Security Automation

Ley 21.663: Chile’s Cybersecurity Framework Law Explained

Chile's Ley 21.663, the Ley Marco de Ciberseguridad, is now in force, and it requires operators of essential services to report a serious incident within three hours. Our guide covers who must comply, the reporting deadlines, the fines, and how to keep up without doing it all by hand.

Author

default avatar

Zynap Team

Ley 21.663: Chile’s Cybersecurity Framework Law Explained

This article is available in Spanish.

Ley 21.663, the Ley Marco de Ciberseguridad, is Chile’s national cybersecurity law. It sets cybersecurity duties for State bodies and for the private companies that run essential services, and it created a regulator, the ANCI, that can investigate incidents and fine non-compliance. The core obligations have applied since 1 March 2025.

If you lead security or compliance at a bank, a utility, a telecoms operator, a hospital, or another essential service in Chile, this shapes how you monitor, report, and prove your work. One duty sets the pace. Serious incidents go to the national response team within three hours.

This guide covers what the law requires, who it applies to, the reporting deadlines, and the penalties. Then it looks at the duties that are hardest to meet by hand, and where automation helps most.

Ley 21.663 at a Glance

  • Ley 21.663 creates Chile’s cybersecurity framework and the ANCI as its regulator.
  • It was published in April 2024, and its core obligations have applied since 1 March 2025.
  • It binds State bodies and private operators of essential services.
  • A subset are designated Operators of Vital Importance (OIV) and carry stricter duties.
  • Serious incidents go to the CSIRT Nacional, starting with an early alert within three hours.
  • Fines reach 20,000 UTM, and 40,000 UTM (roughly US$3 million) for an OIV.

Why Chile Passed the Law

The law arrived after a run of serious incidents. In September 2020, REvil ransomware forced BancoEstado to shut its entire branch network. In 2022, the Guacamaya group leaked hundreds of thousands of emails from the Joint Chiefs of Staff. Ley 21.663 sets baseline cybersecurity duties across the sectors Chile relies on, and gives the country a single regulator to enforce them.

What Ley 21.663 Requires

Ley 21.663 was promulgated on 26 March 2024 and published in the Diario Oficial on 8 April 2024. It sets the institutions, principles, and minimum requirements for preventing, containing, and responding to cybersecurity incidents.

The operative dates came later. The ANCI started work on 1 January 2025. The articles that carry the day-to-day duties, including the OIV obligations and the incident reporting rules, took effect on 1 March 2025. Those duties are active now.

Ley 21.663 is a different law from Chile’s data privacy reform, Ley 21.719. One governs cybersecurity and incident response. The other governs personal data. If you’re mapping both, our guide to data privacy compliance covers the privacy side.

Who Enforces the Law

Enforcement runs through two organizations.

The Agencia Nacional de Ciberseguridad (ANCI) is the regulator. It issues protocols and standards, decides which operators count as OIV, supervises compliance, and applies sanctions.

The CSIRT Nacional is the national incident response team. It receives incident reports and coordinates the response. Reports reach it through the notification platform the ANCI runs.

For a regulated operator, the ANCI is the regulator you’ll deal with directly. It can request information, direct your response during an incident, and open a sanctioning process when a duty is missed.

Who Must Comply, and Which Sectors Are Regulated

The law reaches two overlapping groups. The first is any provider of an essential service (PSE). The second is the smaller set of those providers that ANCI designates as vitally important.

The Essential Sectors

Article 4 defines the essential services. They cover State administration and the national electricity coordinator, holders of public service concessions, and private companies working in:

  • electricity generation, transmission, or distribution
  • fuel transport, storage, or distribution
  • drinking water and sanitation
  • telecommunications and digital infrastructure
  • digital services and third-party managed IT
  • land, air, rail, and maritime transport, and their infrastructure
  • banking, financial services, and payment systems
  • social security administration
  • postal and courier services
  • healthcare
  • pharmaceutical production and research

Provide one of these and you carry the general duties in Article 7. Whether you also carry the stricter Article 8 duties depends on being designated an OIV.

PSE and OIV

An Operator of Vital Importance is a provider whose disruption would significantly affect public safety, the steady supply of essential services, or the functioning of the State. Article 5 sets two conditions, and both have to hold. The service depends on IT systems, and its disruption would cause significant harm. ANCI runs the designation through Decreto 285/2024, weighs each candidate with the relevant sector authority, and reviews the list at least every three years.

Who ANCI Has Already Designated

The designation is already well underway. ANCI ran its first qualification process in two stages. The first, finalized on 17 December 2025, designated 915 operators as OIV. A second stage in 2026 added a further 239, taking the first process to 1,154 operators. They span the essential sectors, including electricity, telecommunications, banking and payments, digital services and infrastructure, healthcare, fuel, and water. If you operate in one of these and haven’t been designated yet, the next review cycle is when your status could change. (OIV figures current as of July 2026.)

How Ley 21.663 Sits With Existing Sector Rules

For several sectors, cybersecurity duties didn’t start with Ley 21.663. The law adds a cross-cutting layer over regimes that already existed, and ANCI now sits above them as the national authority, coordinating the CSIRT Nacional and the sectoral CSIRTs.

If you run security at a bank, you’ve followed the CMF’s Chapter 20-10 on information security and cybersecurity since 2020. Ley 21.663 doesn’t replace it. A bank designated as an OIV reconciles the CMF program with the Article 8 duties, and its incident reporting has to satisfy both.

If you run an electricity operation, the Coordinador Eléctrico Nacional’s cybersecurity standard, built on NERC-CIP and overseen by the SEC, has applied to the sector for years, with its own sectorial CSIRT and incident reporting. Ley 21.663 layers the national duties, and the three-hour CSIRT Nacional alert, on top of that.

The pattern holds across the regulated sectors. The existing sector rules stay in force, and Ley 21.663 sets the common baseline and the single regulator above them. The real work is mapping what you already do onto the Article 8 duties, rather than starting from scratch.

The Core Obligations

Every obligated institution has the general duties set out in Article 7. They apply standing measures to prevent, report, and resolve incidents, and they follow the protocols the ANCI issues.

PSE (essential service provider)OIV (operator of vital importance)
Who Any essential-service provider A PSE, or a critical private entity, that ANCI designates
General duties (Art. 7) Yes Yes
Specific duties (Art. 8) No SGSI, register, continuity plans, drills, delegate, training
Reporting (Art. 9) 3h / 72h / 15 days Plus 24h if a service is down, and a 7-day action plan
Maximum fine Up to 20,000 UTM Up to 40,000 UTM

Article 8 asks more of Operators of Vital Importance. They have to:

  • run a continuous information security management system (SGSI) that keeps assessing risk to networks, systems, and data
  • keep a register of the actions that make up the SGSI (Article 8 b), so there’s an auditable record that the system runs
  • hold operational continuity and cybersecurity plans, certified under Article 28 and reviewed at least every two years
  • run continuous review, exercises, and drills, and report relevant findings to the CSIRT Nacional
  • take prompt measures to limit the impact and spread of an incident
  • appoint a cybersecurity delegate (Article 8 i) as the ANCI’s counterpart
  • train staff and notify affected parties when an incident warrants it

If you already run an ISO 27001 ISMS, the SGSI will feel familiar. The law asks for the same management-system discipline, applied continuously and evidenced in the Article 8 b) register. That continuous stance is the one behind CTEM, treating exposure as something you assess and reduce all the time, not once a year.

The register in Article 8 b) matters more than it first appears. Building an auditable trail of security actions by hand is slow, and gaps show up the moment your team gets busy. Kept as a byproduct of how the work already runs, it stays complete without extra effort.

The Three-Hour Reporting Rule

Article 9 sets the reporting schedule for incidents with significant effects. This is the deadline manual work tends to miss.

ReportDeadlineApplies to
Early alert (alerta temprana) Within 3 hours of becoming aware All obligated institutions
Update (segundo reporte) Within 72 hours General case
Update when an essential service is down Within 24 hours OIV
Action plan Within 7 calendar days OIV
Final report (informe final) Within 15 calendar days of the early alert All

Three hours runs from the moment you become aware of an incident. Inside that window your team has to detect the event, work out its scope, collect indicators of compromise, decide whether it crosses the significant-effects threshold, and file an alert the CSIRT Nacional can act on. Most of that is triage, and most triage still happens by hand, often after hours, against a full queue of alerts.

That’s getting harder. Attackers now discover, validate, and exploit weaknesses at machine speed, often within a day of a vulnerability becoming public. When detection and triage depend on manual handoffs, three hours is very little time.

Missing the report isn’t a technicality. Article 38 treats a failure to report under Article 9 as a serious infraction.

Penalties for Non-Compliance

Article 40 sets the fines on a scale measured in UTM (unidad tributaria mensual). Every ceiling doubles for an OIV.

SeverityStandard OperatorOperator of Vital Importance
Minor (leve) Up to 5,000 UTM Up to 10,000 UTM
Serious (grave) Up to 10,000 UTM Up to 20,000 UTM
Very serious (gravísima) Up to 20,000 UTM Up to 40,000 UTM

In round terms, the top OIV fine of 40,000 UTM is roughly US$3 million; the exact figure tracks the monthly UTM and the exchange rate.

Article 38 lists the general infractions, and Article 39 the ones specific to OIVs. Not keeping the Article 8 b) register, or not naming a delegate, counts as a minor infraction. Failing to contain an incident with significant impact is among the most serious. Infractions lapse three years after they occur.

Operating Under Ley 21.663

The law states what to achieve. How you achieve it is left to you. Most of the effort goes into three time-bound duties that all come due during the same incident: the three-hour alert, the continuous SGSI and its register, and the containment of an active attack. You answer for them to your board and, now, to a regulator.

