Maldives - Cyber Security Act (17/2023)
Cyber Security Act
ސައިބަރ ސެކިއުރިޓީގެ ޤާނޫނު
Maldives
RAI-MV-NA-1720230-202317/2023
A national framework establishing the Maldives' Cyber Security Agency and standards for protecting critical information infrastructure.
Summary
The Cyber Security Act (Law No. 17/2023) establishes a comprehensive legal framework for the Maldives to protect critical information infrastructure and manage cyber threats. It creates the National Cyber Security Agency (NCSA) to oversee national security standards and incident response.
Full article
Read full text ↗Overview
The Cyber Security Act (Law No. 17/2023) represents a landmark legislative milestone for the Republic of Maldives, establishing a comprehensive legal framework to safeguard the nation's digital ecosystem. Ratified by President Ibrahim Mohamed Solih on November 14, 2023, the Act was developed in response to the increasing frequency and sophistication of cyber threats targeting both public and private sector infrastructure. As the Maldives continues its rapid digital transformation, particularly within its tourism, finance, and administrative sectors, the government identified a critical need for centralized oversight and standardized security protocols. The Act serves as the primary instrument for defining national cyber security standards, protecting critical information infrastructure (CII), and ensuring the resilience of essential services against malicious digital activities. This legislation is a core pillar of the Maldives' broader digital strategy, aligning the country with international best practices in cyber governance and incident response. The geographical dispersion of the Maldives' islands makes digital connectivity essential for governance and commerce, making the security of these networks a matter of existential importance for the state's functionality. By codifying these protections, the government aims to build trust in the digital economy and attract foreign investment in the technology sector.
Definitions
The Act provides precise legal definitions for several key terms that form the basis of its regulatory scope. 'Cyber Security' is broadly defined as the protection of information systems, networks, and the data stored therein from unauthorized access, use, disclosure, disruption, modification, or destruction. This definition ensures that the law covers both the physical hardware and the intangible data assets that constitute the digital landscape. Another pivotal term is 'Critical Information Infrastructure' (CII), which refers to those computer systems or networks whose destruction or incapacitation would have a debilitating impact on national security, the economy, public health, or safety. The identification of CII is a dynamic process managed by the newly established regulatory authority, ensuring that the most vital sectors receive the highest level of protection. Furthermore, the Act defines 'Cyber Incident' as any event that jeopardizes the confidentiality, integrity, or availability of information or information systems. This definition is intentionally broad to encompass everything from minor data breaches to large-scale distributed denial-of-service (DDoS) attacks. 'Service Providers' are defined to include any entity providing electronic communication services or processing data on behalf of others, bringing a wide array of private sector actors under the Act's regulatory umbrella. These definitions are crucial for the judicial interpretation of the law, providing clarity for compliance officers and legal practitioners when determining the applicability of specific provisions to various technological contexts.
Governance and Institutional Framework
The centerpiece of the Act's institutional framework is the establishment of the National Cyber Security Agency (NCSA). Operating under the jurisdiction of the relevant Ministry, the NCSA is mandated to serve as the lead authority for all cyber security matters in the Maldives. The agency is tasked with formulating national policies, setting technical standards, and coordinating incident response efforts across the country. One of its primary functions is the designation of Critical Information Infrastructure (CII) across various sectors, including telecommunications, banking, energy, and transportation. By centralizing these powers, the Act ensures a unified national response to threats, moving away from the fragmented approach that characterized previous security efforts. The NCSA also acts as the National Computer Emergency Response Team (CERT), providing real-time assistance during major cyber crises. In addition to the NCSA, the Act outlines a collaborative governance model involving various state organs. The Minister responsible for technology is granted the power to issue regulations and directives to give effect to the Act's provisions. A high-level advisory committee may also be formed to provide strategic guidance on emerging threats and international cooperation. The governance structure emphasizes accountability, requiring the NCSA to submit annual reports to the Parliament and the President regarding the state of national cyber security. This framework is designed to balance the need for executive agility in responding to digital threats with the necessity of democratic oversight.
Critical Information Infrastructure Protection
The Act focuses heavily on the protection of Critical Information Infrastructure (CII). Owners and operators of designated CII are subject to stringent security requirements, including the mandatory implementation of risk management frameworks and regular security audits. These entities must appoint a dedicated Cyber Security Officer who serves as the primary point of contact for the NCSA. The Act recognizes that the failure of a single critical system—such as the national payment gateway or the air traffic control system—could have cascading effects on the entire country. Therefore, the legislation mandates that CII operators maintain high levels of redundancy and disaster recovery capabilities, ensuring that essential services can continue to function even in the event of a successful cyber attack. The NCSA is empowered to issue specific directives to CII owners regarding the procurement of hardware and software, potentially restricting the use of components from vendors deemed to pose a national security risk. This proactive stance on supply chain security is a significant addition to the Maldivian legal landscape. Furthermore, CII operators are required to participate in national cyber security drills and exercises to test their preparedness. The Act also provides for the protection of information shared between CII operators and the NCSA, ensuring that sensitive vulnerability data is not disclosed to the public or unauthorized parties, thereby maintaining the confidentiality of the nation's defensive posture.
Incident Reporting and Response
Another key focus area is the establishment of a mandatory incident reporting regime. Under the Act, service providers and CII operators are legally required to notify the NCSA of any significant cyber incidents within a specified timeframe. This requirement is intended to provide the government with a comprehensive view of the national threat landscape, allowing the NCSA to issue early warnings and coordinate a collective defense. The reporting criteria include incidents that result in the loss of sensitive data, the disruption of essential services, or the unauthorized access to high-level administrative accounts. The NCSA is responsible for analyzing these reports to identify patterns and emerging threats, which are then used to update national security guidelines. In the event of a large-scale incident, the NCSA has the authority to take control of the response efforts, directing the actions of the affected entities to contain the threat and restore services. This centralized command structure is vital for managing crises that transcend individual organizational boundaries. The Act also encourages voluntary reporting from non-CII entities, fostering a culture of transparency and shared responsibility. By aggregating data from across the economy, the NCSA can provide more accurate threat intelligence to all stakeholders, enhancing the overall resilience of the Maldivian digital ecosystem. The response framework also includes provisions for post-incident reviews to identify lessons learned and prevent future occurrences.
Implementation and Technical Standards
The implementation of the Cyber Security Act is structured through a series of phased requirements and regulatory instruments. The NCSA is authorized to issue 'Cyber Security Codes of Practice' which provide detailed technical instructions for different sectors. These codes cover a wide range of topics, including encryption standards, access control policies, and secure software development lifecycles. For entities designated as CII, the implementation framework requires the submission of regular compliance reports and the conduct of third-party security assessments. The NCSA maintains a registry of qualified auditors who are authorized to perform these assessments, ensuring that the evaluations are conducted by competent and independent professionals. For the broader business community and the public sector, implementation involves adhering to baseline security standards set by the NCSA. The Act provides for a transition period during which organizations are expected to align their existing systems with the new legal requirements. During this time, the NCSA is tasked with providing guidance and support to help entities achieve compliance. The implementation framework also includes provisions for 'Cyber Security Exercises,' which are simulated attack scenarios designed to test the readiness of both the government and the private sector. These exercises are critical for identifying gaps in the national response plan and for ensuring that all stakeholders understand their roles during a real-world emergency. This proactive approach to implementation shifts the focus from mere compliance to operational resilience, ensuring that the Maldives is prepared for the evolving nature of digital warfare.
Monitoring and Enforcement
To ensure the effectiveness of the Act, the NCSA is granted extensive monitoring and investigative powers. The agency has the authority to conduct inspections of CII facilities and to request information regarding the security measures in place. If the NCSA suspects that an entity is in breach of the Act or its associated regulations, it can initiate a formal investigation. This includes the power to access computer systems, seize digital evidence, and compel testimony from relevant personnel. These powers are subject to legal safeguards to prevent abuse, ensuring that investigations are conducted in accordance with the principles of due process and the Maldivian Constitution. Evaluation of the Act’s impact is conducted through periodic reviews of the national cyber security strategy. The NCSA is required to track key performance indicators, such as the number of reported incidents, the average time to recovery, and the overall level of compliance across different sectors. This data-driven approach allows the government to refine its policies and allocate resources more effectively. Furthermore, the Act encourages a culture of continuous improvement by requiring CII operators to conduct their own internal reviews and to update their security plans in response to evolving threats. By combining top-down regulatory monitoring with bottom-up organizational evaluation, the Act creates a feedback loop that strengthens the nation's digital defenses over time. The enforcement mechanism also includes the ability to issue public warnings about non-compliant entities, serving as a reputational deterrent.
Penalties and Legal Liability
The Cyber Security Act introduces a robust regime of administrative and criminal penalties to deter non-compliance and punish malicious activities. Administrative fines can be levied against organizations that fail to meet security standards, neglect to report incidents, or obstruct NCSA investigations. These fines are scaled based on the severity of the violation and the potential impact on national security. For more serious offenses, such as unauthorized access to CII or the intentional disruption of essential services, the Act provides for criminal prosecution. Individuals found guilty of such offenses may face significant prison sentences and heavy fines, reflecting the gravity of cyber crimes in the modern era. The Act also addresses the issue of civil liability, clarifying the circumstances under which an entity may be held responsible for damages resulting from a cyber security breach. While the law encourages proactive defense, it also provides a framework for seeking redress if a breach was caused by gross negligence or a willful failure to comply with statutory obligations. To ensure fairness, the Act establishes an appeals process. Any entity or individual aggrieved by a decision of the NCSA—such as a fine or a CII designation—has the right to appeal to the relevant Ministry or a designated tribunal. This ensures that the NCSA's significant powers are exercised transparently and that affected parties have a clear legal path to challenge administrative actions. The legal framework also includes protections for whistleblowers who report security vulnerabilities or non-compliance within their organizations, further strengthening the enforcement ecosystem.
International Cooperation
Recognizing that cyber threats are inherently global and borderless, the Maldives Cyber Security Act is designed to align with international standards and best practices. The legislation draws inspiration from the Budapest Convention on Cybercrime and the security frameworks developed by the International Telecommunication Union (ITU). By adopting standardized definitions and incident reporting protocols, the Maldives facilitates smoother cooperation with international law enforcement agencies and global CERT networks. This alignment is crucial for the Maldives, as many of the threats it faces originate from outside its borders, requiring cross-border information sharing and mutual legal assistance. The Act also empowers the NCSA to enter into bilateral and multilateral agreements with foreign cyber security agencies. These partnerships focus on threat intelligence sharing, joint capacity-building initiatives, and coordinated responses to regional digital threats. For a small island nation like the Maldives, international cooperation is not just a benefit but a necessity for maintaining a secure digital environment. The Act’s emphasis on international alignment also enhances the country's reputation as a secure destination for foreign investment and digital services. By demonstrating a commitment to global norms in cyber governance, the Maldives positions itself as a responsible actor in the international digital economy, capable of protecting both domestic and international data assets. This global perspective ensures that the Maldives can leverage international expertise to stay ahead of emerging threats like AI-driven attacks and quantum computing vulnerabilities.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Ratification of the Act | 2023-11-14 | The Act was officially signed into law by President Ibrahim Mohamed Solih. |
| Establishment of the NCSA | 2024-02-14 | Deadline for the formal creation of the National Cyber Security Agency as a legal entity. |
| Designation of Initial CII | 2024-05-14 | Identification of the first set of critical infrastructure entities across key sectors. |
| Issuance of Codes of Practice | 2024-08-14 | Publication of the first set of technical standards and security guidelines by the NCSA. |
| Mandatory Compliance for CII | 2025-02-14 | Final deadline for designated CII entities to meet all security and reporting requirements. |
Compliance Checklist
| Check | Required Action | Frequency |
|---|---|---|
| CII Identification | Determine if your organization meets the criteria for Critical Information Infrastructure designation. | Annual |
| Cyber Security Officer | Appoint a qualified individual to oversee security and act as a liaison with the NCSA. | Once |
| Incident Reporting | Establish internal protocols to ensure cyber incidents are reported to the NCSA within the legal timeframe. | Continuous |
| Risk Assessment | Conduct annual risk assessments and submit findings to the NCSA as required by sector codes. | Annual |
| Technical Audits | Engage NCSA-approved third-party auditors to evaluate system security and compliance. | Bi-Annual |
| Employee Training | Implement mandatory cyber security awareness programs for all staff members. | Quarterly |
Related Regulations
Personal Data Protection Bill
Maldives91% similar
އިލެކްޓްރޯނިކް މުޢާމަލާތްތަކާބެހޭ ޤާނޫނު (Law No. 2/2022)
Maldives89% similar
Maldives AI Regulation Overview
Maldives89% similar
Communications Authority of Maldives Act (Law No. 42/2015) and related ICT/Telecommunications regulations
Maldives89% similar
ކޮމިއުނިކޭޝަންސް އޮތޯރިޓީ އޮފް މޯލްޑިވްސްގެ ޤާނޫނު (Law No. 42/2015)
Maldives89% similar
© Regulations.AI using Gemini 3 Flash Preview · updated on 13-Jun-2026