UPPERSETUP logo

Hong Kong’s First Cybersecurity Statute: Cap. 653, the Eight Critical Infrastructure Sectors and the 12- and 48-Hour Reporting Clocks

Hong Kong’s First Cybersecurity Statute: Cap. 653, the Eight Critical Infrastructure Sectors and the 12- and 48-Hour Reporting Clocks

The Protection of Critical Infrastructures (Computer Systems) Ordinance — Cap. 653 — is the first statute in Hong Kong’s history to impose binding cybersecurity obligations. It was passed by the Legislative Council on 19 March 2025, assented to on 27 March 2025, and brought into operation in its entirety on 1 January 2026. It does not reach every company: it reaches a narrow population of designated critical infrastructure operators across eight sectors, and imposes on them three categories of duty — organisational, preventive, and incident reporting and response.

Three points that decide whether the Ordinance reaches your company and what it costs.

One: the Ordinance applies only to those designated in writing, and the list of designations is not published. The obligations arise not from operating in one of the eight sectors but from a written notice of designation under section 12. The Commissioner’s Office answers the question directly: “To prevent CIs from becoming targets of attacks, the legislation only sets out the sectors of CIs, instead of disclosing the full list.” An operator is under no duty to disclose its own designation, but is not barred from doing so either.

Two: the reporting clock is twelve hours for a serious incident and forty-eight for anything else. Schedule 6 to Cap. 653 sets: 12 hours from the moment the operator becomes aware, where the incident has disrupted, is disrupting or is likely to disrupt the core function of the critical infrastructure; 48 hours in every other case; 48 hours to put the notification in writing where the first notification was not in the specified form; and 14 days for the full written report.

Three: the maximum fine is HK$5,000,000, and imprisonment attaches to exactly one offence — which is not an operator’s offence. Every Part 4 obligation on operators is fine-only. Imprisonment — up to six months summarily and up to two years on indictment — sits in section 58, for unlawful disclosure of protected information by a person acting in an official capacity.

The Legal Framework: One Ordinance, One Commencement Notice and Six Codes of Practice

As at August 2026 the regulation of critical infrastructure cybersecurity in Hong Kong rests on one Ordinance, one piece of subsidiary legislation bringing it into force, and six codes of practice, none of which is subsidiary legislation.

Instrument

Ide­ntifi­cation

Key dates

Role

Protection of Critical Infra­stru­ctures (Computer Systems) Ordinance

Cap. 653, Ord. No. 4 of 2025

Passed by the Legislative Council on 19 March 2025; assented to by Acting Chief Executive Eric Chan on 27 March 2025; gazetted 28 March 2025; in operation from 1 January 2026

The sole primary instrument

Protection of Critical Infra­stru­ctures (Computer Systems) Ordinance (Co­mmence­ment) Notice

L.N. 144 of 2025

Signed by Secretary for Security Tang Ping-keung on 18 June 2025; gazetted 27 June 2025; appointed 1 January 2026 as the commencement day

The only subsidiary instrument made under Cap. 653 to date; section 70 empowers the Secretary for Security to make regulations, a power not yet exercised

Code of Practice Pursuant to the Protection of Critical Infra­stru­ctures (Computer Systems) Ordinance (generic)

Version 1.0, issued by the Commissioner

Effective 1 January 2026

Categories 1, 2 and 3 for operators regulated by the Commissioner

Sectoral Code of Practice for the Energy Sector

Version 1.0, issued by the Commissioner

Effective 28 January 2026

Categories 1 and 2, energy

Code of Practice for authorized insti­tutio­nsdesignated by the Monetary Authority

Issued by the Monetary Authority

Effective 2 June 2026

Categories 1 and 2, banks

Code of Practice for payment system infra­stru­cture operators

Issued by the Monetary Authority

Effective 10 June 2026

Categories 1 and 2, payment systems

Code of Practice for stored value facility licensees

Issued by the Monetary Authority

Effective 12 June 2026

Categories 1 and 2, SVF

Sectoral Code of Practice for the Land Transport Sector

Version 1.0, issued by the Commissioner

Effective 22 June 2026

Categories 1 and 2, land transport

Commencement was a single event, with no phased timetable. The enacting line on the legislation portal reads “[1 January 2026] L.N. 144 of 2025”, with no provisions carved out. The Law Draftsman’s own information note for Cap. 653 as at 1 January 2026 records: “Provisions Not Yet In Operation — Nil. Amendments Not Yet In Operation — Nil.” As at August 2026 there is nothing in Cap. 653 awaiting commencement.

The Ordinance originates in the Protection of Critical Infrastructures (Computer Systems) Bill, gazetted 6 December 2024, with First Reading on 11 December 2024. The Bill was scrutinised by a Legislative Council Bills Committee whose first meeting was held on 7 January 2025.

A distinction to settle at the outset, and the one most often lost. Cap. 653 is not a personal data statute. Personal data in Hong Kong is governed by the Personal Data (Privacy) Ordinance (Cap. 486), as amended in 2021 for doxxing, and supervised by the Privacy Commissioner for Personal Data. Cap. 653 protects the availability and integrity of computer systems, not the privacy of what sits inside them. Different regulators, different duties, different sanctions — and compliance with one does not discharge the other.

A second distinction that matters for international groups. Mainland China’s critical information infrastructure regime — articles 31 to 39 of the Cybersecurity Law and the Regulations on the Security Protection of Critical Information Infrastructure, in force from 1 September 2021 — does not apply in Hong Kong. Cap. 653 is a purely local Ordinance with its own definitions, its own regulator, and no data-localisation or procurement security-review requirement. The author’s assessment: conflating the two regimes is the commonest substantive error in commentary on Cap. 653, and it produces a materially overstated view of the compliance burden on a Hong Kong entity.

What Cap. 653 Treats as Critical Infrastructure: A Definition with Two Limbs

“Critical infrastructure” is defined in section 2(1) of Cap. 653 through two independent limbs, and the second is not tied to any sector at all. The definition reads:

critical infrastructure (關鍵基礎設施) means — (a) any infrastructure that is essential to the continuous provision in Hong Kong of an essential service in a sector specified in Schedule 1; or (b) any other infrastructure the damage, loss of functionality or data leakage of which may hinder or otherwise substantially affect the maintenance of critical societal or economic activities in Hong Kong.”

Limb

What it reaches

How it is established

Limb (a) — sectoral

Infra­stru­cture essential to the continuous provision in Hong Kong of an essential service in a Schedule 1 sector

Through the list of eight sectors in Schedule 1

Limb (b) — non-se­cto­ral

Any other infra­stru­cture whose damage, loss of functionality or data leakage may hinder or otherwise substantially affect the maintenance of critical societal or economic activities in Hong Kong

At the regulating authority’s discretion, irrespective of sector

Limb (b) is the most underestimated provision in the statute, and it deserves the attention of exactly those who assume no sector applies to them. It is bounded by no industry, no size and no ownership characteristic.The practical consequence: an organisation confident the Ordinance does not reach it because its activity is not named in Schedule 1 can nonetheless be designated a critical infrastructure operator (CI operator) under limb (b), if the regulating authority considers its infrastructure essential to maintaining critical societal or economic activities.

The term “essential service” is not defined in Cap. 653. It appears three times in the text — in limb (a) of “critical infrastructure”, in limb (a) of “core function” and in item 5 of Part 2 of Schedule 3 (“A recovery plan for resuming the provision of essential services by, or the normal operation of, the critical infrastructure concerned”) — and its content is supplied entirely by the Schedule 1 sector list.

