World Watch/Chile/Cybersecurity

Cybersecurity · Chile

Cybersecurity regulation in Chile (2026)

Comprehensive lawLey Marco de Ciberseguridad No. 21.663 (April 8, 2024), enforced by the Agencia Nacional de Ciberseguridad (ANCI)Country index 76 · B+

Chile shaded by its cybersecurity status

Chile enacted Latin America's first comprehensive cybersecurity framework law (Ley 21.663) in April 2024, which became fully enforceable on March 1, 2025. The law established the ANCI as the central regulatory and enforcement body with powers over both public institutions and private essential-service providers. It imposes mandatory incident-reporting duties, minimum security standards, and graduated obligations on two categories of regulated entities: Essential Service Providers and Operators of Vital Importance (OVIs).

Key points

ANCI establishment

The Agencia Nacional de Ciberseguridad (ANCI) was created by Law 21.663 as a decentralized, technically specialized public body. It commenced operations on January 1, 2025, and holds regulatory, supervisory, standard-setting, and sanctioning powers over both public and private entities in scope.

Entry into force timeline

The law was promulgated March 26, 2024, and published in the Diario Oficial on April 8, 2024. Core obligations for essential service providers applied from January 1, 2025; provisions governing OVI designation, OVI-specific duties, and the sanctions regime entered into force on March 1, 2025.

Mandatory incident reporting

All in-scope public and private institutions must report significant cybersecurity incidents to the ANCI's National CSIRT within 3 hours of detection, provide a progress update within 72 hours, and submit a final report within 15 days. Reports are filed through the ANCI portal at portal.anci.gob.cl.

Two-tier regulated entity classification

The law distinguishes Essential Service Providers (energy, healthcare, transport, banking, telecoms, water/sanitation, IT sectors) from Operators of Vital Importance (OVIs), who face stricter obligations including continuous risk management, security audits, and mandatory participation in national cybersecurity exercises.

OVI designation — final list (December 2025)

On December 17, 2025, ANCI published the final first-group list designating 915 public and private institutions as OVIs across electricity, telecoms, banking/payments, digital services, healthcare, and public administration sectors.

Penalties for non-compliance

Serious infringements by Essential Service Providers carry fines up to 10,000 UTM (~USD 725,000). For OVIs the ceiling rises to 40,000 UTM (~USD 2.9 million). Repeat or especially grave violations by OVIs can result in temporary suspension of operations.

Timeline - major decisions & events

Dec 1, 2025guidanceofficial
ANCI Issues General Instructions 2–4 Clarifying Framework Law Obligations

ANCI published three general instructions in the final weeks of 2025 clarifying supplementary registration procedures for essential-service providers, the 60-day deadline to appoint a Cybersecurity Delegate for Vital Importance Operators, and mandatory measures to contain incident propagation. They operationalize Law 21.663's compliance requirements across regulated entities.

ANCI – Agencia Nacional de Ciberseguridad
Jun 4, 2025guidanceofficial
ANCI Instrucción General N°1: Essential Services Must Register on Incident-Reporting Platform

ANCI's inaugural general instruction imposed a mandatory registration obligation on all entities providing essential services, requiring enrollment in the ANCI incident-reporting platform. It was the first direct private-sector compliance deadline enforceable under the Cybersecurity Framework Law.

ANCI – Agencia Nacional de Ciberseguridad
Mar 1, 2025lawofficial
Vital Importance Operator Classification and Mandatory Incident-Reporting Obligations Enter Into Force

The provisions of Law 21.663 governing the designation of Vital Importance Operators (OIVs) — including their specific cybersecurity duties and mandatory incident notification timelines — became enforceable, completing the phased entry into force of Chile's Cybersecurity Framework Law.

ANCI – Agencia Nacional de Ciberseguridad
Jan 1, 2025decisionofficial
ANCI Becomes Operational; General Provisions of Law 21.663 Take Effect

Chile's National Cybersecurity Agency (ANCI) formally commenced operations, making Chile the first Latin American country with a dedicated autonomous cybersecurity regulator. General provisions of the Cybersecurity Framework Law simultaneously entered into force, establishing the new regulatory architecture governing public and private sector entities.

ANCI – Agencia Nacional de Ciberseguridad
Apr 8, 2024lawofficial
Cybersecurity Framework Law 21.663 Published in the Diario Oficial

Chile enacted its first comprehensive Cybersecurity Framework Law — promulgated March 26 and published April 8, 2024 — creating the ANCI as an autonomous regulator, defining Critical Information Infrastructure and essential services (energy, finance, healthcare, transport, telecoms), mandating incident reporting, and imposing proportional cybersecurity obligations on both public and private sectors.

Biblioteca del Congreso Nacional de Chile
Dec 4, 2023decisionofficial
National Cybersecurity Policy 2023–2028 Enacted via Decree N°164

Decree N°164 published in the Diario Oficial adopted Chile's second National Cybersecurity Policy. Its five strategic axes — resilient infrastructure, digital rights, security culture, international cooperation, and institutional development — replaced the 2017–2022 policy and served as the political blueprint for Law 21.663.

ANCI – Agencia Nacional de Ciberseguridad
Sep 25, 2022incidentofficial
LockBit Black Ransomware Attacks Chile's Poder Judicial

A LockBit Black ransomware campaign propagated through the Poder Judicial's network on September 25, 2022, infecting more than 100 computers. CSIRT issued a critical cybersecurity alert; the Judiciary filed criminal complaints. The high-profile attack on the national court system intensified congressional urgency to pass the pending Cybersecurity Framework Law.

CSIRT Nacional de Chile
Sep 7, 2020incidentofficial
REvil/Sodinokibi Ransomware Forces Closure of All BancoEstado Branches

Chile's state-owned BancoEstado was struck by REvil (Sodinokibi) ransomware after a malicious Office attachment was opened by an employee, infecting an estimated 14,000 computers and forcing closure of all 400+ branches. The largest cyberattack on Chilean financial infrastructure to date triggered a Senate inquiry and catalyzed calls for comprehensive cybersecurity legislation.

Senado de la República de Chile
Jan 1, 2018decisionofficial
Government CSIRT Formally Established Under Ministry of Interior

Chile established the Government Computer Security Incident Response Team (CSIRT) under the Ministry of the Interior, providing the state with a dedicated operational cyber-defense capability for public administration and critical infrastructure. Public agencies were required to report cybersecurity incidents to CSIRT within three hours of confirmation.

CSIRT Nacional de Chile
May 1, 2017decisionofficial
National Cybersecurity Policy 2017–2022 Adopted — Chile's First

The Interministerial Committee on Cybersecurity launched Chile's inaugural National Cybersecurity Policy, establishing five objectives: a free, open, secure, and resilient cyberspace; protection of individuals' rights; a security culture; coordinated incident response; and international engagement. It created the institutional and policy foundations for subsequent legislation.

Gobierno Digital de Chile
Jan 1, 2015decisionofficial
Interministerial Committee on Cybersecurity (CICS) Created

Chile established the Comité Interministerial sobre Ciberseguridad (CICS), comprising representatives of Interior, Defense, Foreign Affairs, Justice, Economy, Finance, Telecommunications, and the National Intelligence Agency. CICS was mandated to propose a national cybersecurity policy to the President, marking Chile's first formal inter-agency cybersecurity governance structure.

Biblioteca del Congreso Nacional de Chile
Jun 7, 1993lawofficial
Law 19.223 Enacted — Chile's First Computer Crimes Law

Chile enacted Law 19.223, one of the first computer crimes statutes in Latin America. Its four articles criminalized computer sabotage and computer espionage but covered a narrow range of conduct. The law's inadequacy in addressing modern threats — it went unamended for 29 years — ultimately drove Chile to replace it with Law 21.459 in 2022.

Biblioteca del Congreso Nacional de Chile

Chile - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →