This article is available in Spanish.
Ley 21.663, the Ley Marco de Ciberseguridad, is Chile’s national cybersecurity law. It sets cybersecurity duties for State bodies and for the private companies that run essential services, and it created a regulator, the ANCI, that can investigate incidents and fine non-compliance. The core obligations have applied since 1 March 2025.
If you lead security or compliance at a bank, a utility, a telecoms operator, a hospital, or another essential service in Chile, this shapes how you monitor, report, and prove your work. One duty sets the pace. Serious incidents go to the national response team within three hours.
This guide covers what the law requires, who it applies to, the reporting deadlines, and the penalties. Then it looks at the duties that are hardest to meet by hand, and where automation helps most.
Ley 21.663 at a Glance
- Ley 21.663 creates Chile’s cybersecurity framework and the ANCI as its regulator.
- It was published in April 2024, and its core obligations have applied since 1 March 2025.
- It binds State bodies and private operators of essential services.
- A subset are designated Operators of Vital Importance (OIV) and carry stricter duties.
- Serious incidents go to the CSIRT Nacional, starting with an early alert within three hours.
- Fines reach 20,000 UTM, and 40,000 UTM (roughly US$3 million) for an OIV.
Why Chile Passed the Law
The law arrived after a run of serious incidents. In September 2020, REvil ransomware forced BancoEstado to shut its entire branch network. In 2022, the Guacamaya group leaked hundreds of thousands of emails from the Joint Chiefs of Staff. Ley 21.663 sets baseline cybersecurity duties across the sectors Chile relies on, and gives the country a single regulator to enforce them.
What Ley 21.663 Requires
Ley 21.663 was promulgated on 26 March 2024 and published in the Diario Oficial on 8 April 2024. It sets the institutions, principles, and minimum requirements for preventing, containing, and responding to cybersecurity incidents.
The operative dates came later. The ANCI started work on 1 January 2025. The articles that carry the day-to-day duties, including the OIV obligations and the incident reporting rules, took effect on 1 March 2025. Those duties are active now.
Ley 21.663 is a different law from Chile’s data privacy reform, Ley 21.719. One governs cybersecurity and incident response. The other governs personal data. If you’re mapping both, our guide to data privacy compliance covers the privacy side.
Who Enforces the Law
Enforcement runs through two organizations.
The Agencia Nacional de Ciberseguridad (ANCI) is the regulator. It issues protocols and standards, decides which operators count as OIV, supervises compliance, and applies sanctions.
The CSIRT Nacional is the national incident response team. It receives incident reports and coordinates the response. Reports reach it through the notification platform the ANCI runs.
For a regulated operator, the ANCI is the regulator you’ll deal with directly. It can request information, direct your response during an incident, and open a sanctioning process when a duty is missed.
Who Must Comply, and Which Sectors Are Regulated
The law reaches two overlapping groups. The first is any provider of an essential service (PSE). The second is the smaller set of those providers that ANCI designates as vitally important.
The Essential Sectors
Article 4 defines the essential services. They cover State administration and the national electricity coordinator, holders of public service concessions, and private companies working in:
- electricity generation, transmission, or distribution
- fuel transport, storage, or distribution
- drinking water and sanitation
- telecommunications and digital infrastructure
- digital services and third-party managed IT
- land, air, rail, and maritime transport, and their infrastructure
- banking, financial services, and payment systems
- social security administration
- postal and courier services
- healthcare
- pharmaceutical production and research
Provide one of these and you carry the general duties in Article 7. Whether you also carry the stricter Article 8 duties depends on being designated an OIV.
PSE and OIV
An Operator of Vital Importance is a provider whose disruption would significantly affect public safety, the steady supply of essential services, or the functioning of the State. Article 5 sets two conditions, and both have to hold. The service depends on IT systems, and its disruption would cause significant harm. ANCI runs the designation through Decreto 285/2024, weighs each candidate with the relevant sector authority, and reviews the list at least every three years.
