Hong Kong Protection of Critical Infrastructures (Computer Systems) Ordinance
NIS2-style regime for operators in energy, IT, transport, banking and financial services, healthcare, telecommunications and broadcasting, plus major venues and R&D parks: security management units, risk assessments, audits and incident reporting within 12 hours for serious incidents. Code of Practice issued January 2026.
| Jurisdiction | Hong Kong |
|---|---|
| Category | Cybersecurity |
| Status | Active |
| Effective date |
Related regulations
- NYDFS Cybersecurity Regulation — New York, Active, effective 2025-11-01
- Law on Cybersecurity of Vietnam — Vietnam, Active
- Austria NIS2 Act — Austria, Upcoming
- Luxembourg NIS2 Transposition — Luxembourg, Active
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
- EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026) — European Union, Active, effective 2026-09-11
- Netherlands NIS2 Transposition (Cyberbeveiligingswet) — Netherlands, Active, effective 2026-08-15
- Belgium NIS2 Transposition — Belgium, Active, effective 2024-10-18
Put it into practice
- Generate the policy: NIST CSF policy generator (generatepolicy.com)
- Buy the policy pack: Enterprise Security Bundle (cyberpolicy.shop)
- Build it yourself: Compliance Program Starter (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates