Jordan's cyber-resilience framework rests on the Cyber Security Law No. (16) of 2019, which establishes the National Cyber Security Council and the National Cyber Security Center (the Center) and, in Article 8(b), imposes a duty that reaches beyond government: every ministry, government department, and official, public, private, or civil institution must adhere to the policies, standards, and controls the Center issues for its sector, provide the Center the information it needs to do its work, and inform the Center of any incident that threatens cybersecurity or the security of cyberspace, taking every step necessary to prevent or avoid it.
The Center's own Incident Classification Instructions (2023, amended by National Cyber Security Council Decision No. 37 of 2025) define the bound entity to include any ministry, public or private institution, government department, civil institution, association, company, or individually registered establishment in the Kingdom, which confirms the duty's reach to an ordinary private company rather than only a government-designated class, and set four incident-severity tiers (Critical, High, Medium, Low) keyed to whether an incident disrupts essential services, exposes sensitive data, or touches a critical-infrastructure, security, military, government, or higher-education target; an incident confined to a private company or an individual establishment with no such touchpoint is typically classified Medium or Low.
The Center's Cyber Security Incident Response and Reporting Policy (2025, twice amended that year) sets the operative clock: its Table 1 gives a Critical-tier incident a reporting window as short as 30 minutes, tapering through roughly 1 hour for High, 4 hours for Medium, and 1 day for Low, alongside separate containment and resolution windows in the same table, and names a hotline, an email address, and the JOCERT portal (jocert.ncsc.jo) as the reporting channels.
Where the Council designates an incident a threat to the Kingdom's own security and safety under Article 9, the Center directs the response and every institution involved must follow its instructions.
Layered on top of that general duty, the Center has separately identified critical-infrastructure sectors in its own sector-identification document and published a dedicated set of critical-infrastructure cybersecurity controls (guidance, a controls list, a sector-mapping annex, and a threat annex); because the bound party there is a government-designated critical-infrastructure operator rather than an activity this corpus's vocabulary can express, that sub-regime is deferred rather than flagged on a guess, the same treatment this profile gives DORA's financial entities and NY DFS Part 500's covered entities.
Article 10 separately prohibits providing cybersecurity services in Jordan without a Center-issued license, implemented by a 2024 Licensing System for Cybersecurity Service Providers and a 2025 instructions document grading fines by violation type (a range of roughly 500 to 5,000 dinars depending on the specific violation) and, separately, by an affected incident's own severity tier (up to a 50,000-to-100,000-dinar band where the incident is Severe), all within Article 16's own 500-to-100,000-dinar statutory range; because the bound party is a firm that sells cybersecurity services rather than an activity in this corpus's vocabulary, that licensing duty is deferred and named here rather than filed as an instrument.
The Central Bank of Jordan separately maintains bank-specific cyber-risk instructions, Instructions for Adapting to Cyber Risks No. (1984/1/1/26) of 6 February 2018 for licensed banks and Instructions for Adapting to Cyber Risks for Licensed Exchange Companies No. (17/2018), both listed on the Central Bank's own instructions page; because the bound party is a bank or a licensed money-exchange company, a role this corpus's activity vocabulary cannot express, this sector regime is deferred in the same way as New York's DFS Part 500.
The Telecommunications Regulatory Commission's own instructions listing serves no readable content to either a compliant or a stealth browser, so whether it publishes an equivalent telecom-specific cybersecurity instruction is not established; if one exists, it would in any event bind a licensed telecom operator, a role outside today's activity vocabulary.
No enacted Jordanian statute was found setting security requirements a connected device or software product must meet before or after it reaches the market, so the product-requirements dimension is recorded as a researched absence rather than a gap in coverage.
Enforcement of the Article 8 duty and the Law generally runs through the Center itself: Article 16 lets the Center impose a written warning, an order to correct the violation and reimburse the Center's resulting costs, blocking, cancellation, confiscation, or disabling of the offending communications network, information system, or device, a requirement that the institution take legal measures against a responsible employee, suspension or cancellation of a cybersecurity-services license, or a fine of not less than 500 and not more than 100,000 Jordanian dinars, doubled for a repeated violation; nothing in the Law creates a private right of action, and Article 16's own enumerated remedies are the only route to relief.
Article 13 gives the Center's president and delegated staff judicial-police powers, including a right to search premises and to organize the arrest of a violator, but this reaches an active cyber-attacker rather than an institution that merely misses its own reporting duty under Article 8, and the Law's own penalty ladder in Article 16 carries no criminal sentence of its own. No published enforcement record specific to Article 8 was located.
Jordan's data breach-notification duty, and any safeguards clause inside its comprehensive data-protection regime, already sit in this jurisdiction's privacy row (Personal Data Protection Law No. 24 of 2023, Article 20) and are not repeated here, and the Cybercrime Law No. 17 of 2023's unauthorized-access offenses already sit in this jurisdiction's scraping row rather than here.