CiberLATAMbywhalemate

Chile Sets Incident Reporting Deadlines in Hours

Chile’s ANCI has put in place a phased notification scheme for critical incidents

Whalemate Labs · AI-assisted researchPublished:2 min read

Chile’s ANCI has set a staged incident reporting framework that forces organizations to move on extremely tight deadlines, first with an early alert in 3 hours, then later milestones at 24 hours and 15 days to expand and close the case. In parallel, Exempt Resolution ANCI No. 152, issued in January 2026, set a 6-hour window for the initial notification of critical incidents under Law 21,663, while noncompliance can lead to fines of up to 10,000 UTM.

Reporting in hours, not days

ANCI has already set a staged incident reporting framework that requires organizations to move on very tight timelines, with an early alert due within 3 hours, followed by later milestones such as 24 hours and 15 days to expand and close the report. In local consulting practice, that schedule has become an operational benchmark of 3 hours, 24 hours, and 15 days for building drills, internal reporting flows, and evidence collection.

Exempt Resolution ANCI No. 152, issued in January 2026, adjusted that standard by setting a 6-hour deadline for the initial notification of critical incidents under Law 21,663. The coexistence of both timelines creates a concrete requirement for companies covered by the regime, which must detect, classify, and escalate events almost in real time to avoid missing the deadline.

What vital operators are doing

Netprovider says Vital Operators need 24/7 security monitoring, either through an internal or external CyberSOC, because without continuous detection the legal reporting window is practically impossible to meet in practice. The consultancy also describes monthly roadmaps for essential services and Vital Operators, with steps that include appointing and registering the cybersecurity delegate with ANCI, running a gap analysis against ISO 27001, activating a 24/7 CyberSOC, testing continuity plans, starting training, and completing ISMS certification before mid-2026.

In the power sector, ANCI has already published a preliminary list of Vital Operators that includes generation, transmission, and distribution companies. That publication confirms that a significant part of energy infrastructure is now formally covered by the 3-hour reporting regime, along with the ISMS and monitoring obligations.

Heavy fines and disclosure duties

The regulatory risk is not limited to how fast a company reports. According to Aguila & Cía., failing to notify or delaying notification may be treated as a serious violation and result in fines of up to 10,000 UTM, doubled in cases of repeat offenses or significant damage to critical infrastructure. That framework sharply raises the cost of missing the deadlines.

The same firm warns that liability for compliance with Law 21,663 is being interpreted under a Caremark-like standard, which requires boards to show they are actively implementing and overseeing information and reporting systems for cybersecurity. That includes a certifiable ISMS, detailed documentation of decisions, and dual notification protocols to ANCI and the data protection authority.

Aguila & Cía. and other providers also agree that the law requires incident notification procedures to ANCI to be integrated with personal data breach notification obligations, in order to avoid parallel sanctions and reduce the risk of civil litigation stemming from security incidents.

Sources

View all