Hong Kong Critical Infrastructure Cyber Ordinance
In force Hong Kong · In force Jan 1, 2026 · no upcoming deadlines
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
Hong Kong's critical infrastructure cybersecurity law. Designated critical infrastructure operators (CIOs) must keep a Hong Kong office, set up a computer-system security management unit, run risk assessments and audits, keep security and emergency plans, take part in drills, and report incidents. Serious incidents must be reported within 12 hours and other incidents within 48 hours.
- Who it applies to
- Operators designated by regulators in 8 sectors: energy, IT, banking and financial services, air transport, land transport, maritime transport, healthcare, and telecommunications and broadcasting (plus other infrastructure critical to society). Only designated CIOs and their designated critical computer systems are covered.
- Penalties
- Fines from HKD 300,000 up to HKD 5 million, plus daily fines for continuing offences.
- Enforced by
- Commissioner of Critical Infrastructure (Computer-system Security) under the Security Bureau; Hong Kong Monetary Authority and Communications Authority as designated authorities for their sectors
- Official name
- Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653)
- Citation
- Cap. 653
- Topics
- cybersecurity, breach-notification
Research notes
Gazetted 28 Mar 2025 (the date used as enacted_date); commencement notice gazetted 27 Jun 2025. Duties for each operator run from its designation date, so there is no fixed calendar deadline. The penalty range comes from the Baker McKenzie summary. Reporting windows come from the Code of Practice via Mayer Brown.
Related
Questions about Hong Kong Critical Infrastructure Cyber Ordinance
- What are the Hong Kong Critical Infrastructure Cyber Ordinance compliance deadlines?
- Jan 1, 2026: PCICSO comes into operation.
- When does Hong Kong Critical Infrastructure Cyber Ordinance take effect?
- Hong Kong Critical Infrastructure Cyber Ordinance took effect on Jan 1, 2026.
- Who does Hong Kong Critical Infrastructure Cyber Ordinance apply to?
- Operators designated by regulators in 8 sectors: energy, IT, banking and financial services, air transport, land transport, maritime transport, healthcare, and telecommunications and broadcasting (plus other infrastructure critical to society). Only designated CIOs and their designated critical computer systems are covered.
- What are the penalties under Hong Kong Critical Infrastructure Cyber Ordinance?
- Fines from HKD 300,000 up to HKD 5 million, plus daily fines for continuing offences.