#Ley 21.663
This archive brings together coverage of Chile’s cybersecurity regulatory framework and its effects on public agencies, operators, and companies that must adapt processes, controls, and reporting obligations. It includes analysis, regulatory updates, and sector commentary on how this agenda is reshaping risk management and incident response across the region.
Chile CMF sets new cybersecurity rules
The CMF consolidates duties for banks and payment issuers on operational risk, strong authentication and incident reporting.
Sep 14, 2026 · 3 min
Chile CMF adjusts fraud reporting rule
The CMF removed a semiannual fraud-reporting duty for cases already posted on websites. Law 21,663 adds new cybersecurity obligations.
Sep 10, 2026 · 2 min
Chile extends data protection law timeline
Chile is seeking more time to roll out Law 21,719 as Law 21,663 already has active penalties and 1,154 critical operators.
Sep 7, 2026 · 3 min
Chile's CMF tightens bank security rules
Chile’s CMF activates NCG 583, ending coordinate cards and requiring stronger authentication for transfers and digital onboarding.
Sep 3, 2026 · 3 min
Chile CMF Enforces New Authentication Rule
Chile’s CMF puts NCG 583 into effect, requiring stronger authentication for payments, transfers and digital onboarding.
Sep 1, 2026 · 3 min
Chile’s data law takes effect in 2026
Law 21.719 takes full effect on Dec. 1, 2026, replacing Law 19.628, creating a new agency and setting fines.
Aug 3, 2026 · 4 min
Chile tightens cyber reporting
Law 21.663 requires a 3-hour alert, a 72-hour update and a 15-day final report, with fines reaching 40,000 UTM.
Jul 14, 2026 · 2 min
Chile adjusts cybersecurity obligations
Chile opened a public consultation on mandatory baseline standards under Law 21.663 and added reporting rules for Defense and essential providers.
Jul 8, 2026 · 4 min
Chile Sets Incident Reporting Deadlines in Hours
Chile’s ANCI has put in place a phased notification scheme for critical incidents
Jul 6, 2026 · 2 min