CiberLATAMbywhalemate

Chile adjusts cybersecurity obligations

Chile opened a public consultation on mandatory baseline standards under Law 21.663 and added reporting rules for Defense and essential providers.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

Chile opened a public consultation on the rules that will set mandatory baseline cybersecurity standards under Law 21.663, while ANCI continues defining which entities are covered and the Defense sector added specific reporting rules to CSIRT-DN.

Update August 25, 2026: ANCI opened a public consultation on the rules that will set mandatory baseline cybersecurity standards under Law 21.663, and Defense was brought under a specific reporting regime to CSIRT-DN. The agency had also already asked certain essential providers to complete forms to assess the risk and impact of incidents.

New regulatory requirements

Law 21.663 creates a regulatory framework designed to push better risk management, security and digital continuity practices across organizations of all kinds, although the toughest obligations are aimed at critical sectors. Chilean outreach materials also say the law requires an Information Security Management System, the designation of a cybersecurity lead, and incident reporting procedures, presenting it as a broad change for organizations operating in the country.

What did ANCI add now?

ANCI opened the public consultation on the rules that will establish mandatory baseline cybersecurity standards for entities subject to Law 21.663. According to Exempt Resolution 140, dated May 30, 2026, the process remained open for 30 calendar days from its publication in the Official Gazette.

Specialized outlets such as TrendTIC reported that the agency published the proposal and enabled comments until June 29, 2026 at 11:59 p.m., with the stated goal of moving forward on the implementation of the country's main regulatory framework. Ley21663.info later said that, as of August 5, 2026, the final text still had not been published.

Estado Diario described the proposal under review as organizing nine operational measures that serve as a technical floor of due diligence for essential services, including regular system updates, recurring training, privilege minimization, regular backups, network segmentation, firewall use and intrusion detection and prevention systems. MLV Abogados said the consultation seeks to make 6 of the so-called 9 basic cybersecurity measures mandatory, with controls that include updating, training, minimizing privileges, backing up, securing networks, securing devices, real-time monitoring, MFA and a password manager.

Milestone Date Scope Source
Public consultation on mandatory baseline standards May 30, 2026 Open for 30 calendar days from publication Exempt Resolution 140, LeyChile
Comment deadline reported by specialized press June 29, 2026, 11:59 p.m. Close of comments on the ANCI portal TrendTIC
Final text still pending August 5, 2026 The rule had not yet been published Ley21663.info

Who was covered by the first qualification process?

ANCI also began organizing the regulated universe. According to Exempt Resolution 87, dated December 17, 2025, the agency required essential service providers in categories such as digital services, digital infrastructure and managed third-party IT to complete a form to assess the risk and impact of potential cybersecurity incidents.

TrendTIC added that the first qualification process distinguished between Essential Services and Operators of Vital Importance, and that the roster of OIVs fell from 1,712 to 915 in December 2025. The focus, according to that coverage, was to concentrate the regulatory burden on entities whose compromise through cyberattacks could affect security, public order or the continuity of critical services.

What changed for Defense?

The Defense sector was also required to report cyberattacks and cybersecurity incidents that could have significant effects to CSIRT-DN. Decree 2, dated December 31, 2025, also set strict deadlines for that notification scheme.

Actualidad Jurídica of the Official Gazette said the rule requires early alerts within three hours for relevant incidents, a status update report within intermediate deadlines and a final report within a maximum of 15 days. That analysis also said the regime includes specific confidentiality rules based on Law 21.663, Law 20.285 and the Military Justice Code.

Personal data and penalties

In data protection, training materials in Chile say [Law 21.719](/en/news/chile-data-protection-law-takes) significantly raises the fines and penalties that apply to public and private organizations that process personal data without complying with the rules. That description places the law as a structural change in the sanctioning regime, with a direct impact on internal compliance, processing and safeguarding of personal information.

Deadlines and implementation uncertainty

The regulatory transition still has gray areas. A LinkedIn post by Valentina Palma, a lawyer specialized in data protection in Chile, says there are implementation obligations under the new Law 21.719 with a milestone on December 1, but criticizes the fact that by then there were still no minimum certainties about how the authority and the needed regulations would operate. That argument reflects regulatory uncertainty in the adjustment process.

The debate comes as different local explanatory materials have been mapping the practical scope of Law 21.663, from ANCI's role in regulation and oversight to the need to prepare for a more formal incident, security and privacy management scheme. In that setting, the focus is no longer just on adopting technical controls, but on maintaining proof of compliance across two legal frameworks that are starting to impose stricter order on digital operations in Chile.

Sources

View all