The absence of a definition of “essential service” is a design choice rather than a drafting oversight, and its consequences are practical. Because the service is identified through its sector rather than through criteria of its own, the statutory boundary is set not by what the organisation does but by which of the eight sectors the regulating authority assigns its activity to. There is no service definition to argue against.

“Core function” is defined separately, and differently, for each limb:

core function (核心功能), in relation to a critical infrastructure, means — (a) if the infrastructure falls within paragraph (a) of the definition of critical infrastructure in this subsection — the provision of the essential service concerned; or (b) if the infrastructure falls within paragraph (b) of that definition — any function of the infrastructure that is essential to the maintenance of critical societal or economic activities in Hong Kong.”

“Computer system” is defined broadly:

computer system (電腦系統) — (a) means a set of computer hardware and software that is organized for the collection, processing, storage, transmission or disposition of information; and (b) includes a computer.”

“Computer-system security incident” carries two cumulative elements:

“means an event that — (a) involves — (i) access, without lawful authority, to the critical computer system; or (ii) any other act done, without lawful authority, on or through the critical computer system or another computer system; and (b) has an actual adverse effect on the computer-system security of the critical computer system.”

Both elements must be present together, and that matters for the reporting threshold. There must be an act without lawful authority and an actual adverse effect on the security of the system. The practical consequence: an unsuccessful intrusion attempt, blocked by controls and producing no actual adverse effect, does not meet the Cap. 653 definition and triggers no notification. But the classification has to be made deliberately and documented — “actual adverse effect” is an evaluative test, and the decision will need justifying on an inspection.

“Computer-system security threat” is defined separately and at a lower threshold:

“means an act (whether known or suspected) — (a) that is, or is capable of being, done on or through the critical computer system or another computer system; and (b) the doing of which is likely to have an adverse effect on the computer-system security of the critical computer system.”

The difference between an “incident” and a “threat” is the difference between “actual adverse effect” and “likely to have an adverse effect”. The section 28 notification duty attaches to an incident — that is, to actual effect. The regulator’s Part 5 powers are triggered by a threat as well — at an earlier and lower threshold, extending to an act “whether known or suspected”. The practical consequence: an event that requires no notification as an incident may still ground regulatory action as a threat.

The Eight Schedule 1 Sectors, and Why the List Can Change Without New Legislation

Schedule 1 to Cap. 653, headed “Sectors Specified for Definition of Critical Infrastructure”, contains exactly eight items. The list reads:

1.        Energy

2.        Information technology

3.        Banking and financial services

4.        Air transport

5.        Land transport

6.        Maritime transport

7.        Healthcare services

8.        Telecommunications and broadcasting services

No.

Schedule 1 sector

Regulating authority

1

Energy

The Commissioner

2

Information technology

The Commissioner

3

Banking and financial services

The Monetary Authority — for the named categories of organisation

4

Air transport

The Commissioner

5

Land transport

The Commissioner

6

Maritime transport

The Commissioner

7

Healthcare services

The Commissioner

8

Tele­communi­cations and broadcasting services

The Commu­nica­tions Authority — for the named categories of organisation

Three points of wording that summaries routinely get wrong. The statute says “Maritime transport”, not simply “maritime”; “Telecommunications and broadcasting services”, with “services”; and air transport precedes land transport in the list rather than following it. The Schedule is headed “Sectors”, not “essential services” — consistent with the fact that “essential service” carries no statutory definition.

The sector list can be amended by notice of the Secretary for Security, without new primary legislation. Section 71 reads:

Amendment of Schedules — (1) The Secretary for Security may by notice published in the Gazette amend any of the Schedules. (2) A notice under subsection (1) may contain incidental, consequential, supplemental, transitional or savings provisions that are necessary or expedient in consequence of the notice.”

Such a notice appears to be subsidiary legislation and subject to negative vetting by the Legislative Council — but the Ordinance does not say so expressly. The phrase “is not subsidiary legislation” appears three times in Cap. 653: in section 8(8) on codes of practice, in section 55(2) on exemption notices and in section 55(6) on revocation notices. Section 71 carries no such statement, from which subsidiary legislation status follows under the general rule in section 34 of the Interpretation and General Clauses Ordinance (Cap. 1). This is an inference from the absence of a disapplying clause, not an express provision. The practical consequence: the composition of the eight sectors, the list of regulated organisations in Schedule 2 and the reporting deadlines in Schedule 6 can all be altered by a Gazette notice rather than by amending the Ordinance. For planning purposes the sector list should be treated as movable, not fixed.

Section 71 reaches all seven Schedules, including Schedule 6 with the incident reporting deadlines. That makes the 12- and 48-hour clocks alterable by the same streamlined route.

The author’s assessment: the combination of the non-sectoral limb (b) in the definition and the section 71 power to amend Schedules by notice means the perimeter of this Ordinance is not closed. An organisation outside all eight sectors today can enter the perimeter by two distinct routes — designation under limb (b) with no change to the statute, or an extension of Schedule 1 by a notice of the Secretary for Security. What that means for an international group with a Hong Kong presence: the thing to monitor is not only the text of the Ordinance but the Gazette.

Who Is a CI Operator, and What Counts as a Critical Computer System

The statutory term is “CI operator”, not “critical infrastructure operator”: the phrase “critical infrastructure operator” appears nowhere in Cap. 653. Section 2(1): “CI operator (關鍵基礎設施營運者) means an organization designated under section 12.” The abbreviation “CIO”, widely used in government materials and commentary, is not a statutory term.

Obligations arise from a written notice, not from the factual character of the business. The sequence runs: the regulating authority establishes that infrastructure is critical, designates the organisation as an operator by written notice under section 12, and designates specific computer systems as critical by a separate written notice under section 13.

Section 13(1) sets two conditions for a system to become a critical computer system:

the regulating authority may, by written notice to the operator, “designate a computer system (whether under the control of the operator or not) that — (a) is accessible by the operator in or from Hong Kong; and (b) is essential to the core function of a critical infrastructure operated by the operator, as a critical computer system for the infrastructure.”

Element of the designation regime

Position

Form

Written notice from the regulating authority

What the notice states

The effective date of the designation and the critical computer systems it covers

May the system be outside the operator’s control

Yes — section 13(1) expressly says “whether under the control of the operator or not”

Territorial test

The system must be accessible by the operator in or from Hong Kong

Functional test

The system must be essential to the core function of the critical infra­stru­cture

Is the list of designations published

No

May an operator disclose its own designation

Yes — the Ordinance imposes no bar

“Accessible by the operator in or from Hong Kong” is the Ordinance’s only territorial limiter, and it operates as an element of the test rather than as a carve-out. The same formula recurs in sections 22(2)(c)(i), 30(1)(a)(ii) and 35(1)(a)(ii) in relation to documents. The practical consequence: a system hosted on an overseas cloud service but accessible to the Hong Kong operator from Hong Kong can be designated a critical computer system. Locating the server outside Hong Kong is, by itself, no protection against designation.

The words “whether under the control of the operator or not” extend the regime to suppliers’ systems. An operator can be required to secure a system it neither owns nor runs — a key third-party platform, for instance. The practical consequence: contracts with critical IT suppliers need reviewing for the operator’s right to require audits, risk assessments and drill participation, because the statute places the duty on the operator regardless of whether it has the contractual leverage to discharge it.

