisonment for certain offences. A subset of offences deemed most serious (for example cyber terrorism, large-scale sabotage of CII, and severe hacking of national systems) are treated as non-bailable in line with the Act’s public-order rationale. The law provides rights of appeal against administrative orders and specifies procedural routes for judicial review of agency actions. It also contains provisions for compensation and liability where negligence leads to demonstrable harm, and mechanisms for withdrawing or amending agency directions on appeal.
Relationship to Other Instruments
The CSA expressly amends and replaces parts of the Digital Security Act, 2018 and incorporates relevant sections of the Information and Communication Technology Act, 2006 as consolidated in national law. It provides cross-references to sectoral regulators (telecom, banking, energy) and contemplates MoUs and memoranda of cooperation to align enforcement. Where other laws (data protection, telecommunications, criminal procedure) apply, the CSA sets out primacy in matters of national cyber security while preserving fundamental procedural safeguards embodied in the constitution and criminal procedure laws.
International Alignment
The Act acknowledges the need for international cooperation: it empowers the Agency to enter into mutual assistance arrangements, exchange cyber-threat intelligence, and participate in cross-border investigations. The law references international best practice principles (cooperation, proportionality, and respect for privacy) and invites alignment with global frameworks on incident response and critical infrastructure protection. Stakeholders have urged harmonization with international human rights standards and data-protection norms.
Implementation Timeline
| Milestone | Target/Date |
|---|---|
| Parliamentary enactment | 13 September 2023 |
| Commencement (law in force) | 13 September 2023 |
| Agency reconstitution and initial rules | Drafting and issuance: months after commencement (sectoral timelines set by Agency) |
| CII designation first tranche | Initial period set by Agency (commonly within 3–12 months) |
Sources and References
| Source | Type |
|---|---|
| Cyber Security Act, 2023 - Laws of Bangladesh (Act No. 46 of 2023) | Primary Source |
| Legislative Division PDF: Cyber Security Act, 2023 | Primary Source |
| National Cyber Security Agency (NCSA) – official site | Primary Source |
Requirements for a company
What an organisation has to do under Bangladesh - Cyber Security Act (2023), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
11- Implement mandatory resilience measures for critical functions.Operators of Critical Information Infrastructure (CII).
- Develop and maintain recovery planning for critical functions.Operators of Critical Information Infrastructure (CII).
- Report cyber security breaches to the Cyber Security Agency and CIRT.Entities experiencing cyber security incidents.
- Preserve forensic evidence related to cyber incidents.Entities experiencing cyber security incidents.
- Register with the Cyber Security Agency if required for specific services.Specific classes of service providers and digital product providers.
- Obtain certification if required by the Cyber Security Agency.Specific classes of service providers and digital product providers.
- +5 more in the table below
Must not do
0Nothing in this category.
Should do
2- Develop an incident response plan.All service providers (recommended).
- Designate a reporting officer for cyber incidents.All service providers (recommended).
Should not do
0Nothing in this category.
Who must do what
The obligations under Bangladesh - Cyber Security Act (2023), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Operators of Critical Information Infrastructure (CII). | Implement mandatory resilience measures for critical functions. “Protection of Critical Information Infrastructure (CII) – designation processes, mandatory resilience measures, and recovery planning” | — | — | Critical |
| 2 | Operators of Critical Information Infrastructure (CII). | Develop and maintain recovery planning for critical functions. “Protection of Critical Information Infrastructure (CII) – designation processes, mandatory resilience measures, and recovery planning” | — | — | Critical |
| 3 | Entities experiencing cyber security incidents. | Report cyber security breaches to the Cyber Security Agency and CIRT. “timelines for reporting breaches to the Agency and CIRT and duties to preserve forensic evidence” | As per Agency timelines | — | Critical |
| 4 | Entities experiencing cyber security incidents. | Preserve forensic evidence related to cyber incidents. “timelines for reporting breaches to the Agency and CIRT and duties to preserve forensic evidence” | For the statutory period | — | Critical |
| 5 | Specific classes of service providers and digital product providers. | Register with the Cyber Security Agency if required for specific services. “powers to require registration, certification and technical audits for specific classes of providers and digital products” | — | — | Critical |
| 6 | Specific classes of service providers and digital product providers. | Obtain certification if required by the Cyber Security Agency. “powers to require registration, certification and technical audits for specific classes of providers and digital products” | — | — | Critical |
| 7 | Specific classes of service providers and digital product providers. | Undergo technical audits if required by the Cyber Security Agency. “powers to require registration, certification and technical audits for specific classes of providers and digital products” | — | — | Critical |
| 8 | Entities subject to Agency rules, especially CII operators. | Implement minimum security controls, including patching, logging, encryption, and access control. “minimum security controls (patching, logging, encryption, access control)” | — | — | Critical |
| 9 | Entities subject to Cyber Security Agency orders. | Remediate identified security deficiencies when ordered by the Agency. “fines, orders to remediate, suspension of services” | — | — | Critical |
| 10 | Operators of Critical Information Infrastructure (CII). | Develop an incident response plan. “Is there an incident response plan and designated reporting officer? Obligatory for CII” | — | — | Critical |
| 11 | Operators of Critical Information Infrastructure (CII). | Designate a reporting officer for cyber incidents. “Is there an incident response plan and designated reporting officer? Obligatory for CII” | — | — | Critical |
| 12 | All service providers (recommended). | Develop an incident response plan. “Is there an incident response plan and designated reporting officer? recommended for all providers” | — | — | Recommended |
| 13 | All service providers (recommended). | Designate a reporting officer for cyber incidents. “Is there an incident response plan and designated reporting officer? recommended for all providers” | — | — | Recommended |
Related Regulations
© Regulations.AI · updated on 13-Jun-2026