World Watch/Iran/Cybersecurity

Cybersecurity · Iran

Cybersecurity regulation in Iran (2026)

Sectoral rulesComputer Crimes Law (Law No. 71063, 2009); Supreme Council of Cyberspace (est. 2012 by Supreme Leader decree); FETA (Cyber Police of the Islamic Republic of Iran)Country index 62 · C+

Iran shaded by its cybersecurity status

Iran's cybersecurity regime is built around the 2009 Computer Crimes Law, which criminalises unauthorised access, data interference, and system disruption, enforced by the dedicated Cyber Police (FETA). The Supreme Council of Cyberspace, established in 2012, serves as the apex policy body coordinating all state agencies on cyberspace matters, including the development of Iran's domestic National Information Network. There is no comprehensive horizontal cybersecurity or data-breach-notification law comparable to the EU NIS2 Directive; proposals to expand internet and cyber control legislation have repeatedly stalled or been withdrawn under public pressure.

Key points

Computer Crimes Law (2009)

Law No. 71063, enacted by Parliament in January 2009 and effective June 2009, comprises 55 articles added to Book Five (Ta'zirat) of the Islamic Penal Code. It criminalises unauthorised access, unlawful interception, data destruction, fraud, and distribution of illicit content via computer or telecommunications systems, with penalties ranging from fines to imprisonment.

Supreme Council of Cyberspace

Established on 26 February 2012 by decree of Supreme Leader Khamenei, the SCC is the centralised policymaking, decision-making, and coordination body for all cyberspace matters. All state agencies, including Parliament, are required to comply with its decisions. It oversees the National Information Network (Iran's sovereign intranet) and content governance.

FETA (Cyber Police) enforcement

The Cyber Police of the Islamic Republic of Iran (FETA), established under the Law Enforcement Command, is the primary enforcement body for computer crimes. It handles investigations, seizure of equipment, and blocking of content under powers granted by the Computer Crimes Law.

No breach-notification or incident-reporting regime

Iran has no statutory data-breach notification obligation or formal cyber-incident reporting framework comparable to the EU NIS2 or GDPR regimes. A Draft Protection of Personal Data Law announced by the Ministry of ICT in 2018 remains unratified by Parliament as of 2025–2026.

Proposed internet-control legislation (2025, withdrawn)

In July 2025, the Pezeshkian administration submitted an urgency bill — 'Combating the Dissemination of False Content in Cyberspace' — to Parliament. It was withdrawn after significant public backlash. A separate 'Protection Bill' granting IRIB (state broadcaster) sweeping control over audio-visual online content has also been revived and debated, signalling ongoing legislative attempts to tighten cyber control.

Iran–Russia information-security cooperation (2023)

In December 2023 Iran's Parliament approved a bilateral information-security cooperation agreement with Russia, signalling an intent to deepen defensive and offensive cyber coordination with Moscow outside of any domestic comprehensive cybersecurity law framework.

Iran - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →