World Watch/Nicaragua/Cybersecurity

Cybersecurity · Nicaragua

Cybersecurity regulation in Nicaragua (2026)

Sectoral rulesNo comprehensive NIS2-style cybersecurity-obligations law. Cyber matters are governed by a mix: the criminal Ley Especial de Ciberdelitos (Law 1042/2020, reformed by Law 1219/2024), the policy-level National Cybersecurity Strategy 2020-2025 (Decree 24-2020), and binding sector rules — notably the SIBOIF Norma sobre Gestión de Riesgo Tecnológico for supervised financial institutions.Country index 72 · B

Nicaragua shaded by its cybersecurity status

Nicaragua has no single horizontal cybersecurity law imposing NIS2-style security and incident-reporting duties on operators of essential services. Instead, obligations are sectoral and fragmented: financial institutions face binding IT-risk-management rules from the banking supervisor (SIBOIF), while at national level a 2020 criminal cybercrimes law and a 2020-2025 strategy (which only contemplates a future incident-response capability) set the broader policy. There is no general, cross-sector breach-notification mandate for the public or affected individuals.

Key points

No comprehensive cyber law

There is no enacted horizontal cybersecurity statute defining 'essential/critical' operators with uniform security and incident-reporting duties. The principal national instruments are a criminal law and a non-binding strategy rather than a regulatory obligations regime.

Special Cybercrimes Law (Law 1042)

Law 1042 of 28 Oct 2020 (La Gaceta No. 201, 30 Oct 2020) criminalizes unauthorized system access, illegal interception, malware, e-fraud and spreading of 'false/distorted' information. It is a penal instrument widely criticized as a content-control 'gag law' rather than a corporate security-duties framework.

2024 reform raised penalties (Law 1219)

Law 1219, published in La Gaceta on 12 Sep 2024, reformed and added to Law 1042, increasing maximum imprisonment to up to 15 years for cybercrimes deemed against 'the security of the State'.

Financial-sector IT-risk rules (SIBOIF)

The Norma sobre Gestión de Riesgo Tecnológico (Res. CD-SIBOIF-500-1-SEP19-2007) binds all banks and supervised financial entities to minimum standards for IT governance, security and controls, referencing frameworks such as COBIT, ITIL and ISO 17799 — the clearest example of enforceable cyber/IT obligations.

National Cybersecurity Strategy 2020-2025

Decree 24-2020 approved a National Cybersecurity Strategy 2020-2025, executed by the Foreign Ministry and telecom regulator TELCOR, with five pillars including resilience of critical infrastructure. It only contemplates creating a future computer-emergency response capability rather than imposing mandatory reporting duties now.

Telecom law and breach notification

A new General Law on Converged Telecommunications (approved Oct 2024) enters into force on 6 Nov 2025, adding state oversight of telecom networks. There is no general, cross-sector mandatory breach-notification duty toward affected individuals; incident-reporting obligations are confined to supervised sectors.

Nicaragua - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →