DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
GLOBAL CYBER JURISPRUDENCE & STATUTES

International Cyber Law & Regulatory Index

Statutory frameworks, mandatory critical infrastructure incident notification regimes, consumer IoT standards, and global data protection enforcement mandates.

European Union (27 Member States)CODE: Directive (EU) 2022/2555
STATUS: in forceEFFECTIVE: 2024-10-18

Directive on Measures for a High Common Level of Cybersecurity Across the Union (NIS2 Directive)

NIS2 establishes a harmonized cybersecurity regulatory baseline across the EU, introducing direct management body liability for cybersecurity compliance failures, strict supply chain vetting obligations, and severe non-compliance fines up to €10 Million or 2% of global annual turnover.

MANDATORY COMPLIANCE OBLIGATIONS
  • Early Warning Incident Notification to national CSIRT within 24 hours of significant incident detection.
  • Full Detailed Incident Notification with root cause within 72 hours; Final Report within 1 month.
  • Board of Directors / Management Body mandatory cybersecurity training and personal civil liability.
  • Comprehensive Supply Chain Security Assessments and cryptographic control baselines.
PENALTY CEILING
Up to €10,000,000 or 2% of total worldwide annual turnover for essential entities; temporary suspension of management certifications.
ENFORCEMENT AUTHORITIES
National Cybersecurity Authorities (NCAs) · ENISA CSIRTs Network · EU CyCLONe
United StatesCODE: Public Law 117-103, 6 U.S.C. 681 et seq.
STATUS: in forceEFFECTIVE: 2025-10-01

Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)

Enacted to establish unified national situational awareness of cyber threats targeting 16 critical infrastructure sectors. Grants CISA administrative subpoena authorities to compel incident data and provides legal safe harbor and confidentiality protections for submitted reports.

MANDATORY COMPLIANCE OBLIGATIONS
  • Submit Covered Cyber Incident Report to CISA within 72 hours of reasonable belief an incident occurred.
  • Submit Ransomware Payment Report to CISA within 24 hours of ransom disbursement.
  • Preserve related network logs, memory captures, and forensic artifacts for 24 months.
PENALTY CEILING
CISA administrative subpoenas, contempt proceedings, referral to DOJ for civil enforcement, and loss of federal contracting eligibility.
ENFORCEMENT AUTHORITIES
Cybersecurity and Infrastructure Security Agency (CISA) · Department of Justice (DOJ)
IndiaCODE: Act No. 22 of 2023
STATUS: in forceEFFECTIVE: 2024-06-01

Digital Personal Data Protection Act, 2023 (DPDP Act)

Introduces the Data Protection Board of India (DPBI) and creates strict obligations for Data Fiduciaries. Mandates immediate notification of personal data breaches to both the DPBI and affected Data Principals, while prohibiting dark patterns and unauthorized behavioral profiling of minors.

MANDATORY COMPLIANCE OBLIGATIONS
  • Implement reasonable security safeguards to prevent personal data breaches under Section 8(5).
  • Mandatory immediate notification of data breaches to Data Protection Board of India and affected individuals.
  • Appointment of Indian Data Protection Officer (DPO) and independent data auditors for Significant Data Fiduciaries (SDFs).
PENALTY CEILING
Penalties up to ₹250 Crore (approx. $30 Million USD) per failure to take reasonable security safeguards to prevent a personal data breach.
ENFORCEMENT AUTHORITIES
Data Protection Board of India (DPBI) · CERT-In · Ministry of Electronics and IT (MeitY)
United KingdomCODE: UK Public General Acts 2022 c. 46
STATUS: in forceEFFECTIVE: 2024-04-29

Product Security and Telecommunications Infrastructure Act 2022 (PSTI)

World-first statutory regime holding manufacturers, importers, and distributors of internet-connected consumer smart devices legally accountable for foundational hardware and firmware security hygiene.

MANDATORY COMPLIANCE OBLIGATIONS
  • Ban on universal default passwords (must be unique per device or generated upon setup).
  • Mandatory public vulnerability disclosure program (VDP) with published point of contact.
  • Mandatory published statement of minimum security update support period at point of sale.
PENALTY CEILING
Up to £10 Million or 4% of qualifying worldwide revenue, plus daily fines up to £20,000 for ongoing non-compliance.
ENFORCEMENT AUTHORITIES
Office for Product Safety and Standards (OPSS) · NCSC UK