World Watch/Uzbekistan/Cybersecurity

Cybersecurity · Uzbekistan

Cybersecurity regulation in Uzbekistan (2026)

Comprehensive lawLaw of the Republic of Uzbekistan 'On Cybersecurity' (April 2022, ZRU-764); administered by the State Security Service (SSS) as authorised cybersecurity body and UZCERT as the national CERTCountry index 85 · A

Uzbekistan shaded by its cybersecurity status

Uzbekistan enacted a dedicated Cybersecurity Law in April 2022 establishing an overarching framework covering critical information infrastructure (CII), mandatory certification of security tools, and the SSS as the principal regulator. Presidential Resolution PP-167 (May 2023) elaborated CII-specific obligations, Presidential Decree PQ-153 (April 2025) tightened breach-notification duties especially for the financial sector, and Presidential Decree UP-38 (March 2026) launched a new National Cybersecurity Strategy for 2026–2030.

Key points

Core Cybersecurity Law (2022)

The Law 'On Cybersecurity' (signed 15 April 2022, ZRU-764) consists of 8 chapters and 40 articles covering the legal basis of cyber protection, roles of state bodies, CII registration, certification requirements for hardware/software, and liability for violations.

Regulatory Authority

The State Security Service (SSS) is the authorised state body for cybersecurity policy and maintains the unified register of CII facilities. The Inspectorate for Control in the Sphere of Information and Telecommunications under the Ministry of Digital Technologies serves as the operational/executive arm.

CII Obligations (PP-167, May 2023)

Presidential Resolution No. PP-167 (31 May 2023) requires operators of CII facilities (spanning banking, energy, telecoms, agriculture, health, defence, IT, and mining) to establish dedicated cybersecurity units or engage registered outsourcing providers, and to implement multi-factor authentication and secure connections for public-facing systems.

Breach Notification & 2025 Tightening

Presidential Decree No. PQ-153 (30 April 2025) introduced compulsory breach-notification obligations with particular emphasis on the financial sector, legal liability for data incidents, and a requirement to report significant cyber-incidents within 24 hours to the regulator; non-compliance can trigger administrative investigation and suspension of digital operations.

National CERT & Sector CERTs

UZCERT (uzcert.uz) functions as the national computer emergency response team for coordinating incident response. The Central Bank operates a dedicated CERT-CBU for the banking sector, reflecting a layered incident-handling architecture.

National Cybersecurity Strategy 2026–2030

Presidential Decree UP-38 (signed 10 March 2026) adopted a five-pillar Cybersecurity Strategy covering national cyber resilience, CII protection, cybercrime combat, AI-based cybersecurity development, and international cooperation; it mandates dedicated cybersecurity units across all government agencies from 1 April 2026 and a 'Zero Trust' framework for large-scale public-data operators.

Uzbekistan - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →