Uzbekistan - Cybersecurity Law (ZRU-764)

Law of the Republic of Uzbekistan 'On Cybersecurity'

Kiberxavfsizlik to‘g‘risida”gi O‘zbekiston Respublikasi Qonuni

Uzbekistan

RAI-UZ-NA-ZRU7640-2022

ZRU-764

Effective: July 16, 2022
In Force(In Force)
ActGovernance and OversightRisk ManagementEnforcement and Penalties
Export PDF

A national legislative framework establishing cybersecurity standards, critical infrastructure protection, and centralized oversight in Uzbekistan.

Summary

The Law of the Republic of Uzbekistan 'On Cybersecurity' (ZRU-764) establishes a comprehensive legal framework for protecting the nation's digital sovereignty and critical information infrastructure. It centralizes oversight under the State Security Service and mandates strict security protocols for both state and private entities involved in critical sectors.

Full article

Read full text ↗

Overview

The Law of the Republic of Uzbekistan "On Cybersecurity" (No. ZRU-764), adopted on April 15, 2022, serves as the primary legislative framework governing the protection of the nation's digital sovereignty and information systems. This comprehensive act was introduced to address the increasing frequency of cyber threats and to establish a unified legal environment for the protection of information infrastructure. The law applies broadly to state bodies, legal entities, and individuals involved in the processing of information within the digital space of Uzbekistan. It emphasizes the priority of protecting the interests of the individual, society, and the state from internal and external cyber threats, ensuring that the digital economy can grow within a secure and resilient environment. By codifying these requirements, Uzbekistan aligns its domestic policy with the broader 'Digital Uzbekistan 2030' strategy, which aims to modernize the national economy through technological integration. The law represents a shift from reactive measures to a proactive, state-led security posture that treats digital infrastructure as a core component of national security. It establishes the legal basis for the identification, classification, and protection of critical systems while ensuring that the rights of citizens to access information and maintain privacy are balanced against the needs of national defense.

Definitions and Scope

The legislation provides a rigorous set of definitions that form the technical and legal basis for its enforcement. 'Cybersecurity' is defined as the state of protection of the interests of the person, society, and the state from threats in the cyber-space. This broad definition allows the regulator to address not only technical vulnerabilities but also the socio-political impacts of digital disruptions. A 'cyber-attack' is characterized as an intentional impact on an object of cybersecurity, carried out using software or hardware-software tools with the aim of disrupting its functioning or compromising the integrity, availability, and confidentiality of information. These definitions are crucial for legal proceedings, as they distinguish between accidental system failures and malicious activities that warrant criminal or administrative prosecution. The scope of the law extends to all 'objects of cybersecurity,' which include information systems, data processing centers, and telecommunications networks. Furthermore, the law introduces the concept of 'Critical Information Infrastructure' (CII), which refers to information systems and networks used in areas of state management, defense, security, law enforcement, healthcare, science, education, finance, energy, and industry. The identification of these objects is a centralized process managed by the authorized state body, ensuring that the most vital components of the nation's digital fabric receive the highest level of protection and scrutiny.

Governance and Institutional Framework

The institutional framework established by ZRU-764 is centralized under the State Security Service (SSS) of the Republic of Uzbekistan, which acts as the authorized state body in the field of cybersecurity. The SSS is empowered to implement state policy, coordinate the activities of other government agencies, and develop mandatory technical regulations. This centralized oversight ensures that there is a single point of accountability for national cyber defense. The SSS is responsible for maintaining the unified register of CII objects and conducting mandatory audits to ensure compliance with security standards. Their role also extends to the certification of cybersecurity tools, ensuring that hardware and software used in sensitive sectors meet rigorous national safety criteria. In addition to the SSS, the Cabinet of Ministers plays a strategic role by approving state programs and determining the procedure for classifying objects as critical information infrastructure. Other state bodies, including the Ministry of Digital Technologies, are tasked with integrating cybersecurity measures into their specific sectors. The law also encourages the creation of sectoral centers for cybersecurity (CERTs), which act as specialized response units for specific industries like banking or energy. This multi-layered governance model ensures that while policy is centralized, implementation is distributed across the relevant sectors of the economy, facilitating a rapid flow of information regarding threats from the tactical level of individual organizations up to the strategic level of national security leadership.

Protection of Critical Information Infrastructure

The primary focus of the law is the protection of Critical Information Infrastructure (CII). The legislation mandates that all entities operating CII must implement a comprehensive suite of security controls, including encryption, access management, and continuous monitoring. There is a heavy emphasis on the 'localization' of security, requiring that critical data be processed and stored within the territory of Uzbekistan where feasible. This focus on digital sovereignty is intended to mitigate the risks associated with global supply chain vulnerabilities and foreign interference. The law also prioritizes the protection of personal data within these systems, linking cybersecurity directly to the rights of individual data subjects. Owners of CII are required to develop internal security policies that align with national standards and to ensure that their systems are resilient against both targeted attacks and large-scale systemic failures. The law stipulates that the SSS has the right to access these systems for the purpose of monitoring and incident investigation, creating a partnership between the state and infrastructure owners. This section of the law is particularly detailed regarding the technical requirements for system redundancy and disaster recovery, reflecting the high stakes involved in the protection of essential services such as the power grid, financial markets, and emergency response systems.

Implementation and Technical Compliance

Implementation of the Law on Cybersecurity requires a systematic approach to technical and administrative compliance. Organizations identified as owners of CII objects must establish dedicated cybersecurity departments or appoint responsible officers who report directly to senior management. These entities are required to conduct internal risk assessments and develop incident response plans that are tested through regular drills. The law stipulates that any hardware or software used to protect cybersecurity objects must undergo a mandatory conformity assessment. This ensures that the tools used for defense do not themselves contain vulnerabilities or 'backdoors' that could be exploited by adversaries. The framework also mandates the 'declaration' of cybersecurity systems. Owners of information systems must submit documentation to the State Security Service detailing their security architecture and the measures taken to mitigate identified risks. For private sector entities that do not fall under the CII category, the law provides a voluntary framework for alignment, though they are still encouraged to follow national standards to ensure general digital hygiene. The implementation process is supported by a series of subsidiary acts and technical regulations issued by the SSS, which provide granular details on encryption standards, log retention policies, and physical security requirements for data centers. This structured approach ensures that the high-level principles of the law are translated into actionable technical requirements that can be audited and enforced.

Monitoring, Auditing, and Incident Response

Monitoring is a continuous requirement under the law, involving both automated systems and manual audits. The State Security Service is authorized to conduct periodic inspections of CII objects to verify that security measures are functioning as intended. These inspections can be scheduled or unannounced, particularly following a significant cyber-incident. The law requires CII operators to implement real-time monitoring of their networks and to report any 'cyber-incidents' to the SSS immediately. This rapid reporting mechanism is designed to allow for a coordinated national response to large-scale attacks, preventing the spread of malware or the escalation of a breach across different sectors. Evaluation of the effectiveness of the national cybersecurity strategy is conducted through annual reports submitted by state bodies to the Cabinet of Ministers. These reports analyze the threat landscape, the number of incidents mitigated, and the progress of infrastructure hardening. Furthermore, the law establishes a feedback loop where the results of audits and incident investigations are used to update national standards and technical regulations. This iterative process ensures that the legal and technical framework evolves in tandem with the changing tactics of cyber-criminals. The evaluation also extends to the performance of cybersecurity personnel, with mandatory re-certification programs to ensure that their skills remain current in a rapidly changing technological environment.

Liability, Penalties, and Legal Recourse

The Law on Cybersecurity introduces a regime of liability for both individuals and legal entities that fail to comply with its provisions. Violations of cybersecurity requirements, especially those resulting in the compromise of CII, can lead to administrative or criminal penalties. Administrative liability typically involves substantial fines for officials who fail to implement mandatory security measures or who neglect to report cyber-incidents within the required timeframe. In cases where negligence or intentional violation leads to significant damage, loss of life, or threats to national security, the Criminal Code of Uzbekistan provides for more severe sanctions, including imprisonment. Liability also extends to the providers of cybersecurity services and tools. If a certified security product fails due to a known but undisclosed vulnerability, the developer may be held liable for resulting damages. However, the law also provides a mechanism for appeals. Entities that disagree with the findings of an SSS audit or a classification decision by the Cabinet of Ministers have the right to challenge these decisions through the judicial system. This ensures a level of due process and prevents the arbitrary application of the law. The legal framework emphasizes that while security is paramount, the enforcement of regulations must be transparent and based on objective technical evidence, protecting the rights of legitimate businesses and technology providers. This balanced approach is intended to foster a culture of compliance rather than one of fear, encouraging organizations to proactively share information with the regulator.

International Cooperation and Alignment

Uzbekistan’s Law on Cybersecurity reflects a significant effort to align national practices with international norms and standards. The law explicitly mentions international cooperation as a key principle of state policy. This includes the exchange of information on cyber-threats, joint investigations into cyber-crimes, and participation in international cybersecurity forums. The State Security Service is tasked with representing Uzbekistan in these international dialogues, ensuring that the country's interests are protected and that it remains integrated into the global security architecture. This alignment is particularly important for attracting foreign investment, as international companies require a predictable and secure legal environment for their digital operations. The technical standards referenced in the law and its subsidiary regulations often draw from ISO/IEC 27001 and other globally recognized frameworks. By adopting these standards, Uzbekistan facilitates the interoperability of its systems with those of international partners. Furthermore, the law supports the nation's commitments under various regional security treaties, such as those within the Shanghai Cooperation Organization (SCO) and the Commonwealth of Independent States (CIS), emphasizing a collective approach to digital peace and stability. The focus on 'responsible behavior in cyberspace' mirrors discussions at the United Nations level regarding the application of international law to state behavior in the digital realm. Through this law, Uzbekistan signals its intent to be a responsible and proactive member of the international community in the fight against global cyber-threats.

Implementation Timeline

MilestoneDateDescription
Legislative Adoption2022-02-25The draft law was passed by the Legislative Chamber of the Oliy Majlis.
Senate Approval2022-03-17The Senate of the Oliy Majlis approved the final text of the law.
Presidential Signature2022-04-15President Shavkat Mirziyoyev signed the law into effect as ZRU-764.
Official Publication2022-04-16The law was published in the official gazette 'Khalq Sozi'.
Entry into Force2022-07-16The law became legally binding three months after its official publication.
CII Registry Launch2022-10-01The State Security Service began the formal identification of critical objects.

Compliance Checklist for Organizations

RequirementAction ItemApplicability
CII ClassificationSubmit system details to SSS for determination of critical status.Mandatory for State/Large Entities
Security OfficerAppoint a Chief Information Security Officer (CISO) or equivalent.All CII Owners
Incident ProtocolEstablish a 24/7 reporting line to the State Security Service.All CII Owners
Tool CertificationAudit all security software for valid national certificates.All Cybersecurity Objects
Risk AssessmentConduct and document an annual cybersecurity risk assessment.Mandatory for CII
Data ResidencyEnsure critical database servers are located within Uzbekistan.CII and State Systems

© Regulations.AI using Gemini 3 Flash Preview · updated on 13-Jun-2026