CiberLATAMbywhalemate

Mendoza moves ahead with cybersecurity bill that would

The Mendoza provincial government has introduced a cybersecurity bill that would set obligations for public agencies and companies tied to critical

Whalemate Labs · AI-assisted researchPublished:2 min read

Mendoza’s Senate has confirmed the formal introduction of the cybersecurity bill and outlined an institutional framework that includes a Security Operations Center, an Incident Response Team and a Provincial Incident Registry. The proposal targets agencies across all three branches of government and providers of critical services, with specific rules for data, vulnerabilities and technology procurement.

Scope of the proposal

The Mendoza provincial government has introduced a cybersecurity bill that, according to news coverage, seeks to establish guidelines and requirements for public agencies and companies connected to essential critical services. The measure was submitted to the provincial Senate and is being folded into a broader legislative agenda on security, according to official communications from the Mendoza government.

The bill would apply to the provincial Executive Branch, the Judicial Branch and the Legislative Branch. It would also cover companies that provide critical services such as electricity, transportation, gas and security, and would allow municipalities to opt in.

Operational structure and incident response

The proposal calls for the creation of a special executive committee with a coordination function responsible for carrying out custody policy and incident response mechanisms. At the same time, Mendoza’s Senate confirmed that the text includes a Security Operations Center, known as a SOC, an Incident Response Team and a Provincial Cybersecurity Incident Registry.

According to the information released by the upper chamber, those tools would be used for continuous monitoring, response-time measurement and statistical reporting. In the same context, professionals in the sector who discussed the bill publicly on LinkedIn described it as a comprehensive framework for protecting digital infrastructure and pointed to the Executive committee’s role in oversight and strategic coordination.

Data, responsible disclosure and penalties

The text released by the Senate also says the bill would require a comprehensive data governance regime for public and citizen information. That framework covers the full data lifecycle, from creation and storage to secure sharing, archiving and permanent deletion.

The proposal also includes a Responsible Disclosure Program that would allow specialists, security researchers and ethical hackers to report vulnerabilities in public systems under confidentiality rules and with legal protection for those acting in good faith, according to coverage by Los Andes.

Provincial media also reported that the law would establish a graduated penalty regime for agencies and providers that fail to meet minimum cybersecurity standards, with particular emphasis on cases where incidents affecting public services or sensitive data are concealed. The bill also includes amendments to the Provincial Financial Administration Law to speed up procurement and updates for specific technology tools used for cybersecurity and the protection of strategic state information.

Official presentation

The Mendoza government’s official coverage places the law within a new legislative security agenda and presents it as a state policy aimed at protecting digital infrastructure. In materials released by the Ministry of Security and Justice, the initiative is framed as a tool to strengthen the protection of state and citizen systems and data, with a focus on preventing cyberattacks, shielding essential services and coordinating technical and security teams.

Video coverage from local media documented the public presentation in the Legislature, led by Minister Mercedes Rus and her team, with an emphasis on the law’s goal of providing unified protection for the state against attacks and establishing a public cybersecurity policy for essential services.

Provincial outlets noted that Mendoza could become one of the first jurisdictions in Argentina to adopt a comprehensive cybersecurity law, under a framework that would require companies providing digital services and technology infrastructure to the state to immediately report vulnerabilities or incidents affecting provincial systems.

Sources

View all