Iceland's product-security and cyber-resilience law rests on Act No. 78/2019 on the Security of the Network and Information Systems of Critical Infrastructure, Iceland's transposition of the EU's original NIS Directive (2016/1148), in force since 1 September 2020.
The Act binds an operator of essential services in banking and financial-market infrastructure, transport, health services, and energy, heating and water utilities, and, separately, an operator of essential services in the digital-infrastructure sector (an internet exchange point, a domain-name-system service provider, or a top-level domain registry) and a provider of digital services operating an online marketplace, an online search engine, or a cloud computing service, excluding a provider that qualifies as a micro-enterprise.
Article 7 sets a documented risk-management and preparedness duty and Article 8 a duty to notify Iceland's national cybersecurity incident-response team of a serious incident or risk as soon as may be, carrying no fixed hour-based reporting clock of its own; a breach of either duty draws an administrative fine of up to ISK 10,000,000, capped at 3 percent of turnover for a legal entity, a separate daily coercive fine of up to ISK 500,000 for ignoring a supervisory order, and an intentional breach is separately punishable by up to two years' imprisonment.
Fjarskiptastofa, the Post and Telecom Administration, supervises the digital-infrastructure sector and every digital-service provider; the other essential-service sectors each answer to their own regulator (the Financial Supervisory Authority for banking and financial-market infrastructure, the Transport Authority for transport, the Directorate of Health for health services, and the Environment and Energy Agency for energy, heating and water utilities), a population no declared LexLint activity expresses, so it is described here without a coded row.
Iceland's national cybersecurity incident-response team moved from Fjarskiptastofa to the Ministry for Foreign Affairs under Act No. 51/2025, in force 22 July 2025, which also separated the response team from the supervisory authority by law.
The EU's NIS2 Directive (2022/2555), which would replace this Act's scope and reporting clock with a broader sector list and a tiered 24-hour, 72-hour and one-month clock, had not been incorporated into the EEA Agreement or transposed into Icelandic law as of 15 September 2026: the government's own EEA-incorporation database records the directive as still under review by Iceland, Liechtenstein and Norway, with domestic implementation work not begun and Althingi's own assessment not yet complete.
The Cyber Resilience Act (Regulation (EU) 2024/2847) sits at the same pre-incorporation status in the same database, so no EU-level requirement for a manufacturer placing a product with digital elements on the market yet binds in Iceland.
Regulation (EU) 2022/2554 (DORA) is the one EU cyber-resilience instrument already incorporated and implemented, through Act No. 78/2025, in force 1 January 2026, which routes banking and financial-market-infrastructure incident notification to DORA instead of Article 8 of this Act; DORA's financial-entity duty-bearer is a role no declared LexLint activity expresses, so it is recorded here rather than coded as an instrument.
No general reasonable-security or information-security-programme statute outside this Act and outside the Data Protection Act's own security-of-processing clause (Act No. 90/2018, documented as this jurisdiction's privacy-topic instrument rather than repeated here) was found.