Law / Frameworks / NIST CSF 2.0 / Govern

NIST CSF 2.0, GovernGV.OC-03

Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.OC-03

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

60
laws
51
places
0
with court rulings behind them
5
not yet in force
2
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Albania
  • Andorra
  • Australia
  • Austria
  • Brazil
  • Cameroon
  • Central African Republic
  • China
  • Connecticut
  • Cuba
  • Côte d'Ivoire
  • Democratic Republic of the Congo
  • Denmark
  • Djibouti
  • Egypt
  • European Union
  • France
  • Gabon
  • Ghana
  • Iowa
  • Jordan
  • Kazakhstan
  • Kiribati
  • Kyrgyzstan
  • Lithuania
  • Luxembourg
  • Mexico
  • Micronesia
  • Mongolia
  • Montenegro
  • Morocco
  • Nevada
  • Ohio
  • Peru
  • Serbia
  • Sierra Leone
  • Slovakia
  • Somalia
  • South Sudan
  • Spain
  • State of Palestine
  • Sweden
  • Taiwan
  • Togo
  • Tonga
  • Ukraine
  • United States
  • Utah
  • Uzbekistan
  • Vietnam
  • Yemen

Sector security regimes

32 laws, 28 places
PlaceLawWhat it asks, as read here
Albania Law No. 25/2024, On Cybersecurity

Register your critical or important information infrastructure with the National Authority for Cybersecurity (AKSK), establish a Computer Security Incident Response Team and a single point of contact for AKSK and other CSIRTs, and implement the technical, organisational and operational risk management measures a Council of Ministers methodology sets for your designated category.

Where your organisation processes personal data in the course of these duties, do so under Albania's personal data protection legislation; this law's security measures duty is separate from, and does not substitute for, a breach notification duty to Albania's data protection authority under Law No. 124/2024.

Andorra Llei 22/2022, Cybersecurity Risk-Management Obligations

Adopt the security measures the National Security Scheme (Esquema Nacional de Seguretat) sets for your sector, which you may supplement with recognised international standards.

Austria Netz- und Informationssystemsicherheitsgesetz (NISG), Security Measures for Operators of Essential Services and Digital Service Providers

Prove compliance on request; expect this duty, together with the rest of this Act's Sections 2 to 31, to be repealed and replaced on by the Netz- und Informationssystemsicherheitsgesetz 2026's own risk-management duty, documented on this jurisdiction's companion row.

Austria Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management Measures from , in 2 days

Register with the Bundesamt für Cybersicherheit within three months of this duty applying (by ), and self-declare the risk-management measures you have implemented within twelve months of registration; expect the Bundesamt to be able to demand proof of operative and organisational implementation no earlier than two years after this duty applies.

Central African Republic Cybersecurity Law: Essential-Service Operator Cybersecurity Regime

Comply with the protective measures the Agence Nationale de la Cybersécurité sets to secure your essential infrastructure, and hold the accreditation the Agency grants to a compliant operator.

Central African Republic Cybersecurity Law: Mandatory Security Audit Regime

Provide the information and documents a security audit requires, and do not obstruct or resist it: obstructing a security audit is a criminal offense under Article 43.

Côte d'Ivoire RGSSI and PPIC Compliance Duty

Where your service's information system connects through Côte d'Ivoire's public telecommunications networks, or you automatically process your customers' personal data in providing your service, comply with the RGSSI (the ISO 27001/27002-based security standard Décret n°2021-917's audits check you against) and, if you also operate a designated critical-infrastructure asset, the PPIC.

Denmark NIS 2-loven, Cybersecurity Risk-Management Measures and Registration

If you are a DNS provider, top-level-domain registry, domain-name-registration-service provider, or a provider of cloud-computing, data-centre, content-delivery-network, managed, managed-security, online-marketplace, online-search-engine or social-networking-services-platform services, register with the relevant competent authority within 3 months of first falling within the Act's scope, stating your name, address, sector and sub-sector, contact details, and the EU member states where you provide services. Other essential and important entities register within 2 weeks of first falling within scope. Anyone already in scope when the Act commenced had to register by .

Djibouti Digital Code, Book II: Electronic Communications Network and Service Security

Take all technical and organizational measures necessary to secure your network and services at a level adapted to the existing risk, and comply with the technical security prescriptions the national cybersecurity authority issues.