Who ANCI Has Already Designated
The designation is already well underway. ANCI ran its first qualification process in two stages. The first, finalized on 17 December 2025, designated 915 operators as OIV. A second stage in 2026 added a further 239, taking the first process to 1,154 operators. They span the essential sectors, including electricity, telecommunications, banking and payments, digital services and infrastructure, healthcare, fuel, and water. If you operate in one of these and haven’t been designated yet, the next review cycle is when your status could change. (OIV figures current as of July 2026.)
How Ley 21.663 Sits With Existing Sector Rules
For several sectors, cybersecurity duties didn’t start with Ley 21.663. The law adds a cross-cutting layer over regimes that already existed, and ANCI now sits above them as the national authority, coordinating the CSIRT Nacional and the sectoral CSIRTs.
If you run security at a bank, you’ve followed the CMF’s Chapter 20-10 on information security and cybersecurity since 2020. Ley 21.663 doesn’t replace it. A bank designated as an OIV reconciles the CMF program with the Article 8 duties, and its incident reporting has to satisfy both.
If you run an electricity operation, the Coordinador Eléctrico Nacional’s cybersecurity standard, built on NERC-CIP and overseen by the SEC, has applied to the sector for years, with its own sectorial CSIRT and incident reporting. Ley 21.663 layers the national duties, and the three-hour CSIRT Nacional alert, on top of that.
The pattern holds across the regulated sectors. The existing sector rules stay in force, and Ley 21.663 sets the common baseline and the single regulator above them. The real work is mapping what you already do onto the Article 8 duties, rather than starting from scratch.
The Core Obligations
Every obligated institution has the general duties set out in Article 7. They apply standing measures to prevent, report, and resolve incidents, and they follow the protocols the ANCI issues.
| PSE (essential service provider) | OIV (operator of vital importance) | |
|---|---|---|
| Who | Any essential-service provider | A PSE, or a critical private entity, that ANCI designates |
| General duties (Art. 7) | Yes | Yes |
| Specific duties (Art. 8) | No | SGSI, register, continuity plans, drills, delegate, training |
| Reporting (Art. 9) | 3h / 72h / 15 days | Plus 24h if a service is down, and a 7-day action plan |
| Maximum fine | Up to 20,000 UTM | Up to 40,000 UTM |
Article 8 asks more of Operators of Vital Importance. They have to:
- run a continuous information security management system (SGSI) that keeps assessing risk to networks, systems, and data
- keep a register of the actions that make up the SGSI (Article 8 b), so there’s an auditable record that the system runs
- hold operational continuity and cybersecurity plans, certified under Article 28 and reviewed at least every two years
- run continuous review, exercises, and drills, and report relevant findings to the CSIRT Nacional
- take prompt measures to limit the impact and spread of an incident
- appoint a cybersecurity delegate (Article 8 i) as the ANCI’s counterpart
- train staff and notify affected parties when an incident warrants it
If you already run an ISO 27001 ISMS, the SGSI will feel familiar. The law asks for the same management-system discipline, applied continuously and evidenced in the Article 8 b) register. That continuous stance is the one behind CTEM, treating exposure as something you assess and reduce all the time, not once a year.
The register in Article 8 b) matters more than it first appears. Building an auditable trail of security actions by hand is slow, and gaps show up the moment your team gets busy. Kept as a byproduct of how the work already runs, it stays complete without extra effort.
The Three-Hour Reporting Rule
Article 9 sets the reporting schedule for incidents with significant effects. This is the deadline manual work tends to miss.
| Report | Deadline | Applies to |
|---|---|---|
| Early alert (alerta temprana) | Within 3 hours of becoming aware | All obligated institutions |
| Update (segundo reporte) | Within 72 hours | General case |
| Update when an essential service is down | Within 24 hours | OIV |
| Action plan | Within 7 calendar days | OIV |
| Final report (informe final) | Within 15 calendar days of the early alert | All |
Three hours runs from the moment you become aware of an incident. Inside that window your team has to detect the event, work out its scope, collect indicators of compromise, decide whether it crosses the significant-effects threshold, and file an alert the CSIRT Nacional can act on. Most of that is triage, and most triage still happens by hand, often after hours, against a full queue of alerts.
