Chile’s national cybersecurity law establishes a formal governance framework for cyber risk, incident reporting, and critical infrastructure protection. It assigns duties to public and private entities, creates oversight through the National Cybersecurity Agency, and requires operational practices that support compliance, response, and resilience across essential digital services.
How the law functions as a cybersecurity governance framework
Law No. 21.663 is best understood as Chile’s baseline cyber governance instrument: it turns cybersecurity from an internal IT concern into a formal legal duty with assigned responsibilities, oversight, and consequences for essential digital services. That makes it more than a policy statement, because it establishes who must act, when they must escalate, and how compliance is judged.
For readers, the practical significance is that the law creates an operating model for cyber risk rather than a single technical requirement. It links governance, incident handling, critical infrastructure protection, and resilience into one national framework, so organisations have to align internal controls with external accountability.
What obligations and controls it places on organisations
The law matters because it translates broad cyber objectives into organisational duties that affect readiness, reporting, and response. In practice, that means entities need defined ownership, documented processes, and evidence that cyber incidents can be detected, escalated, and handled within an oversight structure.
Those obligations are especially important for essential service providers and public sector bodies, where weak process discipline can become a regulatory issue as well as an operational one. A common mistake is to treat compliance as a paperwork exercise, when the underlying expectation is sustained control performance, not one-time documentation.
For a useful comparison point, Chile’s approach aligns with the wider governance logic seen in NIST Cybersecurity Framework 2.0, which also ties governance to protection, detection, response, and recovery.
Why incident reporting and resilience are central to the law
The law is not only about preventing breaches; it is also about ensuring that cyber events are reported, assessed, and contained quickly enough to limit damage. That makes resilience a legal and operational requirement, especially where service disruption would affect essential functions or broader national stability.
Because the law creates a structured response model, organisations need to think in terms of continuity, not just security tooling. The National Cybersecurity Agency’s oversight role also means that incident handling must be visible enough to support supervision, accountability, and cross-entity coordination.
That emphasis on resilient operations is consistent with incident-driven guidance such as CISA cyber threat advisories, which help organisations connect current threats to response and recovery priorities.
How to interpret the law in practice
Practitioners should read the law as a compliance and operating requirement, not just a legal citation. The right question is whether an organisation can prove ownership, reporting discipline, and recovery readiness across the systems that matter most, especially where critical services or regulated functions depend on them.
Another practical lens is that this law raises the value of security evidence: incident logs, governance records, escalation paths, and control testing become part of demonstrating preparedness. Organisations that already run mature governance, risk, and response processes will usually find it easier to adapt than those relying on informal security habits.
For broader control alignment, CISA Secure by Design reinforces the same principle that security outcomes improve when resilience and default protections are built into operating practice rather than bolted on later.
Risk and Threat Considerations
This law introduces real exposure if organisations treat compliance as symbolic instead of operational. Weak reporting discipline, poor coordination, or unclear accountability can leave incidents undisclosed for too long, while critical services remain vulnerable to disruption, escalation, or repeated compromise.
Failure mechanism: Organisations fail when governance exists on paper but incident detection, escalation, and recovery are not exercised in practice, especially across complex essential-service environments.
Impact: Delayed containment, wider service disruption, regulatory breach, and reduced national or sector resilience can follow, particularly where one compromised provider has downstream effects on many dependent services.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV — Govern | The law is a national cyber governance framework with oversight and accountability duties. |
| RS — Respond | It requires incident reporting and coordinated response across affected entities. | |
| RC — Recover | Its resilience focus requires continuity and restoration planning for essential services. | |
| Recommendation — Establish governance ownership, oversight, and risk accountability for cyber obligations. Define and exercise incident reporting and response procedures for regulated events. Test recovery plans and restoration priorities for essential digital services. | ||
| CIS Controls v8 | 17 — Incident Response Management | Formal reporting and response duties depend on structured incident handling. |
| 11 — Data Recovery | Critical service resilience depends on restoration capability after cyber events. | |
| Recommendation — Document, test, and improve incident reporting and response workflows. Verify restoration capabilities for systems that support essential services. | ||
| NIS2 | s21 — Cybersecurity risk-management measures | NIS2 captures governance and resilience duties similar to national essential-service requirements. |
| s23 — Reporting obligations | The law’s incident reporting model maps directly to mandatory notification duties. | |
| Recommendation — Align risk-management measures with legal duties for essential-service resilience. Set reporting thresholds and notification timelines for significant incidents. | ||
Practitioner Guidance
Governance implication: Treat the law as an ownership and evidence problem, not only a legal review problem. Assign clear responsibility for reporting, response, and resilience outcomes, then make sure those responsibilities are supported by testable procedures and audit-ready records.
What to watch for: The highest-risk gap is usually not a missing policy, but an inability to prove that the organisation can execute the policy during a real incident. If reporting chains, recovery steps, and oversight duties are unclear, compliance will fail when the event is live.
Practitioner takeaway: The strongest implementation pattern is to connect legal obligations, operational controls, and incident drills into one management system so that compliance and resilience reinforce each other.
Related resources from NHI Mgmt Group
- What do teams get wrong when they use the Cybersecurity Framework for incident response?
- Why do export controlled information programs need both export law controls and cybersecurity controls?
- How should organisations choose a cybersecurity framework for client environments with different regulatory and customer requirements?
- How should security teams implement a broad cybersecurity framework across multiple compliance obligations?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org