Chile - Qualification of Vital Operators (285/2025)

Supreme Decree No. 285 (Regulation) — Qualification Procedure for Vital Importance Operators under the Cybersecurity Framework Law (Law 21.663)

Decreto Supremo N° 285 (Reglamento) — Procedimiento de calificación de Operadores de Importancia Vital en el marco de la Ley Marco de Ciberseguridad (Law 21.663)

Chile

RAI-CL-NA-DSN2RXX-2025
Effective: March 13, 2025
In Force(In Force)
DecreeGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

Decree No. 285 (2024) approves the regulation that sets out the procedure by which the Agencia Nacional de Ciberseguridad (ANCI) qualifies certain providers of essential services as Operators of Vital Importance (OIV) under Law No. 21.663. It defines criteria, procedural steps (including preliminary lists, public consultation for private entities), timelines and review mechanisms (at least every three years) for OIV qualification.

Overview

Decreto Supremo N° 285 (signed 6 September 2024; published in the Diario Oficial on 13 March 2025) approves the "Reglamento del Procedimiento de Calificación de los Operadores de Importancia Vital" under Law N° 21.663 (the Chilean Cybersecurity Framework). The Regulation operationalizes Article 5 and Article 6 of Law 21.663 by establishing the criteria and the step-by-step administrative process ANCI must follow to classify providers of essential services as Operators of Vital Importance (OIV). The regulation is reproduced in the Chilean legislative repositories; see the full text at the Biblioteca del Congreso Nacional (BCN) reproduction of the decree: Decree No. 285 (BCN). The instrument is intended to be applied with the principles of proportionality, graduality and transparency and links to other instruments implementing the Law (e.g., incident-reporting and ANCI internal-organization decrees).

Definitions

The Regulation clarifies key terms used in the qualification process. "Agency" refers to the Agencia Nacional de Ciberseguridad (ANCI). "Dependence" means an operational dependency between operators where one cannot provide its service without a good or service from another operator. "Monoprovision" denotes situations where a single provider delivers an essential service and no immediate replacement exists. "Redundancy" describes the existence of alternative providers able to substitute a service immediately. The decree expressly ties these definitions to the assessment of significant impact: ANCI must examine these and other criteria to evaluate whether an interruption or compromise of services would produce significant consequences for public order, security or the continuity of essential services.

Governance and Institutional Framework

The Regulation assigns ANCI central responsibility for initiating, directing and deciding qualification processes. It requires ANCI to coordinate with sectoral regulators and other public agencies and to act under the administrative rules of Law N° 19.880. The decree explicitly references Chile's digital-administration rules (e.g., DFL N°1/2020 and DS N°4/2020) for the use of electronic procedures and establishes transitional rules for notifications where the full digital notification regime is not yet applicable. The Regulation situates the OIV qualification within broader national cyber governance instruments, such as the National Cybersecurity Policy 2023–2028, and complements other decrees issued under Law 21.663. For the official text and institutional references see BCN Decreto N°285 and commentary at Diario Constitucional.

Key Focus Areas

The Regulation focuses on: (1) objective qualification criteria (dependence on IT systems and significant impact), (2) evidentiary requirements and inter-agency reports (ANCI may request sectoral regulators to provide lists and technical inputs), (3) a multi-stage administrative procedure (preliminary list, notification, public consultation for private entities, final list and reasoned resolution), (4) rights of affected entities (notification, opportunity to present observations and supporting evidence), and (5) periodic review (ANCI must review OIV status at least every three years; interim reviews are possible for changed circumstances). The decree sets detailed process timings drawn from Law N° 19.880 and prescribes principles of transparency and maximum disclosure for the public consultation stage. For background on how the first processes were executed under DS N°285 see ANCI actions referenced in the BCN repository and summaries at BCN — Resolution references.

Implementation Framework

Operational steps: ANCI requests reports from sectoral regulators; within a defined timeframe (established in the Regulation and consistent with Law 19.880), ANCI prepares a preliminary list of institutions that could qualify. If the preliminary list includes private institutions, that list must be published and submitted to a public consultation (30 days as indicated in ANCI implementing resolutions). The Regulation mandates that entities on the preliminary list be notified individually and be allowed to submit observations and documents. After considering comments, ANCI issues a final list and a reasoned resolution naming the entities classified as OIV. The Regulation also sets out rules for the form of notifications (electronic where applicable; otherwise certified mail) and for the content of administrative records. See the reproduced text at BCN Decreto N°285 for procedural wording.

Monitoring and Evaluation

ANCI must review and update OIV classifications at least once every three years, but may open ad-hoc reviews when circumstances change (e.g., major systemic incidents, emergence of new service dependencies, or structural market changes). The Regulation requires ANCI to maintain administrative records supporting each qualification decision and sets out requirements for interagency information exchange. Implementation monitoring is expected to be operationalized through ANCI resolutions, platform tools for reporting and registry systems. The regulation foresees that the ANCI will issue further instructions and guidelines (e.g., Instrucciones Generales) to operationalize aspects like templates, indicators and reporting channels.

