Hong Kong's Critical Infrastructure Cybersecurity Law: A 2026 Compliance Guide and Checklist

Hong Kong's Protection of Critical Infrastructures (Computer Systems) Ordinance is in force from 1 January 2026 — who's caught, the key duties, and a practical checklist.

Hong Kong's first dedicated critical-infrastructure cybersecurity statute is now in force. The Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) came into operation on 1 January 2026, creating binding obligations for designated operators of critical infrastructures in Hong Kong. Although the statutory duties fall primarily on designated CI operators, the regime will also affect technology, cloud, managed-service and other suppliers in practice, because CI operators are expected to manage cybersecurity risks in the systems and vendors that support their critical computer systems.

This guide explains who is caught, what the obligations are, the reporting deadlines that matter, and provides a practical compliance checklist.

What the Ordinance does

The Ordinance establishes a Commissioner of Critical Infrastructure (Computer-system Security) with power to designate critical infrastructure operators (CI operators) and their critical computer systems (CCSs), and to enforce a statutory baseline of cyber-resilience obligations. It is supported by a Code of Practice issued in early 2026 that fleshes out how the obligations should be met.

Importantly, the regime regulates the security and continuity of computer systems — not personal data. It sits alongside, and does not replace, the Personal Data (Privacy) Ordinance. An organisation can be caught by both.

Who is caught

Two groups need to pay attention.

1. Designated CI operators. The regime focuses on essential services in eight sectors: energy; information technology; banking and financial services; air transport; land transport; maritime transport; healthcare services; and telecommunications and broadcasting services — as well as infrastructures for other critical societal or economic activities in Hong Kong. Designation is made by the Commissioner; being in one of these sectors does not automatically make you a CI operator, but organisations of scale in them should expect scrutiny and prepare.

2. Suppliers and service providers to CI operators. The statutory obligations fall primarily on designated CI operators, not on their suppliers directly. In practice, however, suppliers are affected — because CI operators are expected to manage the security of third parties whose systems support or connect with their critical computer systems, and the Code of Practice includes supply-chain and contractual expectations. If you sell technology, cloud or managed services to a CI operator, expect these obligations to reach you through your contracts, even though you are not directly regulated by the Ordinance.

The three categories of obligation

A designated CI operator's duties fall into three groups.

1. Organisational obligations

  • Maintain an office in Hong Kong.
  • Notify the Commissioner of changes to the operator or its critical infrastructure.
  • Set up and maintain a computer-system security management unit, supervised by an employee of the operator (not fully outsourced).

2. Preventive obligations

  • Notify material changes to critical computer systems.
  • Submit and implement a computer-system security management plan.
  • Conduct security risk assessments — within 12 months of designation and at least every 12 months thereafter, with a report filed within 3 months of each assessment deadline.
  • Arrange independent security audits — within 24 months of designation and at least every 24 months thereafter, with a report filed within 3 months of each audit deadline.

3. Incident reporting and response obligations

  • Participate in security drills when notified by the Commissioner (no more than once every two years).
  • Submit and implement an emergency response plan.
  • Report security incidents affecting critical computer systems to the Commissioner within strict deadlines.

The reporting deadlines that matter

The incident-reporting clock is short, and the timeline depends on severity:

  • Serious incidents — within 12 hours of becoming aware. An incident is "serious" by reference to criteria such as service downtime exceeding the maximum tolerable downtime in the operator's business-continuity plan, breach of minimum service levels, leakage of a material volume of customer data, or a credible attack threat from a threat actor.
  • Other reportable incidents — within 48 hours of becoming aware.
  • Written incident report — within 14 days of becoming aware, in addition to the initial notification.

Not every outage or data incident is reportable under the Ordinance. A reportable computer-system security incident must involve unauthorised access or another unauthorised act causing an actual adverse effect on a critical computer system. Pure technical failure, natural disaster, a mass power outage, a threat detected and contained in time, or a personal-data leak arising from human error are not, by themselves, computer-system security incidents — though separate PDPO or sectoral reporting obligations may still apply.

Meeting a 12-hour deadline is an operational discipline, not a drafting exercise. It requires pre-agreed escalation paths, a named accountable person, and templates ready before an incident — including coordination with any vendor whose system is involved.

