World Watch/Georgia/Cybersecurity

Cybersecurity · Georgia

Cybersecurity - Georgia

Comprehensive lawLaw of Georgia on Information Security (2012, as amended through 2025); National Cybersecurity Strategy 2021–2024; CERT-GOV-GE under the Data Exchange Agency of the Ministry of Justice; Department of Information and Cybersecurity of the National Security Council

Georgia's primary cybersecurity instrument is the Law on Information Security, which designates critical information system subjects, imposes mandatory immediate incident reporting to CERT-GOV-GE, and requires those subjects to adopt internal security policies. National-level coordination is provided by the National Security Council's Department of Information and Cybersecurity, which oversees implementation of the 2021–2024 National Cybersecurity Strategy—the country's third such strategy. CERT-GOV-GE, operational since 2011 under the Ministry of Justice's Data Exchange Agency, serves as the principal technical response body.

Law on Information Security

Enacted in 2012 and amended multiple times (amendments recorded as recently as 2025 on matsne.gov.ge), the Law defines 'critical information system subject' as any state body or legal person whose uninterrupted operation is essential to defence, economic security, or public life, and sets binding security obligations for such entities.

Mandatory Incident Reporting to CERT

Critical information system subjects must notify CERT-GOV-GE immediately upon identifying a computer incident and take urgent steps to preserve incident-related information. CERT is empowered to request access to affected systems and infrastructure for incident response.

CERT-GOV-GE

Founded in 2011, CERT-GOV-GE operates under the Data Exchange Agency of the Ministry of Justice. It coordinates incident management, information exchange with critical infrastructure entities, and serves as Georgia's primary technical cybersecurity authority.

National Cybersecurity Strategy 2021–2024

Approved by Government Resolution No. 482 on 30 September 2021, the third national strategy sets four priority goals: developing cyber culture and organisational capacity; strengthening governance resilience and public-private partnership; building cyber workforce and technical capability; and enhancing Georgia's international cybersecurity standing.

Critical Infrastructure Classification

The list of critical information system subjects and their criticality classification is approved by government ordinance, submitted by the Ministry of Justice in agreement with the Ministries of Defence and Internal Affairs and the State Security Service. The original 2013 list identified 36 critical objects.

Budapest Convention & Geopolitical Context

Georgia is a party to the Council of Europe Convention on Cybercrime (Budapest Convention). As of 2025–2026, however, deteriorating relations with Western partners have led to reduced international cybersecurity assistance, affecting Georgia's capacity-building trajectory.

Machine-assisted translation · verified 5/24/2026 · orientation, not legal advice. English version →