International Cyber Law & Regulatory Index
Statutory frameworks, mandatory critical infrastructure incident notification regimes, consumer IoT standards, and global data protection enforcement mandates.
Directive on Measures for a High Common Level of Cybersecurity Across the Union (NIS2 Directive)
NIS2 establishes a harmonized cybersecurity regulatory baseline across the EU, introducing direct management body liability for cybersecurity compliance failures, strict supply chain vetting obligations, and severe non-compliance fines up to €10 Million or 2% of global annual turnover.
- ›Early Warning Incident Notification to national CSIRT within 24 hours of significant incident detection.
- ›Full Detailed Incident Notification with root cause within 72 hours; Final Report within 1 month.
- ›Board of Directors / Management Body mandatory cybersecurity training and personal civil liability.
- ›Comprehensive Supply Chain Security Assessments and cryptographic control baselines.
Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)
Enacted to establish unified national situational awareness of cyber threats targeting 16 critical infrastructure sectors. Grants CISA administrative subpoena authorities to compel incident data and provides legal safe harbor and confidentiality protections for submitted reports.
- ›Submit Covered Cyber Incident Report to CISA within 72 hours of reasonable belief an incident occurred.
- ›Submit Ransomware Payment Report to CISA within 24 hours of ransom disbursement.
- ›Preserve related network logs, memory captures, and forensic artifacts for 24 months.
Digital Personal Data Protection Act, 2023 (DPDP Act)
Introduces the Data Protection Board of India (DPBI) and creates strict obligations for Data Fiduciaries. Mandates immediate notification of personal data breaches to both the DPBI and affected Data Principals, while prohibiting dark patterns and unauthorized behavioral profiling of minors.
- ›Implement reasonable security safeguards to prevent personal data breaches under Section 8(5).
- ›Mandatory immediate notification of data breaches to Data Protection Board of India and affected individuals.
- ›Appointment of Indian Data Protection Officer (DPO) and independent data auditors for Significant Data Fiduciaries (SDFs).
Product Security and Telecommunications Infrastructure Act 2022 (PSTI)
World-first statutory regime holding manufacturers, importers, and distributors of internet-connected consumer smart devices legally accountable for foundational hardware and firmware security hygiene.
- ›Ban on universal default passwords (must be unique per device or generated upon setup).
- ›Mandatory public vulnerability disclosure program (VDP) with published point of contact.
- ›Mandatory published statement of minimum security update support period at point of sale.