Penalties

Non-compliance can attract substantial fines — maximum fines of HK$500,000 or HK$5 million depending on the offence — with daily fines for certain continuing offences. Separate confidentiality offences may also attract criminal liability, including imprisonment. These sit alongside the Commissioner's investigation and direction powers. The reputational and operational consequences of a poorly handled incident typically exceed the fine.

The compliance checklist

Use the checklist below to assess readiness. CI operators should treat every item as a direct obligation; suppliers to CI operators should read it as the standard they will be contractually required to meet.

1. Scoping and designation

  • Assess whether the organisation operates in a covered sector and is likely to be designated a CI operator.
  • Identify which computer systems would qualify as critical computer systems (CCSs).
  • Maintain an inventory of CCSs, their dependencies, and the third parties that support them.

2. Governance and organisation

  • Maintain a Hong Kong office and a named, accountable senior owner for computer-system security.
  • Establish a computer-system security management unit supervised by an employee.
  • Define escalation, decision-making and Commissioner-notification responsibilities.

3. Security management plan and risk assessment

  • Prepare and implement a computer-system security management plan to the Code of Practice standard.
  • Conduct security risk assessments within 12 months of designation and at least annually thereafter, with reports filed on time.
  • Arrange independent security audits within 24 months of designation and at least every two years thereafter, and remediate findings.

4. Incident response and reporting

  • Maintain an emergency response plan with defined roles and communications.
  • Build the capability to report serious incidents within 12 hours, other incidents within 48 hours, and a written report within 14 days.
  • Hold incident templates, contacts and escalation paths ready in advance; participate in drills when notified.

5. Supply chain and contracts

  • Map all vendors and cloud providers whose systems touch critical operations.
  • Flow down security, audit, cooperation and incident-notification obligations into vendor contracts.
  • Confirm vendors can meet your reporting deadlines and support your obligations.

6. Change management and monitoring

  • Notify material changes to CCSs and changes to the operator as required.
  • Continuously monitor critical systems and keep records and audit trails.
  • Review the programme against the Code of Practice and update as guidance evolves.

Who needs to act now — and where to start

The most urgent groups are organisations likely to be designated CI operators, and technology, cloud and managed-service vendors that sell to them. For operators, the priority is governance, a Code-of-Practice-aligned security management plan, and a tested 12-hour incident-reporting capability. For suppliers, the priority is reviewing customer contracts now — before a renewal or an incident forces the issue — and understanding the obligations you are being asked to accept.

The most common gap is not technical: it is the inability to evidence governance and to meet the reporting clock. A security programme that cannot produce a report within 12 hours of a serious incident is not compliant in the way that counts.

How we can help

Alan Wong LLP advises operators and their suppliers on critical-infrastructure cybersecurity compliance — readiness assessments, governance and security management plans, incident-response and reporting frameworks, and the supply-chain contract terms this regime drives in practice. We act both for businesses preparing for possible designation and for vendors negotiating these obligations into their customer agreements, including as part of our fractional in-house counsel service. To discuss your position or request a tailored version of this checklist, get in touch.

Disclaimer: This article is provided for general information only and does not constitute legal advice. It should not be relied upon as a substitute for specific legal advice on any particular matter. No solicitor-client relationship is created by your access to or use of this article. The law may change, and its application will depend on the specific facts and circumstances of each case. To the fullest extent permitted by law, we accept no responsibility for any loss or damage arising from reliance on this article.

You may like

AI Governance in Hong Kong: A 2026 Compliance Checklist for Businesses

AI Governance in Hong Kong: A 2026 Compliance Checklist for Businesses

A practical guide to AI governance and compliance in Hong Kong — the PCPD, HKMA and SFC expectations, plus a 13-point checklist for businesses adopting AI.

PDPO Compliance for Hong Kong Startups – A Practical Legal Guide

PDPO Compliance for Hong Kong Startups – A Practical Legal Guide

Hong Kong startup PDPO guide — privacy notices, direct marketing rules, employee data, cookies, breach response, and a practical compliance checklist for founders.

})