Chile - Cybersecurity Framework Law (21.663)
Law No. 21.663 — Framework Law on Cybersecurity and Critical Information Infrastructure
Ley N° 21.663 — Ley Marco de Ciberseguridad
Chile
RAI-CL-NA-LN2LMXX-2024Ley N° 21.663 establishes a national framework for cybersecurity and protection of critical information infrastructure in Chile. It creates the National Cybersecurity Agency (Agencia Nacional de Ciberseguridad, ANCI), sets duties for public entities and private operators that provide essential services, requires incident reporting to a national CSIRT, and establishes an enforcement and sanctioning regime.
Summary
Ley N° 21.663 — the Framework Law on Cybersecurity and Critical Information Infrastructure — creates a cross‑sectoral legal framework to organize Chile's national cybersecurity governance, set baseline obligations for public and private actors, and protect critical information infrastructure and essential services. Promulgated and published in the Diario Oficial on 8 April 2024, the law provides for the establishment of the Agencia Nacional de Ciberseguridad (ANCI) as the central national authority with powers to coordinate policy, classify and supervise Operators of Vital Importance (Operadores de Importancia Vital — OIV), operate or designate a national CSIRT, issue binding regulations and instructions, and apply administrative sanctions for breaches. The statute defines key concepts (incidents, assets, CSIRT, risk, vulnerability, availability, confidentiality, integrity, etc.) and articulates general principles such as security-by-design, proportionality, cooperation with authorities, protection of fundamental rights and the duty to minimize damage.
The law distinguishes between (a) services that are considered essential for the functioning of the country (services essential to public order, health, national security, supply chains, financial stability, etc.) and (b) Operators of Vital Importance, which the ANCI may designate based on dependency on IT systems and potential consequences of incidents. Entities that provide essential services or that are qualified as OIV are subject to enhanced obligations, which typically include implementing minimum security measures and risk‑management practices, maintaining incident response capabilities (including CSIRTs), conducting periodic audits or security assessments, appointing responsible points of contact, and complying with mandatory reporting timelines for incidents with significant effects. The law imposes graduated sanctions, including substantial administrative fines and operational restrictions for serious or repeated breaches, and contemplates administrative procedures and appeal mechanisms.
Implementation of the law has been staged: a DFL and implementing instruments were published in late 2024 that fixed the ANCI's personnel regime and initiated the agency’s activity; most general provisions entered into force on 1 January 2025, while specific rules on OIV classification, enhanced OIV duties, mandatory incident reporting and the sanctioning regime were phased in later (notably 1 March 2025). The ANCI has begun issuing implementing regulations and general instructions (for example, an Instrucción General requiring registration of entities that provide essential services in the ANCI incident portal, published in mid‑2025). The law is designed to interoperate with existing legal frameworks (criminal law on computer crimes, sectoral regulation, and data protection obligations) and to align Chile’s approach with international cybersecurity norms and cooperative mechanisms. The law therefore represents a structural modernization of Chile’s national cyber governance, introducing centralized coordination, mandatory reporting and compliance duties for sectors considered essential to national functioning.
Full article
Read full text ↗Overview
Ley N° 21.663 (the "Framework Law on Cybersecurity and Critical Information Infrastructure") sets out Chile's basic legal architecture for national cybersecurity. Promulgated and published in the Diario Oficial (8 April 2024), the law establishes the Agencia Nacional de Ciberseguridad (ANCI) as the coordinating authority, creates a multisectoral council and an interministerial committee, and mandates the operation of national and sectoral CSIRTs. The legislation identifies "essential services" and empowers ANCI to designate Operators of Vital Importance (OIV). It sets minimum prevention, detection and response requirements, incident‑reporting obligations, and an administrative sanctions framework for noncompliance. Implementation was staged by subsequent regulatory acts and a DFL that fixed ANCI's organizational start-up; most provisions took effect on 1 January 2025, with specific OIV duties, mandatory reporting and the sanctioning title entering later on 1 March 2025. Key official references and implementing instruments are available from the national legislative archive and from ANCI's official site.
Definitions
The law supplies core definitions used throughout the framework: "cybersecurity" (measures and practices to protect networks, systems and information), "incident of cybersecurity" (any event that compromises confidentiality, integrity or availability), "activo informático" (IT asset), "red or system" (networks, hardware and software), "CSIRT" (computer security incident response team), "risk" and "vulnerability", "operator of vital importance" (OIV), and "essential service". These definitions anchor obligations, reporting triggers and classification procedures and are designed to be technology‑neutral while enabling sectoral specificity by regulation.
Governance and Institutional Framework
The law creates a multi‑layer governance architecture. The core institution is the Agencia Nacional de Ciberseguridad (ANCI), which has policy, coordination, supervisory and sanctioning powers over the national cybersecurity system. Complementing the agency, the law establishes a Council of Multisectoral Stakeholders (a consultative council bringing government, industry and civil society actors together) and a Committee of Interministerial Coordination to align public administration actions. ANCI is empowered to: (i) issue binding norm‑setting instruments and instructions to entities that provide essential services, (ii) operate or accredit a national CSIRT and sectoral CSIRTs, (iii) determine criteria for classifying OIVs, (iv) maintain a national incident reporting platform and registry, and (v) supervise compliance and impose administrative sanctions. The DFL and subsequent regulations set the agency's start of operations (1 January 2025) and detail temporary organizational measures for initial appointments and staffing.
Key Focus Areas
The law concentrates on several interlinked domains: governance and oversight (centralization of coordination in ANCI, council and committee mechanisms), risk management (minimum security requirements and the promotion of risk‑based security practices), incident detection and reporting (mandatory timelines and reporting channels to the CSIRT Nacional), resilience and continuity of essential services (preparation, business continuity planning and contractual obligations), and accountability (documentation, audits and compliance programs). The statute distinguishes baseline duties for all state bodies and private providers of essential services and enhanced duties for OIVs — including more rigorous controls, mandatory audits and reporting to the national CSIRT for incidents that have significant effects. It also includes provisions to protect sensitive information and fundamental rights when the ANCI or CSIRTs process incident data, balancing transparency and confidentiality.
Implementation Framework
Implementation relies on ANCI's regulatory instruments (regulations, general instructions and technical standards) and interagency collaboration. A Decreto con Fuerza de Ley (DFL) and subsequent regulatory acts published in late 2024/early 2025 fixed the agency's plant and start date and staged the law's entry into force: the agency began activities on 1 January 2025, with most general obligations effective then; articles concerning OIV classification, OIV‑specific duties and mandatory incident reporting (Articles 5, 8, 9 and Title VII) became effective on 1 March 2025. ANCI has been granted authority to require registration of essential service providers in a national portal and to publish technical guidance and minimum cybersecurity measures. Implementing rules also define reporting thresholds, timelines, authentication requirements for registry access and the administrative procedure for classification and sanctions.
Monitoring and Evaluation
The law requires ANCI to monitor compliance and to publish guidance on performance metrics, incident trends, and national risk assessments. Monitoring tools include mandatory reporting, sectoral CSIRTs' situation reports, periodic audits, and a centralized incident registry. The law anticipates an evidence‑based evaluation cycle: ANCI will analyze incidents and sectoral vulnerabilities, prepare national risk assessments, recommend updates to minimum measures, and report to the executive and legislative branches. The multisectoral council provides a forum to review outcomes and adjust policy priorities. Monitoring is designed to inform continuous improvement while protecting reserved or sensitive information.
Penalties, Liability, and Appeals
Title VII establishes an administrative regime of infringements and sanctions that can apply to public entities and private providers subject to the law. Sanctions are graduated according to the gravity of the breach and may include fines (ranges differ by size and category of entity, with notably higher maximum fines for Operators of Vital Importance), corrective orders, operational restrictions, and temporary measures to protect continuity of services. The law preserves procedural safeguards: administrative decisions are subject to due process, motivated resolutions, remedies and appeals under the administrative procedure rules; criminal liability for computer crimes remains governed by the penal code and related statutes where conduct constitutes an offence.
Relationship to Other Instruments
The law is intended to integrate with Chile's existing legal framework: it operates alongside sectoral regulatory regimes (energy, telecoms, finance, health), data protection rules, and criminal provisions for computer crimes. Implementing regulations and interagency agreements clarify overlaps and coordination mechanisms. Where sectoral regulators already have cybersecurity rules, ANCI's role is coordination and supervision of cross‑cutting obligations, with ANCI empowered to issue binding instructions when national cybersecurity interests require harmonization. The law also foresees cooperation with law enforcement and national intelligence under prescribed safeguards.
International Alignment
Although domestically focused, the law aligns Chile with international cyber resilience best practices by centralizing national coordination, adopting risk‑based obligations, and mandating incident reporting and CSIRT operation — measures consistent with widely recognized standards and frameworks (e.g., NIS‑style national coordination and CSIRT arrangements). The ANCI is empowered to enter into cooperation agreements with foreign counterparts, to participate in international incident exchange and capacity‑building efforts, and to incorporate international technical standards into its guidance and instructions.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Publication in Diario Oficial | 2024-04-08 | Official promulgation and publication of Ley N° 21.663. Source: Diario Oficial (Colegio de Abogados). |
| DFL fixing ANCI plant & start | 2024-12-24 | Decree with force of law fixes ANCI's personnel, establishes agency start date (1 Jan 2025) and phases for certain provisions. |
| Most provisions enter into force | 2025-01-01 | General obligations and ANCI operation start. |
| OIV duties, reporting & sanctions effective | 2025-03-01 | Article 5, 8, 9 and Title VII phased in (classification of OIVs, OIV obligations, mandatory reporting and sanctioning regime). |
| ANCI Instrucción General N°1 (registration) | 2025-06-11 | Instruction requiring registration of essential service providers in ANCI portal (published 2025-06-04; effective 5th business day thereafter). |
Sources and References
| Source | Type |
|---|---|
| Biblioteca del Congreso Nacional — legislative balance for Ley 21.663 | Primary Source |
| Diario Oficial publication (Colegio de Abogados mirror of the Diario Oficial entry) | Primary Source |
| Agencia Nacional de Ciberseguridad (ANCI) — official site (norms and guidance) | Primary / Implementing Authority |
| Diario Constitucional — commentary and entry‑into‑force details | Secondary / Analysis |
Requirements for a company
What an organisation has to do under Chile - Cybersecurity Framework Law (21.663), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
9- Determine if your organization provides an essential service or may be designated an Operator of Vital Importance.All organizations potentially providing essential services in Chile.
- Register as an essential service provider in the ANCI national portal.Essential service providers.
- Comply with binding norms and instructions issued by the National Cybersecurity Agency (ANCI).Entities providing essential services.
- Report cybersecurity incidents to the national CSIRT within mandatory timelines.Public entities and private operators providing essential services.
- Implement minimum prevention, detection, and response cybersecurity requirements.Public entities and private operators providing essential services.
- Implement more rigorous cybersecurity controls if designated an Operator of Vital Importance (OIV).Operators of Vital Importance (OIVs).
- +3 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Chile - Cybersecurity Framework Law (21.663), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | All organizations potentially providing essential services in Chile. | Determine if your organization provides an essential service or may be designated an Operator of Vital Importance. “The legislation identifies "essential services" and empowers ANCI to designate Operators of Vital Importance (OIV).” | Before 2025-03-01 | Article 5 | Critical |
| 2 | Essential service providers. | Register as an essential service provider in the ANCI national portal. “ANCI Instrucción General N°1 (mandatory registration in national portal) – effective date.” | Jun 11, 2025 | — | Critical |
| 3 | Entities providing essential services. | Comply with binding norms and instructions issued by the National Cybersecurity Agency (ANCI). “ANCI is empowered to: (i) issue binding norm‑setting instruments and instructions.” | Ongoing | Governance and Institutional Framework | Critical |
| 4 | Public entities and private operators providing essential services. | Report cybersecurity incidents to the national CSIRT within mandatory timelines. “mandatory timelines and reporting channels to the CSIRT Nacional.” | Mar 1, 2025 | Articles 8, 9 | Critical |
| 5 | Public entities and private operators providing essential services. | Implement minimum prevention, detection, and response cybersecurity requirements. “It sets minimum prevention, detection and response requirements.” | Jan 1, 2025 | — | Critical |
| 6 | Operators of Vital Importance (OIVs). | Implement more rigorous cybersecurity controls if designated an Operator of Vital Importance (OIV). “enhanced duties for OIVs — including more rigorous controls.” | Mar 1, 2025 | Article 5 | Critical |
| 7 | Public entities and private providers of essential services. | Promote and implement risk-based cybersecurity practices. “promotion of risk‑based security practices.” | Jan 1, 2025 | — | Important |
| 8 | Public entities and private providers of essential services. | Prepare and implement business continuity plans to ensure resilience and continuity of essential services. “resilience and continuity of essential services (preparation, business continuity planning and contractual obligations).” | Jan 1, 2025 | — | Important |
| 9 | Public entities and private providers of essential services, especially OIVs. | Maintain cybersecurity documentation and conduct periodic audits. “accountability (documentation, audits and compliance programs).” | Ongoing | — | Important |
Related Regulations
Decreto Supremo N° 285 (Reglamento) — Procedimiento de calificación de Operadores de Importancia Vital en el marco de la Ley Marco de Ciberseguridad (Law 21.663)
Chile93% similar
Instrucción General N°1 (Agencia Nacional de Ciberseguridad, ANCI) — Inscripción de prestadores de servicios esenciales en la Plataforma de Reporte de Incidentes
Chile92% similar
Law No. 21.719 — Regulates the protection and processing of personal data and creates the Personal Data Protection Agency
Chile90% similar
Loi n° 05-20 relative à la cybersécurité
Morocco88% similar
Decreto N° 662/2025 — Reglamento que regula los Modelos de Prevención de Infracciones (Regulation for Prevention Models under Law 21.719)
Chile88% similar
© Regulations.AI · updated on 13-Jun-2026