The list of designated operators is not published, and that is the official position. The Commissioner’s Office states: “To prevent CIs from becoming targets of attacks, the legislation only sets out the sectors of CIs, instead of disclosing the full list.” On self-disclosure it says: “The Ordinance does not prohibit individual operators from disclosing their identities.” An organisation learns of its status because “Organizations designated as CI operators will receive written notice from the regulating authorities, setting out the effective date and the critical computer systems covered.”

The author’s assessment: keeping the list confidential is defensible on security grounds and inconvenient for counterparty diligence. Whether a supplier, partner or acquisition target is a designated CI operator cannot be established from open sources. The practical consequence for M&A and procurement: the question belongs in the due diligence questionnaire and in the contractual warranties, because there is no public register. The only statutory reference to a document evidencing designation is section 68: a certificate signed by or on behalf of a regulating authority “must be admitted in the proceedings on its production without further proof” — an evidential rule for court proceedings, not a counterparty screening tool. Checking corporate control of a potential operator — through the significant controllers register, for instance — does not reveal Cap. 653 status, but it does establish who owes the section 20 notification.

The Commissioner and the Office: Who Regulates, and with What Resources

The Commissioner of Critical Infrastructure (Computer-system Security) is appointed by the Chief Executive under section 3(1) of Cap. 653, for a term of not more than five years, and is eligible for reappointment. The provision reads: “For the purposes of this Ordinance, the Chief Executive may appoint a person to be the Commissioner of Critical Infrastructure (Computer-system Security).”

The first Commissioner, appointed from 1 January 2026 for a three-year term, is Mr Francis Chan Wing-on.Before the appointment he was Assistant Director (Critical Infrastructure) at the Security Bureau from May 2024, having previously headed the Hong Kong Police Force’s Cyber Security and Technology Crime Bureau and chaired INTERPOL’s Cybercrime Expert Group.

Section 3 creates an office-holder, not a body, and the Ordinance draws that distinction itself. The Office of the Commissioner of Critical Infrastructure (Computer-system Security) is an administrative unit within the Security Bureau, not a free-standing statutory authority. In its own words, it was “Established under the Security Bureau of the Government of the HKSAR in January 2026”.

The Commissioner’s functions are listed in section 4, and the list is not closed:

“(a) to identify critical infrastructures and designate CI operators and critical computer systems; (b) to issue, revise and maintain codes of practice in respect of category 1 obligations, category 2 obligations and category 3 obligations of CI operators; (c) to monitor and supervise compliance with the provisions of this Ordinance; (d) to regulate CI operators with regard to the computer-system security of the critical computer systems of critical infrastructures; (e) to monitor, investigate and respond to computer-system security threats and computer-system security incidents in respect of the critical computer systems of critical infrastructures; (f) to coordinate the implementation of this Ordinance with designated authorities and government departments; and (g) to perform any other functions imposed or conferred on the Commissioner under this or any other Ordinance.”

Paragraph (g) of section 4 leaves the list open — “any other functions imposed or conferred on the Commissioner under this or any other Ordinance”. Section 54 adds to it: the Commissioner may perform a designated authority’s functions in respect of that authority’s infrastructures and operators where satisfied that it is “necessary for the timely protection of the critical computer systems of the critical infrastructure concerned” or “otherwise necessary in the public interest”. Section 70 separately empowers the Secretary for Security to make regulations “for the better carrying out of the provisions of this Ordinance”, with maximum fines of HK$3,000,000 summarily and HK$5,000,000 on indictment; as at August 2026 that power has not been exercised.

The Office’s resources are disclosed in Legislative Council papers.

Measure for the Commi­ssio­ner’s Office

Figure

Total esta­blishme­nt

32 staff

Directorate posts

3 — the Commissioner on a permanent basis, two further posts time-limited

Seconded police officers

11

Computer system profe­ssio­nals

12

Legal profe­ssio­nals

2

Admi­ni­strative and clerical staff

4

Notional annual salary cost of the three directorate posts at mid-point

HK$7,123,020

Full annual average staff cost, including on-costs

HK$10,058,000

The Office has no separate programme or separate line in the Estimates. The 2026-27 Estimates under Head 151, Security Bureau, carry only the narrative that during 2025-26 the Bureau “enacted the Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) and established the Office of the Commissioner of Critical Infrastructure (Computer-system Security)”, with funding sitting inside the internal security programme.

The appeal panel is created by section 47 and was staffed from the same date. A chairperson and seventeen members — eighteen in all — were appointed for 1 January 2026 to 31 December 2027. An individual appeal is not heard by the panel as a whole but by an appeal board drawn from it for that appeal, consisting of a chairperson and at least two other members under section 4(1) of Schedule 7.

The Secretary for Security may direct the Commissioner. Section 69 is the only substantive provision added to the text between the Bill and the Ordinance:

“(1) The Secretary for Security may give any directions the Secretary considers appropriate (whether generally or in any particular case) to any of the following persons with respect to the performance of a function under this Ordinance — (a) the Commissioner; (b) an authorized officer of the Commissioner; (c) a public officer to whom the function is delegated under section 52(1). (2) A person to whom a direction is given under subsection (1) must, in performing the function, comply with that direction.”

The author’s assessment: thirty-two staff across eight sectors describes a regulator working through codes of practice and designations rather than continuous supervision. By contrast, the Office issued six codes of practice in its first six months, while no inspection, direction or penalty has been published. The practical consequence: for the first few years an operator’s principal interface with the regulator will be self-assessment against the code of practice and the statutory reporting, not site inspections.

Two Designated Authorities, and Why There Are Only Two

Alongside the Commissioner, the Ordinance confers regulatory functions on two existing sectoral regulators — the Hong Kong Monetary Authority and the Communications Authority. The mechanism sits in section 5 and Part 2 of Schedule 2: for the organisations listed there, the regulating authority is the sectoral body rather than the Commissioner.

Part 2 of Schedule 2 contains exactly two items.

Designated authority

Sector

Organisations within its remit

Monetary Authority

Banking and financial services

(a) an authorized institution; (b) a licensee under section 2 of Cap. 584; (c) a settlement institution of a designated system; (d) a system operator of a designated system

Co­mmuni­cations Authority

Teleco­mmuni­cations and broadcasting services

(a) a unified carrier licence holder; (b) a space station carrier licence holder; (c) a domestic free television programme service licensee; (d) a licensee under section 13A(1) of Cap. 106

The split of powers between a designated authority and the Commissioner is deliberately partial — and this is the defining feature of the design. Section 6 confines designated authorities to category 1 and category 2 obligations. Category 3 obligations — drills, the emergency response plan and incident notification — remain with the Commissioner in every case without exception.

What this means for a bank or a carrier: there will be two regulators, not one. The bank answers to the Monetary Authority on organisational and preventive requirements; notification of a computer-system security incident within 12 or 48 hours goes to the Commissioner. Different addressees, different forms, different clocks — and an internal escalation procedure has to separate them explicitly.

Sections 2(3) and 2(4) fix this allocation in the Ordinance’s own vocabulary. Section 2(3) creates the concept of a “specified critical infrastructure for the authority”, with every other infrastructure being a specified critical infrastructure for the Commissioner. Section 2(4) allocates operators: “if a CI operator is a regulated organization of a designated authority, the operator is a CI operator regulated by the authority; or a CI operator is otherwise a CI operator regulated by the Commissioner”. Later provisions are addressed to “the regulating authority”, and these definitions determine who that is in a given case.

Section 54 lets the Commissioner take over a designated authority’s functions. The Commissioner may perform any function of a designated authority “as if the Commissioner were the designated authority”, but only where satisfied that it is necessary for the timely protection of the critical computer systems concerned or otherwise necessary in the public interest. The split between the categories is therefore not absolute.

Section 56 allows a designated authority to prosecute offences itself, but only summarily. The practical consequence is material: in a prosecution brought by the Monetary Authority or the Communications Authority, the lower of the two statutory maxima applies — HK$300,000 rather than HK$500,000, or HK$3,000,000 rather than HK$5,000,000.

The Communications Authority has not issued a code of practice of its own; it has adopted the Commissioner’s code. This is confirmed on the Authority’s official page. The Monetary Authority took the opposite course and issued three separate codes — for authorized institutions, for payment system infrastructure operators, and for stored value facility licensees.

The Securities and Futures Commission is not a designated authority under Cap. 653. The SFC’s cybersecurity expectations for licensed corporations stand on their own footing under the Cap. 571 licensing regime, not under Cap. 653. A fund manager operating through OFC and LPF structures does not fall within Cap. 653 by virtue of its SFC licence; it can only be brought in by a designation under section 12.

The author’s assessment: the list in Part 2 of Schedule 2 is closed, and it covers only two of the eight sectors. Energy, information technology, the three transport sectors and healthcare have no designated authority at all — there the Commissioner is the regulating authority. In practice a thirty-two-person office directly supervises most of the sectors, with two sectoral regulators taking weight off only the finance and communications flanks.

Category 1 Obligations: The Organisational Layer

Category 1 is about how the operator is organised: an office in Hong Kong, notification when the operator changes, and an internal computer-system security management unit. These sit in Division 1 and run across sections 19 to 21. None of them is about defensive technology; all three are about who the regulator talks to and at what address.

Section 19: an office in Hong Kong and notification of the address within one month. The operator must have an office in Hong Kong and notify the regulating authority of its address within one month of the date of designation. The period may be extended by the regulating authority. Any change of address must likewise be notified within one month.

Section 20: notification that the operator of the critical infrastructure has changed, within one month. Where an organisation ceases to be the operator of the infrastructure concerned — on a disposal of the asset or a transfer of the function, for example — it must notify the regulating authority within the same one-month period.

Section 21: the computer-system security management unit. The operator must set up such a unit and appoint an employee with adequate knowledge and experience to supervise it. The provision expressly allows the unit’s functions to be carried out by an engaged service provider — but the supervising individual must be an employee of the operator. Changes to the unit and to the supervising employee are notified within one month.

Category 1 obligation

Section

Deadline

Maximum fine on indictment

Office in Hong Kong and notification of address

19

1 month from designation

HK$500,000 + HK$50,000 per day

Notification of a change of address

19

1 month

HK$500,000 + HK$50,000 per day

Notification of a change of operator

20

1 month

HK$5,000,000 + continuing fine

Security management unit and supervising employee

21

from designation; changes 1 month

HK$500,000 + HK$50,000 per day

Note the disproportion: failing to notify a change of operator is punished ten times more heavily than failing to have a security unit at all. The legislative logic is plain — if the regulator does not know who runs the infrastructure today, the rest of the machinery stops working. The practical consequence: on any reorganisation, sale of the business or outsourcing of operations, the section 20 notification belongs on the transaction checklist alongside the corporate filings.

Outsourcing the unit is permitted; outsourcing the liability is not. Section 21 allows an external provider to discharge the unit’s functions, but the duty-holder remains the operator, and the fine under section 21(7)–(8) falls on the operator. A managed-security contract shifts neither the obligation nor the sanction to the vendor.

A Hong Kong office is not the same requirement as a Hong Kong legal entity. The Ordinance speaks of an office and an address, not of a place of incorporation. A foreign organisation designated as an operator must establish a presence at a Hong Kong address — in practice usually through an existing Hong Kong incorporated company or a registered non-Hong Kong company — but Cap. 653 itself prescribes no particular form.

Category 2 Obligations: The Preventive Layer and Three Calendars

Category 2 covers the security management plan, the risk assessment and the security audit — the whole preventive cycle. Division 2 runs from section 22 to section 25 and sets three independent calendars that the operator must run in parallel.

Section 22: notification of material changes to a critical computer system — one month. Notifiable changes include changes to the design, configuration, security or operation of the system. Section 22(2)(c)(i) repeats the Ordinance’s key formula: a system qualifies “whether under the control of the operator or not”.

Section 23: the computer-system security management plan — three months. The operator must prepare the plan within three months of the date of designation, covering the matters listed in Schedule 3. A revised plan is submitted within one month of the revision. The Ordinance requires not only that the plan exist but that it be implemented.

Section 24: risk assessment — the first within twelve months of the designation date, then at least every twelve months after the first period expires. The report is submitted within three months after the expiry of the period within which the assessment was required to be conducted — not within three months of completing it. The statutory words are “within 3 months after the expiry of the period within which the assessment is required under paragraph (a) to be conducted”. The three-month submission period may be extended by the regulating authority on the operator’s application where there are reasonable grounds (s. 24(2)). The assessment must cover all the matters in Schedule 4, including a vulnerability assessment and a penetration test of the critical computer systems. Section 24(5) allows the regulating authority to require an ad hoc assessment.

Section 25: security audit — the first within twenty-four months, then at least every twenty-four months. The report is submitted within three months after the expiry of the period within which the audit was required to be carried out — the same formula as in section 24 — and must cover all the matters in Schedule 5. The submission period is likewise extendable on application (s. 25(2)). Sections 25(4) and 25(6) allow the regulating authority to require an ad hoc audit.

An audit counts as carried out only if an independent auditor carried it out. Section 25(9): “a computer-system security audit is not to be regarded as carried out unless it is carried out by an independent auditor.” Section 25(8) permits an auditor who is an employee of the operator, but subject to that independence requirement. It is the only requirement in Part 4 directed at who performs the work, and it turns the audit into a budget line rather than an internal procedure.

Category 2 obligation

Section

Schedule

First deadline

Frequency

Report deadline

Notification of material changes

22

1 month from the change

as they arise

Security management plan

23

Schedule 3

3 months from designation

revisions 1 month

Risk assessment

24

Schedule 4

12 months

at least every 12 months

3 months from expiry of the period

Security audit

25

Schedule 5

24 months

at least every 24 months

3 months from expiry of the period

The essential difference between sections 24 and 25 is not only frequency but direction of travel. The risk assessment looks forward and identifies threats; the audit looks backward and tests whether the operator has in fact followed its own plan and the Ordinance. They cannot be merged into a single document — the Ordinance prescribes different Schedules with different report content.

All four category 2 obligations carry the same penalty — up to HK$500,000 on indictment plus HK$50,000 for each day the contravention continues. That uniformity is less benign than it looks: the daily element turns an overdue audit into an accumulating figure rather than a one-off fine.

Time runs from the “designation date”, a defined term, not from the date the notice is received. Section 2(1): “designation date, in relation to a CI operator, means the date on which the operator is designated under section 12.” The obligation provisions use a uniform formula — “after the operator’s designation date”. The Commissioner’s Office explains that the written designation notice states the effective date of the designation and identifies the critical computer systems covered.

The author’s assessment: the first two years after designation are the heaviest, and finishing early does not bring the report deadline forward. The plan and the emergency response plan are due at three months, the first risk assessment at twelve, its report at fifteen, the first audit at twenty-four and its report at twenty-seven. Completing an assessment ahead of time does not advance the report deadline: it attaches to the expiry of the period, not to the date the work finishes. The practical consequence: budget for an independent auditor and a risk assessor two years ahead, at the moment the designation notice arrives — not when the deadline approaches.

Category 3 Obligations: Drills, the Response Plan and the Notification Clock

Category 3 stays with the Commissioner in every case, banks and carriers included, and comprises three duties: participation in drills, an emergency response plan, and incident notification. Division 3 runs from section 26 to section 28.

Section 26: computer-system security drills. The Commissioner may require an operator to take part in a drill organised by the Commissioner, on reasonable written notice. There is no free-standing duty to run drills on the operator’s own initiative — the duty is triggered by the Commissioner’s requirement.

Section 27: the emergency response plan — three months. The operator must prepare the plan within three months of the date of designation, covering the matters set out in Part 2 of Schedule 3. A revised plan is submitted within one month.

How Long Is There to Notify an Incident?

Section 28 and Schedule 6 set four deadlines, and the difference between the first two turns on the incident’s effect on the core function of the infrastructure.

What is filed

Provision

Deadline

Runs from

First notification where the incident has disrupted, is disrupting or is likely to disrupt the core function

s. 28(2)(a), Schedule 6

12 hours

when the operator becomes aware of the incident

First notification in all other cases

s. 28(2), Schedule 6

48 hours

when the operator becomes aware of the incident

Written record of a notification given orally or otherwise

s. 28(3)

48 hours

when the first notification was given

Full written incident report

s. 28(4)

14 days

when the operator becomes aware of the incident

The twelve-hour clock does not start with the attack; it starts with disruption of the core function — or with the judgement that disruption is likely. The statutory words are “has disrupted, is disrupting or is likely to disrupt”. “Likely” places the call on the operator at a moment when the picture is still incomplete: if there is reason to believe the core function will be disrupted, the twelve-hour clock applies, not the forty-eight-hour one.

Not every security event is a “computer-system security incident” for the purposes of the Ordinance. The section 2(1) definition requires two cumulative elements: the act must be done without lawful authority, and it must have an actual adverse effect. An unsuccessful intrusion attempt blocked by controls, with no effect, falls outside the definition and requires no notification.

Notification goes to the Commissioner on form CICS005 and the full report on form CICS006. The Commissioner’s Office has published six forms — CICS001 to CICS006 — covering the office address, a change of operator, appointment of the supervising employee, material changes, incident notification and the written incident report.

Sections 26 and 28 are the only operator duties with no continuing fine. The maximum on indictment is HK$5,000,000 for both failure to take part in a drill and failure to notify an incident, but neither provision carries a daily penalty. The reasoning reads plainly enough: a deadline measured in hours does not lend itself to a fine measured in days.

The author’s assessment: twelve hours is a deadline for a signal, not for an investigation. The Ordinance allows fourteen days for the full report, and that is the document intended to carry established facts. The practical consequence: the internal procedure must permit a first notification on incomplete information — stating what is known at the time of filing — rather than waiting for the investigation to close.

Liability: The Full Penalty Scale and the Single Custodial Offence

The maximum fine under Cap. 653 is HK$5,000,000 on indictment, and that is the ceiling for any operator contravention. The Ordinance uses a two-tier scale: a lower figure on summary conviction, a higher one on indictment. Most offences carry an additional continuing fine “for every day during which the offence continues”.

Provision

Substance of the contravention

Summary

On indictment

Continuing fine per day

s. 7(8)–(9)

Failure to comply with a direction of the regulating authority

HK$3,000,000

HK$5,000,000

HK$60,000 / HK$100,000

s. 18

Failure to furnish information — CI operator

HK$3,000,000

HK$5,000,000

HK$60,000 / HK$100,000

s. 18

Failure to furnish information — person other than an operator

HK$300,000

HK$500,000

HK$30,000 / HK$50,000

s. 19(4)–(5)

No office, or address not notified

HK$300,000

HK$500,000

HK$30,000 / HK$50,000

s. 20(2)–(3)

Failure to notify a change of operator

HK$3,000,000

HK$5,000,000

HK$60,000 / HK$100,000

s. 21(7)–(8)

No security management unit or supervising employee

HK$300,000

HK$500,000

HK$30,000 / HK$50,000

s. 22

Failure to notify material changes

HK$300,000

HK$500,000

HK$30,000 / HK$50,000

s. 23(7)–(8)

Failure to submit the security management plan or a revised plan

HK$300,000

HK$500,000

HK$30,000 / HK$50,000

s. 24(8)–(9)

Failure to carry out a risk assessment or submit the report

HK$300,000

HK$500,000

HK$30,000 / HK$50,000

s. 25(11)–(12)

Failure to carry out a security audit or submit the report

HK$300,000

HK$500,000

HK$30,000 / HK$50,000

s. 26(3)–(4)

Failure to take part in a drill

HK$3,000,000

HK$5,000,000

no continuing fine

s. 27(7)–(8)

No emergency response plan

HK$300,000

HK$500,000

HK$30,000 / HK$50,000

s. 28(5)–(6)

Failure to notify an incident

HK$3,000,000

HK$5,000,000

no continuing fine

ss. 42, 45

Obstructing the exercise of powers

HK$300,000

HK$500,000

s. 58(3)

Unlawful disclosure of information

level 6 fine + 6 months’ impri­sonme­nt

HK$1,000,000 + 2 years’ impri­sonme­nt

Imprisonment appears exactly once in Cap. 653 — in section 58(3) — and it is not aimed at operators. The offence targets a person who discloses information obtained in the administration of the Ordinance in breach of the secrecy duty in section 57. No operator obligation is punishable by imprisonment at all.

This is the structural difference between Cap. 653 and Hong Kong’s criminal law on cyber offences. The critical infrastructure statute imposes regulatory liability on an organisation; criminal liability for the attacks themselves sits elsewhere. The Law Reform Commission of Hong Kong issued its report “Cyber-Dependent Crimes and Jurisdictional Issues” on 9 January 2026, recommending five new offences carrying up to two years summarily and up to fourteen years on indictment, with life imprisonment where life is endangered. As at August 2026 no bill implementing those recommendations has been introduced.

Four offences stand apart in severity, and all four address the same thing — the regulator losing sight of the situation. Failure to comply with a direction (s. 7), failure to notify a change of operator (s. 20), failure to take part in a drill (s. 26) and failure to notify an incident (s. 28) are punished an order of magnitude more heavily than the absence of a plan or an audit. The Ordinance treats plans and reports as routine, and communication with the regulator as the condition on which the whole design depends.

Section 65 provides a complete defence to every Part 4 offence and to section 7. The defendant “is entitled to be acquitted” where sufficient evidence is adduced to raise an issue that “(i) the commission of the offence was due to a cause beyond the defendant’s control; and (ii) the defendant took all reasonable precautions and exercised all due diligence to avoid the commission of the offence by the defendant”, and the prosecution does not disprove it beyond reasonable doubt. Section 66 separately governs the “reasonable excuse” element built into several offences, including section 18.

The practical consequence of section 65: documenting reasonable steps has direct evidential value. The defence turns on process rather than outcome — the precautions taken and the diligence exercised. That is why observing a code of practice, documenting a risk assessment and minuting the decision on how an incident was classified serve twice over: as compliance, and as defence material.

The indictment maxima in the table are not available in every case. Under section 56 a designated authority may prosecute in its own name, but such a prosecution is tried before a magistrate summarily only. For an operator supervised by the Monetary Authority or the Communications Authority, the applicable ceiling in such a case is the lower of the two figures.

No enforcement has been published as at August 2026. The Ordinance has been in force since 1 January 2026; the Commissioner’s Office, the Monetary Authority and the Communications Authority have published no directions, prosecutions or fines. No designations of individual operators have been published either, so it is not possible to tell from public sources whether the first deadlines — one month under sections 19 and 21, three months under sections 23 and 27 — have yet fallen due.

Codes of Practice: What Binds and What Does Not

A code of practice under Cap. 653 is not subsidiary legislation and creates no liability of itself, but it is admissible in evidence. This structure is set by sections 8 and 9, and it determines how compliance actually works.

Section 8(8) states it directly: “A code of practice is not subsidiary legislation.” A code therefore does not go through the Legislative Council’s negative vetting procedure and can be revised by the regulating authority without a parliamentary step.

Section 9 supplies the evidential effect. Failure to observe a code does not of itself give rise to liability — but the code is admissible in evidence in proceedings under the Ordinance, and compliance with it is taken into account in deciding whether a statutory duty has been discharged.

In practice a code is neither guidance nor binding law; it is an evidential benchmark. An operator that followed the code will find it easier to demonstrate compliance; an operator that departed from it must be ready to explain by what other means it discharged the same statutory obligation.

Six codes of practice have been issued as at August 2026.

Code of practice

Issued by

Date of issue

Application

Generic Code of Practice

Commissioner

1 January 2026

all operators not covered by a sectoral code

Code of Practice for the Energy Sector

Commissioner

28 January 2026

operators in the energy sector

Code of Practice — authorized institutions

Monetary Authority

2 June 2026

authorized institutions

Code of Practice — payment system infra­stru­cture operators

Monetary Authority

10 June 2026

payment system infra­stru­cture operators

Code of Practice — stored value facility licensees

Monetary Authority

12 June 2026

stored value facility licensees

Code of Practice for the Land Transport Sector

Commissioner

22 June 2026

operators in the land transport sector

The Communications Authority has issued no code of its own and applies the Commissioner’s code. This is confirmed by the Authority itself. Telecommunications and broadcasting operators therefore work to the generic code, not a sectoral one.

Six sectors remain without a dedicated code as at August 2026: information technology, air transport, maritime transport, healthcare services, telecommunications and broadcasting, and the part of banking and financial services outside the Monetary Authority’s three codes. The Generic Code of Practice governs them.

The author’s assessment: the pace at which codes appear is the clearest signal of regulatory priorities. In the Ordinance’s first six months the Commissioner issued codes for two of the six sectors under direct supervision, while the Monetary Authority closed its entire perimeter with three documents inside ten days of June. The practical consequence: an operator in a sector with no dedicated code works from the generic document and must interpret it against its own technology estate — an interpretation that will be tested in evidence if the matter is ever litigated.

A code of practice does not displace obligations arising under other regimes. An authorized institution remains bound by the Monetary Authority’s supervisory expectations under CFI 2.0, C-RAF 2.0 and SPM module TM-E-1; a licensed corporation by the SFC’s requirements; and any data user by the Personal Data (Privacy) Ordinance, Cap. 486. These regimes run alongside Cap. 653 rather than being absorbed into it, and mapping the obligations under each is separate work that Hong Kong company incorporation and maintenance does not itself cover.

Investigation Powers and the Safeguards Built Around Them

Part 5 gives the regulating authority powers to investigate threats and incidents, and they fall into three groups: powers directed at the operator itself, which need no warrant; entry to premises, which needs a magistrate’s warrant; and entry to premises in an emergency, which needs no warrant but does need four cumulative conditions. This is the second layer of the design: the operator’s obligations generate reporting; the investigation powers generate intervention.

Powers aimed at the operator itself require no warrant. Sections 30 and 35 allow an authorized officer, by written notice, to require production of documents, explanations and written answers, and the attendance of a representative, and to inspect, copy, take extracts from and take possession of a document. Section 18 separately makes failure to furnish information an offence — up to HK$5,000,000 for an operator and HK$500,000 for anyone else, in both cases with a continuing fine for every day the offence continues.

A magistrate’s warrant is required for entry to premises and access to devices under sections 31, 32, 37, 38, 39 and 46. Designation as an operator does not by itself give the regulator a right of entry or of connection; section 39 sets the conditions for issuing a warrant, and execution is confined to seven days.

Section 40 is the significant exception: entry to premises in an emergency, without a warrant. The Commissioner may authorize an officer to enter any premises and do the acts specified in section 38(2) “without warrant”, where all four conditions in section 40(2) are met at once:

Condition in section 40(2)

Substance

(a)

reasonable grounds to suspect that something relevant to the investigation is on the premises, or that the investigated system is located there

(b)

reasonable grounds to believe that the operator, or the organisation mentioned in section 37(2), is “unwilling or unable” to take all reasonable steps to assist the investigation or respond to the threat or incident

(c)

“it is not reasonably practicable to obtain a warrant in the circumstances of the case”

(d)

reasonable grounds to believe that entry and the acts are in the public interest, having regard to five listed factors

It is inaccurate to say that access to premises under Cap. 653 always requires a magistrate’s warrant.Section 40 is a real exception, built on the same “unwilling or unable” test as the additional power in section 36, plus the impracticability of obtaining a warrant and a public interest test. Only the act specified in section 38(2)(a) is excluded from what may be done.

Section 36 — the “additional power” — confers a power to require the operator to act, not a power for the regulator to read data itself. It too is conditioned on “unwilling or unable” and on a public interest test.

Safeguard

Provision

What it limits

Ma­gistra­te’s warrant

ss. 31, 32, 37, 38, 39, 46

entry to premises and access to devices in the ordinary course

Four cumulative conditions

s. 40(2)

warrantless entry to premises in an emergency

“Unwilling or unable” plus public interest

s. 36

exercise of the additional power

Re­stri­ctions on self-i­ncrimi­nating material

ss. 41, 44

admissibility in criminal proceedings, except proceedings under sections 42 and 45 and under Part V of the Crimes Ordinance (Cap. 200)

Legal professional privilege

s. 61

the Ordinance does not affect claims, rights or entitlements arising on that ground

Immunity for compliance

s. 60

no civil liability by reason only of complying with the Ordinance

Protection of informers

s. 59

disclosure of an informer’s identity

Secrecy duty

s. 57

use and disclosure of information obtained

Criminal sanction for disclosure

s. 58

breach of section 57

Appeal mechanism

Part 7 and Schedule 7

the five categories of decision listed in section 48(1)

The protection against self-incrimination is not unqualified. Sections 41 and 44 exclude the use of compelled material in criminal proceedings other than proceedings for offences under sections 42 and 45 (obstruction) and proceedings under Part V of the Crimes Ordinance (Cap. 200).

Section 57 sets out a closed list of grounds on which information obtained may be disclosed. One gateway runs to the Privacy Commissioner for Personal Data — section 57(3)(a)(viii). Section 57(8) provides that the secrecy duty does not affect section 13(3) of The Ombudsman Ordinance (Cap. 397) or section 44(8) of the Personal Data (Privacy) Ordinance (Cap. 486).

What Can Be Appealed, and What Cannot

Section 48(1) contains a closed list of five appealable decisions:

•          a decision to give a direction under section 7;

•          a decision to make a designation under section 12;

•          a decision to make a designation under section 13;

•          a decision to impose a requirement under section 24(5) — an ad hoc risk assessment;

•          a decision to impose a requirement under section 25(4) or (6) — an ad hoc audit.

Nothing else is appealable by this route — including a refusal of an exemption under section 55, a requirement under section 36 and information requirements under sections 14 to 17. A notice of appeal is lodged with the chairperson of the appeal panel within one month of receiving notice of the decision (Schedule 7). Lodging an appeal does not of itself stay execution of the decision (s. 48(3)); a stay requires a separate application to the appeal board.

The author’s assessment: the safeguards are real, but they are procedural rather than subject-matter based — and one of them, the warrant, has an express exception. The single genuinely subject-matter limit is legal professional privilege under section 61. The practical consequence: contracts with cloud and managed service providers deserve a review of how the provider will behave on a section 18 demand or when the operator has to comply with a section 36 requirement; and section 60, which removes civil liability by reason only of compliance, is a point worth carrying into the contract itself.

What Cap. 653 Does Not Regulate: The Limits of the Subject Matter

The Ordinance’s subject matter is the computer-system security of critical computer systems, and the limits of that subject matter are visible in the text itself. A search of the enacted text shows which concepts are absent from it.

Concept

Presence in the text of Cap. 653

“content” (of information)

does not appear

“personal data”

does not appear outside two proper names — the Personal Data (Privacy) Ordinance (Cap. 486) and the Privacy Commissioner for Personal Data

“Mainland”

does not appear

“trade secret”

does not appear

“critical infra­stru­cture operator”

does not appear — the statutory term is “CI operator”

“essential service”

not defined — the Ordinance contains no definition of it

A concrete conclusion about the design follows: the Ordinance contains almost no carve-outs by category of information. Cap. 653 has no provision excluding the content of information, personal data or trade secrets from its scope. The one genuine subject-matter carve-out is legal professional privilege: section 61 provides that the Ordinance “does not affect any claims, rights or entitlements that would, apart from this Ordinance, arise on the ground of legal professional privilege”. Otherwise the limitation is procedural — a magistrate’s warrant subject to the section 40 exception, the conditions in section 36, and the secrecy duty in section 57.

Relief is available not by category of data but by obligation, under section 55. The Commissioner may by written notice exempt an operator from any category 1, 2 or 3 obligation where satisfied that it is in the public interest. In deciding, the Commissioner must consider among other things whether the operator is subject to an “alternative obligation” that “is imposed by or under another Ordinance, or any code of practice, direction or requirement (however described)” and “corresponds substantially to the subject obligation”. The practical consequence: a bank already bound by the Monetary Authority’s supervisory requirements is precisely the case section 55(3)(b) is built for. An exemption notice and a revocation notice are not subsidiary legislation (ss. 55(2) and 55(6)), and a refusal to exempt is not among the decisions appealable under section 48(1).

The statement that the Ordinance does not target personal data and business secrets is a policy position, not a provision of the statute. It appears in the Government’s Legislative Council (LegCo) Brief on the Bill and is repeated in the Commissioner’s Office guidance: “The Ordinance does not target personal data or business secrets in the computer systems.” That is the regulator’s official position, but it is stated in explanatory material rather than in the text of Cap. 653.

Extraterritorial reach is not stated expressly, and it is not excluded either. A critical computer system under section 13 is defined as a system “whether under the control of the operator or not” and “accessible by the operator in or from Hong Kong”. The test turns on accessibility to the operator from Hong Kong, not on physical location. A system hosted outside Hong Kong, accessible to the operator from there and essential to the core function of the infrastructure, falls within the definition.

The second limb of the definition of critical infrastructure is considerably wider than the sectoral list. Beyond the eight sectors in Schedule 1, section 2(1) reaches “any other infrastructure the damage, loss of functionality or data leakage of which may hinder or otherwise substantially affect the maintenance of critical societal or economic activities in Hong Kong”. An organisation outside the eight sectors can be designated on that basis.

The Mainland critical information infrastructure regime does not apply in Hong Kong. The PRC Regulations on the Security Protection of Critical Information Infrastructure, promulgated on 27 April 2021 and effective 1 September 2021, together with articles 31 to 39 of the PRC Cybersecurity Law, operate in Mainland China. Hong Kong, as a separate jurisdiction with its own legal system, applies Cap. 653; these are two independent regimes with different regulators, different notification clocks and different sanctions.

The author’s assessment: the most underestimated provision in the Ordinance is the second limb of the definition of critical infrastructure. Public discussion has settled on the eight sectors, while the ground for designation is not confined to them. The practical consequence: an organisation in none of the eight sectors, but whose failure could substantially affect the maintenance of critical societal or economic activities in Hong Kong, sits within the potential reach of the Ordinance — and will learn of it from a written designation notice rather than from its sector classification.

Hong Kong, the European Union and Singapore: Three Regimes Compared

On the first notification deadline, Cap. 653 sits in the middle: stricter than the European Union and more relaxed than Singapore. The comparison is meaningful on three parameters — notification clocks, sectoral coverage and the size of sanctions — because those are directly comparable across the regimes.

Parameter

Hong Kong, Cap. 653

European Union, Network and Information Security Directive (NIS2)

Singapore, Cybersecurity Act 2018

Instrument

Protection of Critical Infra­stru­ctures (Computer Systems) Ordinance, Ord. No. 4 of 2025

Directive (EU) 2022/2555 of 14 December 2022

Act 9 of 2018 as amended by Act 19 of 2024

In force from

1 January 2026

applies from 18 October 2024 (art. 41(1))

key provisions from 31 October 2025 (S 677/2025)

Number of sectors

8

18 (11 in Annex I, 7 in Annex II)

9 critical information infra­stru­cture (CII) sectors

First notification

12 hours where the core function is disrupted; 48 hours otherwise

24 hours — early warning (art. 23(4)(a))

2 hours — set by subsidiary legislation, not by the Act itself

Second deadline

48 hours — written record

72 hours — incident notification (art. 23(4)(b))

Final report

14 days

one month

Maximum sanction

HK$5,000,000

set by Member States on transposition

S$100,000 and 2 years’ imprisonment for failure to report; for the new classes, the greater of S$200,000 or 10 per cent of annual turnoverin Singapore

Imprisonment for the operator

none

determined by national law

yes

NIS2 is not directly applicable law. It obliges Member States to transpose its provisions into national law, and penalty levels are set nationally. A direct comparison of fine amounts between Cap. 653 and NIS2 is therefore not meaningful; the notification clocks and sectoral coverage are.

Singapore is the only one of the three where failure to notify an incident carries imprisonment for the operator. The 2018 Act provides for a fine of up to S$100,000 and imprisonment of up to two years for failure to report. The two-hour figure is not in the Act itself: section 14(1) requires notification “in the prescribed form and manner, within the prescribed period”, and the period is fixed by subsidiary legislation — the Cybersecurity (Critical Information Infrastructure) Regulations. The Act 19 of 2024 amendments introduced new classes of regulated person — entities of special cybersecurity interest (s. 18F) and major foundational digital infrastructure (s. 18M) — with a turnover-linked sanction.

Singapore’s two hours and Hong Kong’s twelve embody different models of operator behaviour. Two hours implies an automatic signal on detection; twelve hours leaves room for an initial assessment of whether the core function is affected. Cap. 653 is deliberately built on the second model: the clock attaches not to detection of an attack but to disruption, or likely disruption, of the core function.

