World Watch/Mexico/Cybersecurity

Cybersecurity · Mexico

Cybersecurity regulation in Mexico (2026)

Sectoral rulesNo single comprehensive cybersecurity statute. Obligations are distributed across sectoral and cross-cutting rules: financial-sector information-security/cyber requirements issued by the CNBV and Banco de México; breach/security-vulnerability duties under the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP, 2025); the Penal Code's computer-crime provisions; and the binding National Cybersecurity Plan 2025–2030 / General Cybersecurity Policy for the Federal Public Administration (ATDT). A comprehensive 'Ley General/Federal de Ciberseguridad' is proposed but not yet enacted.Country index 73 · B

Mexico shaded by its cybersecurity status

As of mid-2026 Mexico lacks an enacted, economy-wide cybersecurity law; cyber obligations arise from sector-specific regulation (notably banking/fintech rules from the CNBV and Banxico), the 2025 data-protection law's security and breach-notification duties, and a 2025–2030 National Cybersecurity Plan that binds federal agencies. A General Cybersecurity Law creating a national cybersecurity agency and a critical-infrastructure registry was introduced in the Senate in April 2025 and remains under legislative consideration.

Key points

No comprehensive law yet

Mexico has no single, in-force comprehensive cybersecurity statute; requirements are spread across sectoral and data-protection rules and a federal-government policy. The last standalone strategy (Estrategia Nacional de Ciberseguridad) dates to 2017.

Financial-sector cyber rules (CNBV/Banxico)

The CNBV's general provisions for credit institutions include a dedicated information-security section (arts. 168 Bis 11–17) and Anexo 72 information-security indicators, requiring a CISO, risk monitoring, remediation plans and reporting of security incidents; parallel rules apply to fintech (ITF) entities.

Data-protection security & breach duties (LFPDPPP 2025)

The new Federal Law on Protection of Personal Data Held by Private Parties was published in the DOF on 20 March 2025 and entered into force on 21 March 2025; it mandates risk-based security measures and requires data controllers to immediately notify affected data subjects of security breaches that materially harm their rights.

National Cybersecurity Plan 2025–2030 (federal government)

Published in late 2025 by the Agencia de Transformación Digital y Telecomunicaciones (ATDT), this first specialized federal cyber policy binds the Federal Public Administration across eight strategic axes, creates a national cyber operations center (CSOC) and CSIRT, and gives the ATDT 180 days (to ~mid-June 2026) to issue technical guidelines and compliance criteria.

Proposed General Cybersecurity Law

On 30 April 2025, Senators Luis Donaldo Colosio Riojas and Lucía Trasviña Waldenrath introduced a cybersecurity bill (64 articles) that would create a National Cybersecurity Agency and a Critical Information Infrastructure Registry (RICI) and require regulated operators to appoint a formal cybersecurity officer; it remains a pending initiative, not enacted law.

Computer crime via Penal Code

Absent a dedicated cyber-offenses statute, conduct such as unauthorized access, system damage and data interference is prosecuted under the Federal Criminal Code (Código Penal Federal) provisions on illicit access to computer systems.

Timeline - major decisions & events

Dec 18, 2025law
Política General de Ciberseguridad 2025–2030 Published in DOF — First Legally Binding Federal Cybersecurity Mandate

The Agencia de Transformación Digital y Telecomunicaciones (ATDT) published Mexico's first legally enforceable national cybersecurity policy in the Diario Oficial de la Federación, requiring all federal agencies to appoint an Institutional Cybersecurity Officer within 60 days and establishing a national CSOC and CSIRT under ATDT direction. This supersedes the non-binding 2017 strategy and creates audit obligations for the entire Federal Public Administration.

InfoChannel (reporting DOF/ATDT publication)
Mar 20, 2025lawofficial
New LFPDPPP Enacted, INAI Formally Extinguished

A wholly revised Federal Law on Protection of Personal Data Held by Private Parties was published in the DOF, repealing the 2010 statute and transferring data-protection enforcement from the dissolved INAI to the Secretariat of Anti-Corruption and Good Governance. The reform expands who counts as a 'data controller,' imposes direct obligations on processors, and mandates security-incident notification — but critics warn the loss of an independent enforcement authority undermines effective oversight.

Diario Oficial de la Federación
Dec 20, 2024law
Constitutional 'Organic Simplification' Reform Published — INAI Abolished

The constitutional decree extinguishing INAI and six other autonomous bodies was published in the DOF, ending 14 years of independent data-protection supervision and concentrating all enforcement within the executive branch. Privacy advocates warned the reform eliminated the structural independence required to effectively sanction government entities for cybersecurity and data breaches.

BASHAM (reporting DOF decree of 20 Dec 2024)
Jan 1, 2023enforcement
INAI Imposes Record MXN 47 Million in Data-Protection Fines

In its final full year of operation, INAI reported imposing nearly MXN 47 million in aggregate fines against private-sector entities for data-protection violations, with financial and insurance firms accounting for the largest share (MXN 22 million). These represented the highest enforcement totals under the 2010 LFPDPPP and came just before the authority's budget was slashed ahead of its abolition.

ICLG Data Protection Laws and Regulations — Mexico 2025–2026
Sep 1, 2022incident
Guacamaya Hacktivists Breach SEDENA — 6 TB of Classified Military Data Leaked

The hacktivist collective Guacamaya exploited a ProxyShell vulnerability to exfiltrate more than 6 TB of classified documents from Mexico's Ministry of National Defence (SEDENA), the largest military data breach in Mexican history. Leaked files revealed army surveillance of journalists, opposition politicians, and activists; a military IT commander was arrested in March 2023 in connection with the breach.

National Security Archive, George Washington University
Jan 1, 2019decisionofficial
Banxico Circular 4/2019: Mandatory Cybersecurity Requirements for Fintech Institutions

Following the Ley Fintech, Banco de México issued Circular 4/2019 establishing binding operational-security and cybersecurity requirements for financial technology institutions (ITFs), covering virtual-asset custody controls, access management, audit trails, and cyber-incident reporting to Banxico. This was Mexico's first sector-specific cybersecurity rulebook for digital financial services.

Banco de México
Apr 17, 2018incident
SPEI Interbank Payment System Cyberattack — ~MXN 300–400 Million Fraudulently Diverted

Attackers compromised the internal SPEI-gateway software of at least five Mexican banks, injecting fraudulent transfer orders that diverted approximately MXN 300–400 million (≈ USD 15–20 million) to mule accounts; accomplices immediately withdrew cash at branches before transfers could be reversed. The incident was Mexico's first large-scale cyber-enabled bank heist and directly prompted Banxico to issue emergency security circulars and tighten SPEI participant access controls.

Hogan Lovells / BSTL
Mar 8, 2018lawofficial
Ley Fintech (LRITF) Enacted — First Sector-Specific Cybersecurity Obligations for Digital Finance

The Law to Regulate Financial Technology Institutions was published in the DOF, creating a regulatory framework for fintechs under joint CNBV/Banxico supervision and expressly requiring ITF operators to maintain security standards for electronic-money operations and virtual-asset custody. It was the first Mexican statute to impose technology-specific cybersecurity duties on a non-bank financial sector.

Cámara de Diputados — Diario Oficial
Nov 1, 2017guidanceofficial
Estrategia Nacional de Ciberseguridad (ENCS) Published

Mexico published its first National Cybersecurity Strategy across five pillars (Society & Rights, Economy & Innovation, Public Institutions, Public Security, National Security), formally establishing CERT-MX as the national cyber-incident response body and adopting a multi-stakeholder governance model. The ENCS was the foundational policy document underpinning all subsequent cybersecurity regulation for nearly eight years, until superseded by the 2025 Política General.

Gobierno de México
May 26, 2017lawofficial
LGPDPPSO Enacted — Public-Sector Data Protection and Security Obligations

The General Law on Protection of Personal Data Held by Obligated Subjects extended data-protection and minimum-security requirements to all government bodies, requiring agencies to implement technical and administrative safeguards, appoint data-protection officers, and report security incidents to INAI. It created a unified framework with the private-sector LFPDPPP, closing a major gap that left government-held data unprotected.

Cámara de Diputados
Jul 5, 2010lawofficial
LFPDPPP Enacted — Mexico's Foundational Data-Protection and Cybersecurity Compliance Law

The Federal Law on Protection of Personal Data Held by Private Parties was published in the DOF, establishing Mexico's first comprehensive data-protection regime: consent requirements, ARCO rights, mandatory security-breach notification, and minimum technical and administrative security measures for private entities processing personal data. For 15 years it was the primary legal basis for cybersecurity obligations on private-sector organisations and the statute enforced by INAI.

Cámara de Diputados

Mexico - other topics

Last verified 5/23/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →