Chile adjusts cybersecurity obligations
Chile opened a public consultation on mandatory baseline standards under Law 21.663 and added reporting rules for Defense and essential providers.
Chile opened a public consultation on the rules that will set mandatory baseline cybersecurity standards under Law 21.663, while ANCI continues defining which entities are covered and the Defense sector added specific reporting rules to CSIRT-DN.
Update August 25, 2026: ANCI opened a public consultation on the rules that will set mandatory baseline cybersecurity standards under Law 21.663, and Defense was brought under a specific reporting regime to CSIRT-DN. The agency had also already asked certain essential providers to complete forms to assess the risk and impact of incidents.
New regulatory requirements
Law 21.663 creates a regulatory framework designed to push better risk management, security and digital continuity practices across organizations of all kinds, although the toughest obligations are aimed at critical sectors. Chilean outreach materials also say the law requires an Information Security Management System, the designation of a cybersecurity lead, and incident reporting procedures, presenting it as a broad change for organizations operating in the country.
What did ANCI add now?
ANCI opened the public consultation on the rules that will establish mandatory baseline cybersecurity standards for entities subject to Law 21.663. According to Exempt Resolution 140, dated May 30, 2026, the process remained open for 30 calendar days from its publication in the Official Gazette.
Specialized outlets such as TrendTIC reported that the agency published the proposal and enabled comments until June 29, 2026 at 11:59 p.m., with the stated goal of moving forward on the implementation of the country's main regulatory framework. Ley21663.info later said that, as of August 5, 2026, the final text still had not been published.
Estado Diario described the proposal under review as organizing nine operational measures that serve as a technical floor of due diligence for essential services, including regular system updates, recurring training, privilege minimization, regular backups, network segmentation, firewall use and intrusion detection and prevention systems. MLV Abogados said the consultation seeks to make 6 of the so-called 9 basic cybersecurity measures mandatory, with controls that include updating, training, minimizing privileges, backing up, securing networks, securing devices, real-time monitoring, MFA and a password manager.
| Milestone | Date | Scope | Source |
|---|---|---|---|
| Public consultation on mandatory baseline standards | May 30, 2026 | Open for 30 calendar days from publication | Exempt Resolution 140, LeyChile |
| Comment deadline reported by specialized press | June 29, 2026, 11:59 p.m. | Close of comments on the ANCI portal | TrendTIC |
| Final text still pending | August 5, 2026 | The rule had not yet been published | Ley21663.info |
Who was covered by the first qualification process?
ANCI also began organizing the regulated universe. According to Exempt Resolution 87, dated December 17, 2025, the agency required essential service providers in categories such as digital services, digital infrastructure and managed third-party IT to complete a form to assess the risk and impact of potential cybersecurity incidents.
TrendTIC added that the first qualification process distinguished between Essential Services and Operators of Vital Importance, and that the roster of OIVs fell from 1,712 to 915 in December 2025. The focus, according to that coverage, was to concentrate the regulatory burden on entities whose compromise through cyberattacks could affect security, public order or the continuity of critical services.
What changed for Defense?
The Defense sector was also required to report cyberattacks and cybersecurity incidents that could have significant effects to CSIRT-DN. Decree 2, dated December 31, 2025, also set strict deadlines for that notification scheme.
Actualidad Jurídica of the Official Gazette said the rule requires early alerts within three hours for relevant incidents, a status update report within intermediate deadlines and a final report within a maximum of 15 days. That analysis also said the regime includes specific confidentiality rules based on Law 21.663, Law 20.285 and the Military Justice Code.
Personal data and penalties
In data protection, training materials in Chile say [Law 21.719](/en/news/chile-data-protection-law-takes) significantly raises the fines and penalties that apply to public and private organizations that process personal data without complying with the rules. That description places the law as a structural change in the sanctioning regime, with a direct impact on internal compliance, processing and safeguarding of personal information.
Deadlines and implementation uncertainty
The regulatory transition still has gray areas. A LinkedIn post by Valentina Palma, a lawyer specialized in data protection in Chile, says there are implementation obligations under the new Law 21.719 with a milestone on December 1, but criticizes the fact that by then there were still no minimum certainties about how the authority and the needed regulations would operate. That argument reflects regulatory uncertainty in the adjustment process.
The debate comes as different local explanatory materials have been mapping the practical scope of Law 21.663, from ANCI's role in regulation and oversight to the need to prepare for a more formal incident, security and privacy management scheme. In that setting, the focus is no longer just on adopting technical controls, but on maintaining proof of compliance across two legal frameworks that are starting to impose stricter order on digital operations in Chile.
Sources
- Ciberseguridad, Protección de Datos y Gestión Digital - Cambios regulatorios en Chile (Ley 21.663 y Ley 21.719)goose-design.com· Goose
- Publicación en Instagram sobre cambio de dominio TGR y referencia a Ley 21.663 (SGSI, CISO y reporte de incidentes)instagram.com· Tesorería General de la República de Chile
- Reel en Instagram sobre impacto de la Ley 21.719 de protección de datos personales en Chileinstagram.com· Educación Continua DCC – Universidad de Chile
- SOC Chile — Centro de Operaciones de Seguridadnbitek.com· Nbitek
- Servicio Red Team – Seguridad Ofensiva Ciberseguridad Chilenbitek.com· Nbitek
- Mayor fiscalización: La ANCI tiene el poder de regular y supervisar – Ley 21.663instagram.com· Cuenta de divulgación en ciberseguridad en Chile
- Publicación en LinkedIn sobre puntos clave de la Ley 21.663es.linkedin.com· A3Sec
- Post en Facebook sobre datos sensibles y definiciones de la Ley 21.663facebook.com· Rodolfo Marín
- Resumen sobre intentos de ciberataques y exigencias de la Ley 21.663instagram.com· Cuenta de formación en ciberseguridad en Chile
- Reel: Ley Marco de Ciberseguridad, desafío estratégico para el Estadoinstagram.com· Cuenta de divulgación sobre Ley Marco de Ciberseguridad
- ANCI inicia consulta pública para definir los estándares básicos obligatorios de ciberseguridad en Chiletrendtic.cl· TrendTIC
- Consulta de estándares básicos de ciberseguridad: ad portas de la obligatoriedadestadodiario.com· Estado Diario
- Resolución 140 Exenta (30-may-2026) M. de ...bcn.cl· Biblioteca del Congreso Nacional de Chile (LeyChile)
- Reglamentos de la Ley 21.663: los 7 decretos vigentes y los estándares básicos obligatorios (pendientes)ley21663.info· Ley21663.info
- Decreto 2 (31-dic-2025) M. de Defensa Nacionalbcn.cl· Biblioteca del Congreso Nacional de Chile (LeyChile)
- ANCI disminuye de 1712 a 915 los Operadores de Importancia Vital (OIV)trendtic.cl· TrendTIC
- Proceso de consulta pública: 9 básicos de la Ciberseguridadamlv.cl· MLV Abogados
- Resolución 87 Exenta (17-dic-2025) M. de ...bcn.cl· Biblioteca del Congreso Nacional de Chile (LeyChile)
- Defensa Nacional aprueba reglamento de ciberseguridadactualidadjuridica.doe.cl· Actualidad Jurídica DOE
- Publicación sobre desafíos de implementación y plazos de la nueva ley de protección de datos en Chilees.linkedin.com· Valentina Palma (LinkedIn)