Penalties, Liability, and Appeals

While the Regulation focuses on procedure, it reiterates that sanctions for non-compliance derive from Law N° 21.663 (which establishes a graduated sanctioning regime with fines in UTM and administrative measures). The decree references Law 21.663’s framework for classifying infractions as light, serious and very serious and for applying higher maxima for operators of vital importance. The Regulation confirms that enforcement and sanctioning powers remain with ANCI and that affected entities may exercise administrative remedies established in Law N° 19.880 (reposición, reconsideración and other administrative routes), and judicial remedies foreseen in the law (e.g., judicial review before competent courts). For the Law’s sanctions framework consult the legislative record: BCN — Law 21.663 history and sanction summary.

Relationship to Other Instruments

DS N°285 sits within a family of secondary rules implementing Law 21.663: it complements the Decree regulating incident reporting, the Decree setting ANCI’s internal structure and decrees on the interministerial committee and multisector council. DS N°285 is administrative-procedural in nature and designed to be used alongside ANCI resolutions (e.g., those initiating qualification rounds and approving preliminary lists or calendars). The decree also integrates with Chile’s transformation-digital rules (DFL N°1/2020 and DS N°4/2020) that regulate electronic procedures and notifications. See consolidated references in legislative repositories: Decree text and the UdeC summary of related decrees at UdeC decrees list.

International Alignment

DS N°285 reflects internationally recognized approaches to critical infrastructure and essential service classification: it uses a risk- and impact-based approach and procedural safeguards rather than an automatic sectoral capture model. This resembles versions of the EU NIS2 approach (impact-based classification plus sectoral focus) while keeping a declaratory model where a national authority (ANCI) issues designations. The Regulation’s emphasis on interdependency analysis, redundancy and monoprovision is consistent with international frameworks such as NIST’s Cybersecurity Framework and OECD recommendations on critical infrastructure protection. For comparative context see commentaries linking Chilean implementation to international frameworks at Diario Constitucional analysis.

Implementation Timeline

EventDate
Decree signed2024-09-06
Decree published in Diario Oficial / Effective date2025-03-13
Start of first qualification process (ANCI Resolution)2025-05-30 (ANCI Resolution Exenta N°24 — process initiation reported in BCN records)
Publication of preliminary lists and public consultation (first cycle)2025-09-16 (preliminary list publication and consultation referenced in subsequent ANCI acts)
Periodic review requirementEvery 3 years from designation

Compliance Checklist

ActionResponsibleNotes/Deadline
Determine whether your service is classified as a Service EssentialEntity / Legal Dept.Immediate
Monitor ANCI communications (preliminary lists)Entity / CISODuring qualification cycles
Respond to notification / submit observationsEntity / Legal & SecurityWithin consultation period (30 days for private entities as per Regulation/ANCI practice)
Prepare evidence of redundancy and dependency mappingIT & Risk TeamsPre-notification and on request
Prepare to comply with OIV obligations if designatedBoard, CISOUpon final designation

Sources and References

SourceType
Decree No. 285 — "Aprueba Reglamento del Procedimiento de Calificación de los Operadores de Importancia Vital" (BCN reproduction)Primary Source
vLex reproduction of Decreto N° 285 (Diario Oficial publication details)Secondary Source
Diario Constitucional — legal commentary on the RegulationSecondary Source
Plain English

Chile's new regulation, effective March 13, 2025, establishes the official process for the National Cybersecurity Agency (ANCI) to identify and designate certain essential service providers as "Operators of Vital Importance" (OIVs) under the country's Cybersecurity Framework Law.

This applies to both public and private organizations that provide services deemed essential, where an interruption or compromise could severely impact public order, national security, or the continuity of other critical services. ANCI will assess potential OIVs based on objective criteria, including their dependence on IT systems, the operational reliance of other services on them, whether they are a sole provider (monoprovision), and the lack of immediate alternative providers (redundancy).

The qualification process is multi-staged and transparent. ANCI will first gather information from sectoral regulators to create a preliminary list of potential OIVs. If your organization is on this list, ANCI will notify you directly. For private entities, this preliminary list will also be published for public consultation, allowing affected organizations to submit observations and evidence – for example, demonstrating existing redundancies or lesser impact. After reviewing all input, ANCI will issue a final, reasoned decision designating OIVs.

While this regulation details the *how* of designation, it's crucial to understand that being classified as an OIV brings significant cybersecurity obligations under the broader Cybersecurity Framework Law. Non-compliance with these obligations can lead to substantial fines, which are higher for OIVs, and other administrative measures enforced by ANCI. Organizations have rights to appeal these decisions. ANCI is also required to review OIV designations at least every three years, meaning your status isn't permanent and can change based on evolving circumstances.

A key takeaway is that the public consultation phase for private entities means your organization could be publicly identified as a potential OIV before a final decision is made. This underscores the importance of proactively understanding your service's criticality and preparing documentation regarding your operational dependencies and redundancies, rather than waiting for ANCI's notification.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

© Regulations.AI — created on 13-Jun-2026