Mongolia's cyber-resilience law is the Law of Mongolia on Cyber Security (Кибер аюулгүй байдлын тухай), adopted by the State Great Khural of Mongolia on 17 December 2021 and in force since 1 May 2022; a February 2025 Oxford Global Cyber Security Capacity Centre review and a 15 September 2026 search found no subsequent repeal or substantive amendment to the Law itself, though Mongolia's Criminal Code and its Laws on Communications, Violations, and Criminal Procedure were amended alongside the Law's original enactment to align cybercrime definitions with the Council of Europe's Budapest Convention, a change already reflected in this jurisdiction's scraping row rather than repeated here.
The Law binds four separate classes of legal person, and only one of the four reaches a declared LexLint activity.
A state-owned legal person (Art. 16, drawing its definition of 'state-owned legal person' from Article 13 of the Law on State and Local Properties) and a legal person providing information technology services in the processing, storing, distributing, computer-analytics, and shared-information-system-hosting sense of Article 17.1, both, like an organization with critical information infrastructure under Article 19 (a Government-adopted list spanning 17 named categories of business from power and water utilities to banks, fuel importers, strategic-mineral miners, and border-crossing control systems), are classifications this corpus's activity vocabulary cannot express: Article 17.1's shared-information-system hosting, processing and analytics description falls on the browser-or-API side of the line distributes_software_product's own definition draws, and none of the three classes names a specific digital-service category the way NIS2 names social networking platforms, marketplaces or search engines, so all three are recorded here rather than raised against a guessed activity, the same treatment this profile gives Singapore's five Cybersecurity Act bound-party classes and DORA's financial entities.
Article 17.1's duties for the class it does reach, an internal procedure, an officer or unit for cyber security, biennial risk assessments, annual information-security audits, a check on new information-technology products and their updates, and immediate notification of both the relevant center and affected users on a cyber-attack, and Article 19's parallel and heavier set for a critical-information-infrastructure operator, annual risk assessments, biennial audits, an action plan, a detection-and-termination system, and notification within one month of receiving a risk-assessment or audit report, are both real, substantial law, unreached by this topic's export for the same activity-vocabulary reason.
The fourth class, 'legal persons other than that stipulated in article 17.1' (Art. 17.3), is the residual catch-all that reaches every other legal person conducting activity in Mongolia's cyberspace, extended by Article 3.2 to a foreign or foreign-invested legal person operating through Mongolia's information systems and networks; it is the row raised as this jurisdiction's one security-topic instrument, flagged inclusively across this topic's baseline activity set because the duty carries no sector or personal-data gate at all.
The Law sets no security requirement a software product or connected device must meet to be placed on the market and no support-period or update duty running with a product once sold; the nearest text, Article 17.1.8's duty for an information-technology-service legal person to check its own new products and updates, is an operational duty on that narrower class rather than a market-placement regime, and it too sits inside the Article 17.1 deferral.
Enforcement of the Law runs through Article 24, which imposes an official's liability under the Law on Public Service or the Labor Law for non-criminal conduct (Art. 24.1) and a violator's liability under the Criminal Law or the Law on Violations (Art. 24.2, covering both an individual and a legal person) without stating a specific offense or a penalty figure in the Law's own text; the Criminal Law and the Law on Violations are not described here, so no penalty_structure is recorded for the instrument below.
Mongolia's breach-notification duty for personal data sits in the Law on Protection of Personal Data, already this jurisdiction's privacy row; an unauthorized-access or computer-misuse offense sits in the Criminal Code's Chapter 25/26 computer-crime provisions, already this jurisdiction's scraping row, and neither is repeated here.