Skip to content

Hong Kong Critical Infrastructure Cyber Ordinance

In force Hong Kong · In force Jan 1, 2026 · no upcoming deadlines

Deadlines

DateWhat happens
Jan 1, 2026PCICSO comes into operation9 months ago

Summaries for reference, not legal advice. Check the official text.

What it does

Hong Kong's critical infrastructure cybersecurity law. Designated critical infrastructure operators (CIOs) must keep a Hong Kong office, set up a computer-system security management unit, run risk assessments and audits, keep security and emergency plans, take part in drills, and report incidents. Serious incidents must be reported within 12 hours and other incidents within 48 hours.

Who it applies to
Operators designated by regulators in 8 sectors: energy, IT, banking and financial services, air transport, land transport, maritime transport, healthcare, and telecommunications and broadcasting (plus other infrastructure critical to society). Only designated CIOs and their designated critical computer systems are covered.
Penalties
Fines from HKD 300,000 up to HKD 5 million, plus daily fines for continuing offences.
Enforced by
Commissioner of Critical Infrastructure (Computer-system Security) under the Security Bureau; Hong Kong Monetary Authority and Communications Authority as designated authorities for their sectors
Official name
Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653)
Citation
Cap. 653
Topics
cybersecurity, breach-notification
Verified 2026-09-22 info.gov.hk coms-auth.hk mayerbrown.com
Research notes

Gazetted 28 Mar 2025 (the date used as enacted_date); commencement notice gazetted 27 Jun 2025. Duties for each operator run from its designation date, so there is no fixed calendar deadline. The penalty range comes from the Baker McKenzie summary. Reporting windows come from the Code of Practice via Mayer Brown.

Related

Questions about Hong Kong Critical Infrastructure Cyber Ordinance
What are the Hong Kong Critical Infrastructure Cyber Ordinance compliance deadlines?
Jan 1, 2026: PCICSO comes into operation.
When does Hong Kong Critical Infrastructure Cyber Ordinance take effect?
Hong Kong Critical Infrastructure Cyber Ordinance took effect on Jan 1, 2026.
Who does Hong Kong Critical Infrastructure Cyber Ordinance apply to?
Operators designated by regulators in 8 sectors: energy, IT, banking and financial services, air transport, land transport, maritime transport, healthcare, and telecommunications and broadcasting (plus other infrastructure critical to society). Only designated CIOs and their designated critical computer systems are covered.
What are the penalties under Hong Kong Critical Infrastructure Cyber Ordinance?
Fines from HKD 300,000 up to HKD 5 million, plus daily fines for continuing offences.

When the rules change: new data, privacy and AI laws and deadlines, the next morning.