Law / Frameworks / NIST CSF 2.0 / Govern
NIST CSF 2.0, GovernGV.OC-03
Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.OC-03
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 60
- laws
- 51
- places
- 0
- with court rulings behind them
- 5
- not yet in force
- 2
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.6 Mechanisms are in place to inventory AI systems and are resourced according to...
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations4.2 Risk Disclosure
- MIT mitigations1.1 Board Structure & Oversight
- NIST Privacy FrameworkGV.PO-P5 Legal, regulatory, and contractual requirements regarding privacy are understood and managed.
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
A law in force is unmarked; the rest wear their state: not yet in force proposed
Sector security regimes
32 laws, 28 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 25/2024, On Cybersecurity |
Register your critical or important information infrastructure with the National Authority for Cybersecurity (AKSK), establish a Computer Security Incident Response Team and a single point of contact for AKSK and other CSIRTs, and implement the technical, organisational and operational risk management measures a Council of Ministers methodology sets for your designated category. Where your organisation processes personal data in the course of these duties, do so under Albania's personal data protection legislation; this law's security measures duty is separate from, and does not substitute for, a breach notification duty to Albania's data protection authority under Law No. 124/2024. |
|
| Llei 22/2022, Cybersecurity Risk-Management Obligations |
Adopt the security measures the National Security Scheme (Esquema Nacional de Seguretat) sets for your sector, which you may supplement with recognised international standards. |
|
| Netz- und Informationssystemsicherheitsgesetz (NISG), Security Measures for Operators of Essential Services and Digital Service Providers |
Prove compliance on request; expect this duty, together with the rest of this Act's Sections 2 to 31, to be repealed and replaced on by the Netz- und Informationssystemsicherheitsgesetz 2026's own risk-management duty, documented on this jurisdiction's companion row. |
|
| Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management Measures from , in 2 days |
Register with the Bundesamt für Cybersicherheit within three months of this duty applying (by ), and self-declare the risk-management measures you have implemented within twelve months of registration; expect the Bundesamt to be able to demand proof of operative and organisational implementation no earlier than two years after this duty applies. |
|
| Cybersecurity Law: Essential-Service Operator Cybersecurity Regime |
Comply with the protective measures the Agence Nationale de la Cybersécurité sets to secure your essential infrastructure, and hold the accreditation the Agency grants to a compliant operator. |
|
| Cybersecurity Law: Mandatory Security Audit Regime |
Provide the information and documents a security audit requires, and do not obstruct or resist it: obstructing a security audit is a criminal offense under Article 43. |
|
| RGSSI and PPIC Compliance Duty |
Where your service's information system connects through Côte d'Ivoire's public telecommunications networks, or you automatically process your customers' personal data in providing your service, comply with the RGSSI (the ISO 27001/27002-based security standard Décret n°2021-917's audits check you against) and, if you also operate a designated critical-infrastructure asset, the PPIC. |
|
| NIS 2-loven, Cybersecurity Risk-Management Measures and Registration |
If you are a DNS provider, top-level-domain registry, domain-name-registration-service provider, or a provider of cloud-computing, data-centre, content-delivery-network, managed, managed-security, online-marketplace, online-search-engine or social-networking-services-platform services, register with the relevant competent authority within 3 months of first falling within the Act's scope, stating your name, address, sector and sub-sector, contact details, and the EU member states where you provide services. Other essential and important entities register within 2 weeks of first falling within scope. Anyone already in scope when the Act commenced had to register by . |
|
| Digital Code, Book II: Electronic Communications Network and Service Security |
Take all technical and organizational measures necessary to secure your network and services at a level adapted to the existing risk, and comply with the technical security prescriptions the national cybersecurity authority issues. Give the cybersecurity authority confidential access, on request, to the arrangements you have made to secure your network, and submit your network to a security and integrity inspection the authority conducts or commissions, at your own expense. |
|
| Digital Code, Book VII: Health-Data Hosting Security Certification |
Hold a conformity certificate the national cybersecurity authority issues before hosting digital health data, if your activity is making available and maintaining the physical site, the physical or virtual infrastructure, or an application-hosting platform for a health-data information system, administering or operating such a system, or backing up health data. |
Show the other 22 laws
| NIS2 Directive, Cybersecurity Risk-Management Measures |
If you are not established in the Union but offer a covered service within it, designate a representative established in a Member State where you offer the service. |
|
| Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security Requirements |
Where you are instead designated as an operator of essential services, apply the security rules the Premier ministre sets under Article 6 at your own expense, covering governance, protection, defence and resilience of your networks and systems. |
|
| Cybersecurity Act, Licensing of Cybersecurity Service Providers |
Obtain a licence from the Cyber Security Authority before providing the cybersecurity service; the Authority acknowledges an application within fourteen days and decides it within thirty days. A granted licence is valid for two years from the date it is granted; apply in writing for renewal not later than one month before it expires. +1 more |
|
| Cybersecurity Act 2026, Critical Infrastructure Operator Obligations from a date not yet set |
Once designated, register with the DTO and notify it of any change in ownership of the infrastructure or in the person or entity operating it within 30 days; furnish the DTO whatever information it requires by written notice to assess the infrastructure's security and cybersecurity measures; and report a material change to the infrastructure's design, configuration, security or operation to the DTO within 30 days of the change. Comply with cybersecurity standards the DTO issues, submit to its periodic or ad hoc audits, inspections and penetration testing, and conduct and submit periodic cybersecurity assessments of the infrastructure's risk, vulnerability and preparedness. +1 more |
|
| Kibernetinio saugumo įstatymas (Law on Cyber Security), Risk-Management Measures |
Follow the detailed technical and organisational measures the Government's Cybersecurity Requirements Description sets out; if you are newly registered, you have 12 months from registration to implement the organisational measures and 24 months to implement the technical measures. |
|
| Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important Entities |
Notify the measures you take under this duty to the competent authority in the form, format and timeframe it sets by règlement or circulaire. |
|
| FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Risk-Management Duties proposed |
Notify the Department of Justice of a change of ownership or control of your designated critical information infrastructure no later than seven days after the change. |
|
| Law on Information Security, Essential and Important Entities |
Report any change to your registration details to the competent ministry within 14 days of the change (Article 26). |
|
| Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security Duties |
Take the protective measures the national cybersecurity authority directs to prevent and neutralize the effects of a threat or breach affecting your clients' information systems. |
|
| Law on Information Security, ICT Systems of Special Importance and Security Measures |
Apply for registration of your ICT system in the Ministry's registry of priority and important ICT systems. |
|
| Cyber Security and Crime Act, 2021, Critical National Information Infrastructure |
If your system, data, or traffic data is designated, meet the minimum standards, guidelines, rules, or procedures the Presidential Order prescribes, which section 7(2) requires to cover at least securing systems by default and logging system and user activity for audit, and permit the National Computer Security Incidence Response Team to audit and inspect the designated infrastructure at any time. |
|
| Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Risk-Management Measures |
Where you also operate a service the Act designates a "critical basic service" (broadly: a large enterprise, above the medium-enterprise threshold, active in an Annex 1 sector other than public administration, or a qualified trust service, TLD registry, DNS service, or an at-least-medium-sized public electronic communications network or service), report that status to the Authority and expect a higher administrative-fine ceiling for the same duties. |
|
| National Cybersecurity Law (2025) |
As a designated Critical Information Infrastructure operator, meet the cybersecurity standards the National Communications Authority sets and comply with its incident reporting obligations; the located text does not state a reporting clock, a reporting threshold, or a penalty for a missed report. If you provide cybersecurity services, or work as a cybersecurity professional, in Somalia, hold a current National Communications Authority licence or registration before operating. |
|
| National Communication Act, 2012, Licensee Security Duty |
Cooperate with the Authority's own efforts to protect communication networks against intrusion and vandalism, and discourage and prevent disruptive, unethical or malicious practices contrary to the Authority's policies and regulations (Sec. 88(1)). |
|
| Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service Providers |
If designated an operator of essential services, designate a responsable de la seguridad de la informacion within three months of your designation, notify the competent authority of the appointment, and file a Declaracion de Aplicabilidad of the security measures you apply within six months of designation, reviewing it at least every three years. |
|
| Law by Decree No. 41 of 2022 concerning National Payments, Licensing and Security-Systems Duty |
Comply with the security and protection systems and procedures the Palestine Monetary Authority prescribes by instruction for a licensed payment-service or financial-technology company, apply them, and keep pace with their required development (Art. 8(2)(b)). |
|
| Cybersäkerhetslag, Cybersecurity Risk-Management Measures |
Register with the authority the government designates as soon as you can, per Cybersäkerhetsförordning (2025:1507) 5 §, and notify a change in what you registered within 14 days of the change. |
|
| Cyber Security Management Act, Specific Non-Government Agency Cyber Security Management |
Report to the competent authority for approval or recordation of the agency's assigned cyber security responsibility level, based on the sensitivity, volume and nature of the information the agency holds and the scale and nature of its information and communication systems. Comply with the central competent authority's periodic or ad hoc audits of the maintenance plan's implementation; a designated critical infrastructure provider's audit results are forwarded to the Ministry of Digital Affairs. |
|
| Telecommunications Management Act, Cyber Security and Critical Infrastructure Protection Plans |
Where the competent authority designates the enterprise's PSTN, in whole or in part, as critical telecommunications infrastructure, additionally draw up a critical telecommunications infrastructure protection plan before the competent authority's own deadline, submit it for the competent authority's evaluation before implementing it, and comply with the technical specifications for info-communications security evaluation the competent authority sets for that infrastructure. |
|
| Loi n° 2018-026, opérateurs de services essentiels and the National Cybersecurity Agency (ANCy) |
Once designated, comply with the cybersecurity rules for protecting your essential infrastructure that a decree in Council of Ministers fixes under Article 3, and expect the Agence nationale de la cybersécurité (ANCy) to control, audit and inspect your compliance with them. |
|
| Cybersecurity Act 2025, Critical Infrastructure Operator Obligations from a date not yet set |
Once designated, register with the Minister CPR, notify the Minister CPR of any change in your legal ownership or in the person or entity operating the infrastructure, and conduct and submit periodic cybersecurity self-assessments to the Ministry CPR in the form and manner it prescribes. Comply with any minimum standards the Minister CPR issues for critical infrastructure, submit to the Minister CPR's periodic and ad hoc audits and inspections of your compliance, and comply with any order the Minister CPR makes to take remedial, protective or preventative action following an audit, an assessment, or a reported incident. |
|
| Law No. 40 of 2006 on Electronic Payment Systems and Financial and Banking Operations, Secure-Services and Banking-Confidentiality Duty |
Comply with the Central Bank of Yemen's Bank Law, Banks Law, and the related regulations and instructions issued for electronic funds transfer operations. |
Security baseline statutes
19 laws, 18 places| Place | Law | What it asks, as read here |
|---|---|---|
| Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, articles 6, 7, 13-14, 24, 26-30, 32, 61(3) (mesures de sécurité et audit de sécurité obligatoire par l'ANTIC) |
Have Cameroon's National Information and Communication Technologies Agency (ANTIC) approve the security mechanisms you put in place for this purpose. Submit your networks and information systems to ANTIC's mandatory security audit, conducted at least once a year or whenever circumstances require it. +1 more |
|
| Cybersecurity Law: Network and Information System Security Duty |
Put in place technical mechanisms addressing threats to your systems' permanent availability, integrity, authentication, non-repudiation and data confidentiality, and to their physical security, and submit those mechanisms to the Agence Nationale de la Cybersécurité for approval. |
|
| Adoption of cybersecurity controls by businesses, exemption from punitive damages |
The program must conform to the current version of a named framework (the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53/53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, or the ISO/IEC 27000-series), or, for an entity already regulated under HIPAA, Gramm-Leach-Bliley Title V, FISMA or HITECH, conform to that regime, or comply with the PCI Data Security Standard together with another listed framework; conform to a revised version within six months of its publication. |
|
| Decreto No. 360/2019 and its Reglamento de Seguridad de las TIC (Resolución 128/2019), TIC Security System duty |
If you produce equipment or provide network, program, application or IT services, whether from inside or outside Cuba, implement the requirements that guarantee the secure operation of the equipment and services you supply; obtain a Ministry of Communications operating license before offering TIC security services to a third party, a license reserved to a state entity whose staff reside permanently in the country. |
|
| Digital Code, Livre IV: Digital Services Provider Security Obligations |
Submit your information system to controls the Agence Nationale de Cybersécurité conducts to verify its security level and its compliance with security rules, at your own cost. |
|
| Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, System-Security Duty on a System Manager |
Take the security precautions and measures the executive regulations of this Law prescribe. A negligent failure to do so that results in your website, private account, email account, or information system being exposed to a crime under this Law carries imprisonment of not less than six months plus a fine of EGP 10,000 to 100,000. |
|
| Sécurité des systèmes d'information (dispositions communes) |
Deploy technical mechanisms addressing threats to your systems' continuous availability, integrity, authentication, resistance to repudiation by third-party users, data confidentiality and physical security, and have those mechanisms cleared for conformity with the competent administrative authority's cybersecurity policy. Retain your systems' connection and traffic data for ten years, and submit your networks and information systems to a mandatory, periodic security audit on terms a regulation sets. |
|
| Cybersecurity Act, Cybersecurity Standards and Enforcement |
Comply with the cybersecurity standards the Cyber Security Authority develops, establishes, adopts and publishes on its website, which by section 59(1) cover education and skills development, hardware and software engineering, governance and risk management, research and development, and any other area the Authority determines in line with international best practice. |
|
| Tort Liability for Cybersecurity Programs, affirmative defense for a reasonable security program |
Satisfy the framework requirement by reasonably conforming the program to a named industry-recognized cybersecurity framework (the NIST framework for improving critical infrastructure cybersecurity, NIST SP 800-171, NIST SP 800-53 and 800-53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, or the ISO/IEC 27000 family), or, where already regulated under one, by conforming the program to the entirety of HIPAA's Security Rule, Gramm-Leach-Bliley Title V, the federal Information Security Modernization Act of 2014, HITECH, Iowa's own Insurance Data Security Act (chapter 507F), or applicable federal critical-infrastructure-protection rules, or by combining PCI Data Security Standard compliance with one of the named frameworks; conform the program to a revised framework or amended regulation within one year of its publication or effective date. |
|
| Digital Code, general cybersecurity duty on digital-object owners and holders |
Also follow the specific requirements set by the Law of the Republic of Kazakhstan "On Cybersecurity" and the unified digitalization and cybersecurity requirements adopted under it; their own specific duties are not further detailed here. |
Show the other 9 laws
| Digital Code, digital resilience baseline security measures |
Follow any measure the sectoral regulator for your sector directs you to take to prevent an incident in the digital environment or reduce its negative consequences; the regulator may issue binding instructions to that effect. |
|
| Ley Federal de Protección al Consumidor, Electronic Transaction Security Duty (Arts. 76 Bis, 76 Bis 1) |
Follow the Secretaria de Economia's Norma Mexicana for electronic commerce, which requires among other things reliable technical security mechanisms that guarantee the protection and confidentiality of the consumer's personal information and of the transaction itself. |
|
| Security measures for a data collector accepting payment cards, encryption duty, and conditioned liability shield from a date not yet set |
If you accept a payment card in connection with a sale of goods or services to a Nevada resident, comply with the current version of the Payment Card Industry (PCI) Data Security Standard adopted by the PCI Security Standards Council, with respect to those transactions, by the compliance date the standard itself sets. |
|
| Security measures for data collectors maintaining personal information from a date not yet set |
If you are a governmental agency, additionally comply, to the extent practicable, with the current version of the CIS Controls published by the Center for Internet Security or the corresponding National Institute of Standards and Technology standards, with respect to the collection, dissemination, and maintenance of those records. |
|
| Ohio Data Protection Act, cybersecurity program safe harbor |
Make the program reasonably conform to the current version of the NIST Cybersecurity Framework, NIST Special Publication 800-171, NIST Special Publications 800-53 and 800-53A, the FedRAMP security assessment framework, the CIS Critical Security Controls, or the ISO/IEC 27000 family, alone or in combination, or, if already regulated under it, reasonably conform to the entirety of the HIPAA security rule, Gramm-Leach-Bliley Act Title V, the Federal Information Security Modernization Act, or HITECH, or comply with the PCI Data Security Standard together with one of the first group's frameworks. |
|
| Proyecto de Ley 9906/2024-CR, Ley de Seguridad Digital o Ciberseguridad proposed |
If enacted as introduced, expect a duty to cooperate with public authorities on national cybersecurity matters where you operate as a private legal person in Peru, and expect the Comite de Ciberseguridad the bill creates to address you with guidelines on countering security breaches rather than a specific, clock-bound technical duty. |
|
| Cybersecurity Affirmative Defense Act |
Build the program as a reasonable security program, a designated coordinator, procedures to detect, prevent and respond to a breach, employee training, and periodic risk assessments of network and software design, information handling, and data storage and disposal, adjusted as circumstances change, or have it reasonably conform to a current named framework: NIST SP 800-171; NIST SP 800-53 and 800-53A; the FedRAMP Security Assessment Framework; the CIS Critical Security Controls; the ISO/IEC 27000 family; the HIPAA Security Rule or Gramm-Leach-Bliley Title V regulations for information those regimes cover; or the PCI Data Security Standard for payment card information. |
|
| Law on Cybersecurity, general cybersecurity duties on cybersecurity subjects |
Comply with the cybersecurity requirements the State Security Service sets for protecting information systems and resources. |
|
| Cybersecurity Law, Information System Classification and Protection Measures |
At level 3 or level 4, and not on the Prime Minister's list of information systems critical to national security, perform every Article 10(1) task and, without discretion, promulgate cybersecurity design-and-operation rules, apply management measures meeting national cybersecurity standards, back up and store data protecting the system's components, inspect and supervise compliance, monitor the system, and respond to and remedy incidents; file a dossier proposing your system's level and put it into operation only once that level is approved. |
Vulnerability and incident reporting
5 laws, 5 places| Place | Law | What it asks, as read here |
|---|---|---|
| Cybersecurity Act, Duty to Report Cybersecurity Incident |
Where the institution is itself a cybersecurity service provider licensed by the Authority, also submit a periodic report on its operations, including any cybersecurity incident, within the period the Authority sets. |
|
| Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation duty |
Adhere to the policies, standards, and controls the Center issues for the institution's own sector, provide the Center the information it needs to do its work, and inform the Center of any incident that threatens cybersecurity or the security of cyberspace, taking every step necessary to prevent or avoid it. |
|
| Law on Cyber Security, Cyber-Attack Notification Duty for Other Legal Persons |
Abide by the Government's common procedure for ensuring, preventing, detecting and countering cyber-attacks once the Government adopts it under Article 7.1. Comply with the recommendations and requirements the relevant authorities issue to you in relation to ensuring cyber security. |
|
| Law on the Basic Principles of Ensuring Cybersecurity, CERT-UA Incident Notification Duty |
Where the incident information you exchange with CERT-UA or another party contains personal data, handle that exchange under the requirements of the Law on the Protection of Personal Data. |
|
| Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 252.204-7012) |
If this clause applies to your organization, provide adequate security on every covered contractor information system, implementing the security requirements of NIST Special Publication 800-171 unless the system is part of an information technology service the government operates on its own behalf, in which case follow the security requirements stated elsewhere in the contract. |
Product security requirements
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Security Standards for Smart Devices |
Publish, before supply, the period including an end date for which the device will receive security updates, provide or supply the product with a statement of compliance with the security standard, and retain a copy of that statement for five years. |
|
| Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment) |
Demonstrate this compliance to Anatel's conformity-assessment agent when you seek homologação for the device, or by presenting your own Cybersecurity Policy showing you meet the full set of supplier requirements; Anatel can suspend a homologação it already granted if it later finds a security flaw or vulnerability, and a suspended homologação bars the product from being distributed in the Brazilian market until the problem is fixed. |
|
| Cybersecurity Law, Network Product and Service Security Duties |
Meet the mandatory requirements of the applicable national standard for your product or service, and do not embed a malicious program in it. |
|
| Digital Code, Livre IV: ICT Product and Service Vendor Security Certification |
Apply to the Minister responsible for digital affairs for a compliance certificate, which issues only after a vulnerability analysis and a security-guarantee evaluation performed by information security experts the Minister has accredited. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.