That’s getting harder. Attackers now discover, validate, and exploit weaknesses at machine speed, often within a day of a vulnerability becoming public. When detection and triage depend on manual handoffs, three hours is very little time.
Missing the report isn’t a technicality. Article 38 treats a failure to report under Article 9 as a serious infraction.
Penalties for Non-Compliance
Article 40 sets the fines on a scale measured in UTM (unidad tributaria mensual). Every ceiling doubles for an OIV.
| Severity | Standard Operator | Operator of Vital Importance |
|---|---|---|
| Minor (leve) | Up to 5,000 UTM | Up to 10,000 UTM |
| Serious (grave) | Up to 10,000 UTM | Up to 20,000 UTM |
| Very serious (gravísima) | Up to 20,000 UTM | Up to 40,000 UTM |
In round terms, the top OIV fine of 40,000 UTM is roughly US$3 million; the exact figure tracks the monthly UTM and the exchange rate.
Article 38 lists the general infractions, and Article 39 the ones specific to OIVs. Not keeping the Article 8 b) register, or not naming a delegate, counts as a minor infraction. Failing to contain an incident with significant impact is among the most serious. Infractions lapse three years after they occur.
Operating Under Ley 21.663
The law states what to achieve. How you achieve it is left to you. Most of the effort goes into three time-bound duties that all come due during the same incident: the three-hour alert, the continuous SGSI and its register, and the containment of an active attack. You answer for them to your board and, now, to a regulator.
The First 90 Days
A practical order of work tends to hold across operators. Confirm your status as a provider or an OIV, and appoint the delegate. Stand up the SGSI and the register so evidence starts accumulating by default. Then connect detection to reporting, so the three-hour and 72-hour steps don’t depend on someone noticing.
What to Automate, and What Stays Human
The three-hour alert and the Article 8 b) record are repetitive and run to a deadline. That’s the work automation does well. Piecing together an early alert by hand, mid-incident, uses up most of the three hours, and a reactive, ticket-driven SOC rarely hits it. Writing up the record afterward leaves gaps the ANCI will find. A system that detects the incident, drafts the alert from what it already knows, and builds the record as the response happens takes both off your team.
The judgment stays with you. Whether a risk is acceptable, how a duty applies to your operation, the root-cause analysis, the calls with the regulator and the board, none of that can be handed to software. Automating the mechanical work is what frees the time to do it properly.
The tool you choose has to act inside limits you set, because automation that moves on its own during an incident can cause the next one. It has to produce a record the ANCI accepts as it stands, not a log you rewrite later. And it has to work with your ISO 27001 program, your CMF obligations, and your sector CSIRT, not replace them.
That’s how we’ve built Zynap. Its agents act within your limits and bring the decisions that matter back to you. Its workflows keep the Article 8 b) record as they run. Neither asks you to drop the frameworks you already answer to. For enterprise teams, that’s Zynap for Enterprises.
Ley 21.663 for MSSPs
If you’re a managed provider, you meet these duties for several regulated clients at once, each with its own deadlines and evidence trail. Handling that at scale is a question of multitenancy and delivery automation, running proactive workflows per client without rebuilding the process each time. Our MSSP solution is built for that.
How It Compares to NIS2
The structure will look familiar to multinationals. The staged reporting in Ley 21.663 mirrors the early-warning and follow-up model in the European NIS2 directive, and the essential-operator scope resembles NIS2’s essential and important entities. A Chilean subsidiary of an EU group can often reuse the same framework, mapped to the ANCI’s deadlines and the OIV designation.
Meet Us at the CISO Breakfast and Segurinfo Chile
We’re running a session on exactly this. On Tuesday 11 August 2026 at 10:00 Chile time, our Field CTO Vicente Martín and Carlos Ortiz Hijar of Anida host a CISO Breakfast, in Spanish, on meeting Ley 21.663. It’s built for CISOs, cybersecurity delegates, and compliance leads in regulated sectors.
We’ll also be at SEGURINFO Chile 2026 on 25 August, at the Hotel W in Santiago. Come find the team if you’ll be there, we’re happy to talk through what the law means for your operation. Or, to see how the reporting and evidence duties can run without manual effort, request a demo.