Belarus has one enacted, in-force instrument that imposes a security-posture duty on a private-sector information system operator, distinct from a personal-data trigger and from an intruder-facing computer-misuse offense: article 40 of Law No. 455-Z of 10 November 2008 On Information, Informatization and Protection of Information.
The article obliges an information system operator, defined broadly enough to include a private legal entity or an individual entrepreneur, to ensure the integrity and safety of the information its system holds and to take measures against disclosure, loss, distortion, destruction, unauthorized modification, and illegitimate blocking of access to that information.
No product-placement or connected-device security regime comparable to the Cyber Resilience Act or the United Kingdom's product-security regime is confirmed present in Belarus: no statute sets security requirements a software product or connected device must meet before or after it reaches the market, and no update, support-period, or vulnerability-disclosure duty binds a manufacturer as such.
No vulnerability or incident-reporting regime running to a computer emergency response team or a sector authority is confirmed either. The only reporting clock this corpus holds for Belarus is the personal-data breach notice to the National Center for Personal Data Protection within three working days, which belongs to Law No. 99-Z's own record under the privacy topic and is not restated here as a security duty.
No sector-specific cyber-resilience regime naming a digital service, a financial entity, or a telecommunications operator is confirmed present in Belarus. A Presidential decree or a National Bank directive addressing information security specifically, separate from Decree No. 8's digital-economy and High Technologies Park regime, is neither confirmed to exist nor confirmed absent from the sources reachable here, and stays an open question for the corpus rather than a recorded absence.
Law No. 455-Z's own chapter on public administration assigns rulemaking competence over informatization to the Ministry of Communications and Informatization and competence over technical and cryptographic protection of information to the Operation and Analysis Center under the President, and either body's subordinate regulatory acts could plausibly narrow or extend article 40's baseline duty; neither is authored as an instrument here, because neither body's own regulatory text is confirmed available.
Belarus's Criminal Code (Law No. 275-Z), articles 349, 350, 352, 354, and 355, is already filed in this corpus under the scraping topic's computer_misuse family. Those articles punish a person who defeats a protection system, unlawfully acquires computer information, distributes a circumvention tool, or negligently breaches operating rules while holding lawful access, all offenses against the system rather than a duty on its operator, so no row is added here on top of that filing.
Law No. 99-Z On Personal Data Protection carries its own security, breach-notice, and governance duties for personal data specifically, already filed under the privacy topic as the comprehensive regime Belarus's data-protection law is. Article 40 of Law No. 455-Z binds an information system operator regardless of whether the information the system holds is personal data, so the two duties reach different triggers and neither restates the other.
Decree No. 8 On Development of the Digital Economy and the Law On Investments remain filed as compute and investment-incentive instruments and are not restated here.