Give the cybersecurity authority confidential access, on request, to the arrangements you have made to secure your network, and submit your network to a security and integrity inspection the authority conducts or commissions, at your own expense.

Djibouti Digital Code, Book VII: Health-Data Hosting Security Certification

Hold a conformity certificate the national cybersecurity authority issues before hosting digital health data, if your activity is making available and maintaining the physical site, the physical or virtual infrastructure, or an application-hosting platform for a health-data information system, administering or operating such a system, or backing up health data.

Show the other 22 laws
European Union NIS2 Directive, Cybersecurity Risk-Management Measures

If you are not established in the Union but offer a covered service within it, designate a representative established in a Member State where you offer the service.

France Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security Requirements

Where you are instead designated as an operator of essential services, apply the security rules the Premier ministre sets under Article 6 at your own expense, covering governance, protection, defence and resilience of your networks and systems.

Ghana Cybersecurity Act, Licensing of Cybersecurity Service Providers

Obtain a licence from the Cyber Security Authority before providing the cybersecurity service; the Authority acknowledges an application within fourteen days and decides it within thirty days.

A granted licence is valid for two years from the date it is granted; apply in writing for renewal not later than one month before it expires.

+1 more
Kiribati Cybersecurity Act 2026, Critical Infrastructure Operator Obligations from a date not yet set

Once designated, register with the DTO and notify it of any change in ownership of the infrastructure or in the person or entity operating it within 30 days; furnish the DTO whatever information it requires by written notice to assess the infrastructure's security and cybersecurity measures; and report a material change to the infrastructure's design, configuration, security or operation to the DTO within 30 days of the change.

Comply with cybersecurity standards the DTO issues, submit to its periodic or ad hoc audits, inspections and penetration testing, and conduct and submit periodic cybersecurity assessments of the infrastructure's risk, vulnerability and preparedness.

+1 more
Lithuania Kibernetinio saugumo įstatymas (Law on Cyber Security), Risk-Management Measures

Follow the detailed technical and organisational measures the Government's Cybersecurity Requirements Description sets out; if you are newly registered, you have 12 months from registration to implement the organisational measures and 24 months to implement the technical measures.

Luxembourg Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important Entities

Notify the measures you take under this duty to the competent authority in the form, format and timeframe it sets by règlement or circulaire.

Micronesia FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Risk-Management Duties proposed

Notify the Department of Justice of a change of ownership or control of your designated critical information infrastructure no later than seven days after the change.

Montenegro Law on Information Security, Essential and Important Entities

Report any change to your registration details to the competent ministry within 14 days of the change (Article 26).

Morocco Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security Duties

Take the protective measures the national cybersecurity authority directs to prevent and neutralize the effects of a threat or breach affecting your clients' information systems.

Serbia Law on Information Security, ICT Systems of Special Importance and Security Measures

Apply for registration of your ICT system in the Ministry's registry of priority and important ICT systems.

Sierra Leone Cyber Security and Crime Act, 2021, Critical National Information Infrastructure

If your system, data, or traffic data is designated, meet the minimum standards, guidelines, rules, or procedures the Presidential Order prescribes, which section 7(2) requires to cover at least securing systems by default and logging system and user activity for audit, and permit the National Computer Security Incidence Response Team to audit and inspect the designated infrastructure at any time.

Slovakia Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Risk-Management Measures

Where you also operate a service the Act designates a "critical basic service" (broadly: a large enterprise, above the medium-enterprise threshold, active in an Annex 1 sector other than public administration, or a qualified trust service, TLD registry, DNS service, or an at-least-medium-sized public electronic communications network or service), report that status to the Authority and expect a higher administrative-fine ceiling for the same duties.

Somalia National Cybersecurity Law (2025)

As a designated Critical Information Infrastructure operator, meet the cybersecurity standards the National Communications Authority sets and comply with its incident reporting obligations; the located text does not state a reporting clock, a reporting threshold, or a penalty for a missed report.

If you provide cybersecurity services, or work as a cybersecurity professional, in Somalia, hold a current National Communications Authority licence or registration before operating.

South Sudan National Communication Act, 2012, Licensee Security Duty

Cooperate with the Authority's own efforts to protect communication networks against intrusion and vandalism, and discourage and prevent disruptive, unethical or malicious practices contrary to the Authority's policies and regulations (Sec. 88(1)).