The First 90 Days

A practical order of work tends to hold across operators. Confirm your status as a provider or an OIV, and appoint the delegate. Stand up the SGSI and the register so evidence starts accumulating by default. Then connect detection to reporting, so the three-hour and 72-hour steps don’t depend on someone noticing.

What to Automate, and What Stays Human

The three-hour alert and the Article 8 b) record are repetitive and run to a deadline. That’s the work automation does well. Piecing together an early alert by hand, mid-incident, uses up most of the three hours, and a reactive, ticket-driven SOC rarely hits it. Writing up the record afterward leaves gaps the ANCI will find. A system that detects the incident, drafts the alert from what it already knows, and builds the record as the response happens takes both off your team.

The judgment stays with you. Whether a risk is acceptable, how a duty applies to your operation, the root-cause analysis, the calls with the regulator and the board, none of that can be handed to software. Automating the mechanical work is what frees the time to do it properly.

The tool you choose has to act inside limits you set, because automation that moves on its own during an incident can cause the next one. It has to produce a record the ANCI accepts as it stands, not a log you rewrite later. And it has to work with your ISO 27001 program, your CMF obligations, and your sector CSIRT, not replace them.

That’s how we’ve built Zynap. Its agents act within your limits and bring the decisions that matter back to you. Its workflows keep the Article 8 b) record as they run. Neither asks you to drop the frameworks you already answer to. For enterprise teams, that’s Zynap for Enterprises.

Ley 21.663 for MSSPs

If you’re a managed provider, you meet these duties for several regulated clients at once, each with its own deadlines and evidence trail. Handling that at scale is a question of multitenancy and delivery automation, running proactive workflows per client without rebuilding the process each time. Our MSSP solution is built for that.

How It Compares to NIS2

The structure will look familiar to multinationals. The staged reporting in Ley 21.663 mirrors the early-warning and follow-up model in the European NIS2 directive, and the essential-operator scope resembles NIS2’s essential and important entities. A Chilean subsidiary of an EU group can often reuse the same framework, mapped to the ANCI’s deadlines and the OIV designation.

Meet Us at the CISO Breakfast and Segurinfo Chile

We’re running a session on exactly this. On Tuesday 11 August 2026 at 10:00 Chile time, our Field CTO Vicente Martín and Carlos Ortiz Hijar of Anida host a CISO Breakfast, in Spanish, on meeting Ley 21.663. It’s built for CISOs, cybersecurity delegates, and compliance leads in regulated sectors.

We’ll also be at SEGURINFO Chile 2026 on 25 August, at the Hotel W in Santiago. Come find the team if you’ll be there, we’re happy to talk through what the law means for your operation. Or, to see how the reporting and evidence duties can run without manual effort, request a demo.

FAQs

What is Ley 21.663?

It's Chile's Ley Marco de Ciberseguridad, the first law to set broad cybersecurity duties for the State and for providers of essential services. It was published in April 2024, and its core obligations have applied since 1 March 2025.

Who regulates cybersecurity in Chile?

The Agencia Nacional de Ciberseguridad (ANCI). It supervises compliance, designates Operators of Vital Importance, coordinates the CSIRT Nacional, and applies sanctions.

Which companies have to comply?

State bodies and providers of essential services in sectors such as energy, banking, water, health, transport, telecommunications, and digital infrastructure. A subset are designated OIV and carry stricter duties.

What's the difference between a PSE and an OIV?

A provider of an essential service (PSE) has general duties. An OIV is a provider whose disruption would cause significant harm. ANCI designates it and applies the Article 8 duties, including a continuous SGSI, continuity plans, and a cybersecurity delegate.

How do I know if my company is an OIV?

ANCI designates an Operator of Vital Importance when your service depends on IT systems and its disruption would cause significant harm to public safety, essential services, or the functioning of the State. It makes the call under Decreto 285/2024 and reviews the list at least every three years, so a company can be brought in at a later round.

How fast do incidents have to be reported?

An early alert to the CSIRT Nacional within three hours, an update at 72 hours (24 hours for an OIV whose essential service is down), an OIV action plan within seven days, and a final report within 15 days of the early alert.

What are the penalties for non-compliance?

Fines scale with severity, measured in UTM. They reach up to 20,000 UTM for a standard operator, and up to 40,000 UTM for an Operator of Vital Importance, whose ceilings are double at every level.

Since when has Ley 21.663 applied?

It was published in April 2024. The ANCI began operating on 1 January 2025, and the core obligations, including the OIV duties and incident reporting, have applied since 1 March 2025. OIV designation has been rolling out in stages through 2025 and 2026.

Is CiberLupa part of the law's obligation?

No. CiberLupa is a public service the ANCI runs so people can check whether their email appears in known data leaks. It's not the reporting channel, and not a duty under the law.

The Future of Cybersecurity is Preemptive

By clicking the button above, I consent to Zynap, storing and processing the personal information submitted above to provide me the content requested in accordance with the Privacy Policy. In compliance with the information obligation established by the data protection regulation, we provide you the information regarding the processing of your personal data, how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy in our Privacy Policy.