Spain Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service Providers

If designated an operator of essential services, designate a responsable de la seguridad de la informacion within three months of your designation, notify the competent authority of the appointment, and file a Declaracion de Aplicabilidad of the security measures you apply within six months of designation, reviewing it at least every three years.

State of Palestine Law by Decree No. 41 of 2022 concerning National Payments, Licensing and Security-Systems Duty

Comply with the security and protection systems and procedures the Palestine Monetary Authority prescribes by instruction for a licensed payment-service or financial-technology company, apply them, and keep pace with their required development (Art. 8(2)(b)).

Sweden Cybersäkerhetslag, Cybersecurity Risk-Management Measures

Register with the authority the government designates as soon as you can, per Cybersäkerhetsförordning (2025:1507) 5 §, and notify a change in what you registered within 14 days of the change.

Taiwan Cyber Security Management Act, Specific Non-Government Agency Cyber Security Management

Report to the competent authority for approval or recordation of the agency's assigned cyber security responsibility level, based on the sensitivity, volume and nature of the information the agency holds and the scale and nature of its information and communication systems.

Comply with the central competent authority's periodic or ad hoc audits of the maintenance plan's implementation; a designated critical infrastructure provider's audit results are forwarded to the Ministry of Digital Affairs.

Taiwan Telecommunications Management Act, Cyber Security and Critical Infrastructure Protection Plans

Where the competent authority designates the enterprise's PSTN, in whole or in part, as critical telecommunications infrastructure, additionally draw up a critical telecommunications infrastructure protection plan before the competent authority's own deadline, submit it for the competent authority's evaluation before implementing it, and comply with the technical specifications for info-communications security evaluation the competent authority sets for that infrastructure.

Togo Loi n° 2018-026, opérateurs de services essentiels and the National Cybersecurity Agency (ANCy)

Once designated, comply with the cybersecurity rules for protecting your essential infrastructure that a decree in Council of Ministers fixes under Article 3, and expect the Agence nationale de la cybersécurité (ANCy) to control, audit and inspect your compliance with them.

Tonga Cybersecurity Act 2025, Critical Infrastructure Operator Obligations from a date not yet set

Once designated, register with the Minister CPR, notify the Minister CPR of any change in your legal ownership or in the person or entity operating the infrastructure, and conduct and submit periodic cybersecurity self-assessments to the Ministry CPR in the form and manner it prescribes.

Comply with any minimum standards the Minister CPR issues for critical infrastructure, submit to the Minister CPR's periodic and ad hoc audits and inspections of your compliance, and comply with any order the Minister CPR makes to take remedial, protective or preventative action following an audit, an assessment, or a reported incident.

Yemen Law No. 40 of 2006 on Electronic Payment Systems and Financial and Banking Operations, Secure-Services and Banking-Confidentiality Duty

Comply with the Central Bank of Yemen's Bank Law, Banks Law, and the related regulations and instructions issued for electronic funds transfer operations.

Security baseline statutes

19 laws, 18 places
PlaceLawWhat it asks, as read here
Cameroon Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, articles 6, 7, 13-14, 24, 26-30, 32, 61(3) (mesures de sécurité et audit de sécurité obligatoire par l'ANTIC)

Have Cameroon's National Information and Communication Technologies Agency (ANTIC) approve the security mechanisms you put in place for this purpose.

Submit your networks and information systems to ANTIC's mandatory security audit, conducted at least once a year or whenever circumstances require it.

+1 more
Central African Republic Cybersecurity Law: Network and Information System Security Duty

Put in place technical mechanisms addressing threats to your systems' permanent availability, integrity, authentication, non-repudiation and data confidentiality, and to their physical security, and submit those mechanisms to the Agence Nationale de la Cybersécurité for approval.

Connecticut Adoption of cybersecurity controls by businesses, exemption from punitive damages

The program must conform to the current version of a named framework (the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53/53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, or the ISO/IEC 27000-series), or, for an entity already regulated under HIPAA, Gramm-Leach-Bliley Title V, FISMA or HITECH, conform to that regime, or comply with the PCI Data Security Standard together with another listed framework; conform to a revised version within six months of its publication.

Cuba Decreto No. 360/2019 and its Reglamento de Seguridad de las TIC (Resolución 128/2019), TIC Security System duty

If you produce equipment or provide network, program, application or IT services, whether from inside or outside Cuba, implement the requirements that guarantee the secure operation of the equipment and services you supply; obtain a Ministry of Communications operating license before offering TIC security services to a third party, a license reserved to a state entity whose staff reside permanently in the country.

Democratic Republic of the Congo Digital Code, Livre IV: Digital Services Provider Security Obligations

Submit your information system to controls the Agence Nationale de Cybersécurité conducts to verify its security level and its compliance with security rules, at your own cost.

Egypt Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, System-Security Duty on a System Manager

Take the security precautions and measures the executive regulations of this Law prescribe. A negligent failure to do so that results in your website, private account, email account, or information system being exposed to a crime under this Law carries imprisonment of not less than six months plus a fine of EGP 10,000 to 100,000.

Gabon Sécurité des systèmes d'information (dispositions communes)

Deploy technical mechanisms addressing threats to your systems' continuous availability, integrity, authentication, resistance to repudiation by third-party users, data confidentiality and physical security, and have those mechanisms cleared for conformity with the competent administrative authority's cybersecurity policy.

Retain your systems' connection and traffic data for ten years, and submit your networks and information systems to a mandatory, periodic security audit on terms a regulation sets.

Ghana Cybersecurity Act, Cybersecurity Standards and Enforcement

Comply with the cybersecurity standards the Cyber Security Authority develops, establishes, adopts and publishes on its website, which by section 59(1) cover education and skills development, hardware and software engineering, governance and risk management, research and development, and any other area the Authority determines in line with international best practice.

Iowa Tort Liability for Cybersecurity Programs, affirmative defense for a reasonable security program

Satisfy the framework requirement by reasonably conforming the program to a named industry-recognized cybersecurity framework (the NIST framework for improving critical infrastructure cybersecurity, NIST SP 800-171, NIST SP 800-53 and 800-53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, or the ISO/IEC 27000 family), or, where already regulated under one, by conforming the program to the entirety of HIPAA's Security Rule, Gramm-Leach-Bliley Title V, the federal Information Security Modernization Act of 2014, HITECH, Iowa's own Insurance Data Security Act (chapter 507F), or applicable federal critical-infrastructure-protection rules, or by combining PCI Data Security Standard compliance with one of the named frameworks; conform the program to a revised framework or amended regulation within one year of its publication or effective date.

Kazakhstan Digital Code, general cybersecurity duty on digital-object owners and holders

Also follow the specific requirements set by the Law of the Republic of Kazakhstan "On Cybersecurity" and the unified digitalization and cybersecurity requirements adopted under it; their own specific duties are not further detailed here.

Show the other 9 laws
Kyrgyzstan Digital Code, digital resilience baseline security measures

Follow any measure the sectoral regulator for your sector directs you to take to prevent an incident in the digital environment or reduce its negative consequences; the regulator may issue binding instructions to that effect.

Mexico Ley Federal de Protección al Consumidor, Electronic Transaction Security Duty (Arts. 76 Bis, 76 Bis 1)

Follow the Secretaria de Economia's Norma Mexicana for electronic commerce, which requires among other things reliable technical security mechanisms that guarantee the protection and confidentiality of the consumer's personal information and of the transaction itself.

Nevada Security measures for a data collector accepting payment cards, encryption duty, and conditioned liability shield from a date not yet set

If you accept a payment card in connection with a sale of goods or services to a Nevada resident, comply with the current version of the Payment Card Industry (PCI) Data Security Standard adopted by the PCI Security Standards Council, with respect to those transactions, by the compliance date the standard itself sets.

Nevada Security measures for data collectors maintaining personal information from a date not yet set

If you are a governmental agency, additionally comply, to the extent practicable, with the current version of the CIS Controls published by the Center for Internet Security or the corresponding National Institute of Standards and Technology standards, with respect to the collection, dissemination, and maintenance of those records.

Ohio Ohio Data Protection Act, cybersecurity program safe harbor

Make the program reasonably conform to the current version of the NIST Cybersecurity Framework, NIST Special Publication 800-171, NIST Special Publications 800-53 and 800-53A, the FedRAMP security assessment framework, the CIS Critical Security Controls, or the ISO/IEC 27000 family, alone or in combination, or, if already regulated under it, reasonably conform to the entirety of the HIPAA security rule, Gramm-Leach-Bliley Act Title V, the Federal Information Security Modernization Act, or HITECH, or comply with the PCI Data Security Standard together with one of the first group's frameworks.

Peru Proyecto de Ley 9906/2024-CR, Ley de Seguridad Digital o Ciberseguridad proposed

If enacted as introduced, expect a duty to cooperate with public authorities on national cybersecurity matters where you operate as a private legal person in Peru, and expect the Comite de Ciberseguridad the bill creates to address you with guidelines on countering security breaches rather than a specific, clock-bound technical duty.

Utah Cybersecurity Affirmative Defense Act

Build the program as a reasonable security program, a designated coordinator, procedures to detect, prevent and respond to a breach, employee training, and periodic risk assessments of network and software design, information handling, and data storage and disposal, adjusted as circumstances change, or have it reasonably conform to a current named framework: NIST SP 800-171; NIST SP 800-53 and 800-53A; the FedRAMP Security Assessment Framework; the CIS Critical Security Controls; the ISO/IEC 27000 family; the HIPAA Security Rule or Gramm-Leach-Bliley Title V regulations for information those regimes cover; or the PCI Data Security Standard for payment card information.

Uzbekistan Law on Cybersecurity, general cybersecurity duties on cybersecurity subjects

Comply with the cybersecurity requirements the State Security Service sets for protecting information systems and resources.

Vietnam Cybersecurity Law, Information System Classification and Protection Measures

At level 3 or level 4, and not on the Prime Minister's list of information systems critical to national security, perform every Article 10(1) task and, without discretion, promulgate cybersecurity design-and-operation rules, apply management measures meeting national cybersecurity standards, back up and store data protecting the system's components, inspect and supervise compliance, monitor the system, and respond to and remedy incidents; file a dossier proposing your system's level and put it into operation only once that level is approved.

Vulnerability and incident reporting

5 laws, 5 places
PlaceLawWhat it asks, as read here
Ghana Cybersecurity Act, Duty to Report Cybersecurity Incident

Where the institution is itself a cybersecurity service provider licensed by the Authority, also submit a periodic report on its operations, including any cybersecurity incident, within the period the Authority sets.

Jordan Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation duty

Adhere to the policies, standards, and controls the Center issues for the institution's own sector, provide the Center the information it needs to do its work, and inform the Center of any incident that threatens cybersecurity or the security of cyberspace, taking every step necessary to prevent or avoid it.

Mongolia Law on Cyber Security, Cyber-Attack Notification Duty for Other Legal Persons

Abide by the Government's common procedure for ensuring, preventing, detecting and countering cyber-attacks once the Government adopts it under Article 7.1.

Comply with the recommendations and requirements the relevant authorities issue to you in relation to ensuring cyber security.

Ukraine Law on the Basic Principles of Ensuring Cybersecurity, CERT-UA Incident Notification Duty

Where the incident information you exchange with CERT-UA or another party contains personal data, handle that exchange under the requirements of the Law on the Protection of Personal Data.

United States Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 252.204-7012)

If this clause applies to your organization, provide adequate security on every covered contractor information system, implementing the security requirements of NIST Special Publication 800-171 unless the system is part of an information technology service the government operates on its own behalf, in which case follow the security requirements stated elsewhere in the contract.

Product security requirements

4 laws, 4 places
PlaceLawWhat it asks, as read here
Australia Security Standards for Smart Devices

Publish, before supply, the period including an end date for which the device will receive security updates, provide or supply the product with a statement of compliance with the security standard, and retain a copy of that statement for five years.

Brazil Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment)

Demonstrate this compliance to Anatel's conformity-assessment agent when you seek homologação for the device, or by presenting your own Cybersecurity Policy showing you meet the full set of supplier requirements; Anatel can suspend a homologação it already granted if it later finds a security flaw or vulnerability, and a suspended homologação bars the product from being distributed in the Brazilian market until the problem is fixed.

China Cybersecurity Law, Network Product and Service Security Duties

Meet the mandatory requirements of the applicable national standard for your product or service, and do not embed a malicious program in it.

Democratic Republic of the Congo Digital Code, Livre IV: ICT Product and Service Vendor Security Certification

Apply to the Minister responsible for digital affairs for a compliance certificate, which issues only after a vulnerability analysis and a security-guarantee evaluation performed by information security experts the Minister has accredited.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.