The twelve and forty-eight hour figures entered the text before the Bill was introduced, not during its passage. The consultation paper of July 2024 canvassed two and twenty-four hours; the Bill gazetted on 6 December 2024 already carried 12, 48, 48 hours and 14 days in Schedule 6. The relaxation happened between the consultation and the introduction of the Bill.

The author’s assessment: Hong Kong has chosen a model closer to Europe in philosophy and to Singapore in instrumentation. Like NIS2, the Ordinance emphasises risk management and periodic reporting rather than continuous technical supervision. As in Singapore, the list of regulated organisations is not published and obligations arise from individual designation. The practical consequence for an international group: a single corporate incident response procedure needs three separate time valves — two hours for the Singapore perimeter, twelve for Hong Kong and twenty-four for Europe — because collapsing them into one means running every jurisdiction to the strictest clock.

A Step-by-Step Algorithm for an Organisation

Step 1. Establish whether the organisation sits in one of the eight sectors in Schedule 1. The list is closed: energy; information technology; banking and financial services; air transport; land transport; maritime transport; healthcare services; telecommunications and broadcasting services. Sector membership creates no obligations by itself, but it places the organisation within the regulator’s field of view.

Step 2. Test the second limb of the definition — even if the organisation is outside the eight sectors. If failure of the infrastructure could substantially affect the maintenance of critical societal or economic activities in Hong Kong, designation is possible on that ground too.

Step 3. Identify the regulating authority. An authorized institution, a licensee under section 2 of Cap. 584, a settlement institution or a system operator of a designated system answers to the Monetary Authority for categories 1 and 2. A unified carrier licence holder, a space station carrier licence holder, a domestic free television programme service licensee or a licensee under section 13A(1) of Cap. 106 answers to the Communications Authority. Everyone else answers to the Commissioner. Category 3 is the Commissioner in every case.

Step 4. Wait for the written designation notice and record the effective date of designation. The notice states that date and identifies the critical computer systems covered. Every deadline runs from it. No Cap. 653 obligation arises before the notice is received.

Step 5. Build a twenty-seven-month calendar. One month: office address and security management unit. Three months: security management plan and emergency response plan. Twelve months: first risk assessment; fifteen months: its report. Twenty-four months: first security audit; twenty-seven months: its report.

Step 6. Map the critical computer systems, including systems outside the organisation’s own control. The section 13 test is accessibility to the operator in or from Hong Kong and essentiality to the core function — not ownership and not hosting location.

Step 7. Build an incident notification procedure with two valves. Twelve hours where the core function is disrupted or likely to be disrupted; forty-eight hours otherwise; forty-eight hours for the written record; fourteen days for the full report. The addressee is the Commissioner in every case, on forms CICS005 and CICS006.

Step 8. Test whether there is a basis for an exemption under section 55. Where the operator is already bound by an “alternative obligation” under another Ordinance, code of practice, direction or requirement that “corresponds substantially” to the Cap. 653 obligation, the Commissioner may exempt it by written notice. A refusal is not appealable under section 48(1), so the application is worth preparing on the merits.

Step 9. Budget for an independent auditor. Section 25(9) treats an audit as carried out only if an independent auditor carried it out.

Step 10. Map Cap. 653 obligations against obligations under other regimes. Cap. 486 on personal data, the Monetary Authority’s supervisory expectations, the SFC’s requirements for licensed corporations and contractual commitments to counterparties all run in parallel and are not absorbed into Cap. 653.

Common Mistakes and What They Cost

Mistake 1. Treating the twelve-hour clock as starting with detection of an attack. It attaches to disruption of the core function or to the judgement that disruption is likely. An organisation waiting for confirmation loses hours. Cost: up to HK$5,000,000 on indictment under section 28(5)–(6) — one of the four most severe sanctions in the Ordinance.

Mistake 2. Assuming the Ordinance reaches only systems owned by the operator and hosted in Hong Kong. Section 13 expressly covers systems “whether under the control of the operator or not”, accessible to the operator “in or from Hong Kong”. Cost: an incomplete map of critical systems produces failures to notify material changes (s. 22) and gaps in the security management plan (s. 23) — up to HK$500,000 plus HK$50,000 per day on each count.

Mistake 3. Outsourcing the security management unit and stopping there. Section 21 permits the unit’s functions to be outsourced but requires a supervising individual who is an employee of the operator. Cost: up to HK$500,000 plus HK$50,000 per day, even where the substantive security work is being done properly.

Mistake 4. Failing to notify a change of operator on a disposal or transfer of operations. Section 20 allows one month. Cost: up to HK$5,000,000 plus a continuing fine — ten times heavier than the absence of a security plan, and the most underestimated sanction in the Ordinance for M&A purposes.

Mistake 5. Sending all filings to a single regulator. A bank or carrier reports on categories 1 and 2 to its sectoral regulator and on category 3 to the Commissioner. Cost: an incident notification sent only to the Monetary Authority does not discharge the section 28 duty — up to HK$5,000,000.

Mistake 6. Treating a sectoral code of practice as sufficient compliance, or conversely as optional. A code is not subsidiary legislation (s. 8(8)) and failure to observe it creates no liability of itself (s. 9), but it is admissible in evidence. Cost: in any proceedings, an operator that departed from the code without documented reasoning loses the most direct route to demonstrating that the statutory duty was discharged.

Mistake 7. Giving the audit to the internal audit function. Section 25(8) allows an auditor who is an employee of the operator, but section 25(9) treats an audit as carried out only if it was carried out by an independent auditor. Cost: an audit that fails the independence requirement is legally no audit at all, which is a breach of section 25(1) — up to HK$500,000 plus HK$50,000 per day, with the substantive work fully done.

Mistake 8. Counting the report deadline from the date the assessment or audit was completed. The Ordinance allows three months from the expiry of the period within which the work was required to be done, not from completion. Cost: in one direction a late filing, in the other an unnecessarily compressed internal cycle; the periods are extendable on application (ss. 24(2), 25(2)) — but only before they expire.

Mistake 9. Assuming entry to premises always requires a magistrate’s warrant. Section 40 permits warrantless entry where four conditions are met together, including that a warrant cannot reasonably be obtained in time and that the operator is “unwilling or unable” to assist. Cost: not a fine but unpreparedness — the procedure for dealing with regulators has to cover a warrantless entry scenario, including how events are recorded and how legal professional privilege under section 61 is asserted.

Mistake 10. Notifying every security event. The definition requires two cumulative elements — an act without lawful authority and an actual adverse effect. A blocked intrusion attempt with no effect falls outside it. Cost: not a fine, but the regulator’s time and the organisation’s own, plus the loss of any meaningful distinction between significant and insignificant events in the internal record.

Who Is Caught, Who Is Not, and When Professional Review Is Needed

An organisation is caught if it has received a written notice designating it a CI operator — and only from the date stated in that notice. Nothing else creates an obligation under Cap. 653.

Likely to attract the regulator’s attention:

•          organisations in the eight sectors of Schedule 1 operating infrastructure whose failure would affect the maintenance of critical activities in Hong Kong;

•          organisations outside the eight sectors caught by the second limb of the definition of critical infrastructure;

•          foreign groups whose Hong Kong operations run such infrastructure, whatever the parent’s place of incorporation;

•          organisations whose critical systems are hosted outside Hong Kong but accessible to the operator from there.

An organisation is not caught merely because it:

•          operates in Hong Kong and processes personal data — that is Cap. 486, not Cap. 653;

•          holds an SFC licence — the Securities and Futures Commission is not a designated authority under Cap. 653;

•          belongs to one of the eight sectors but has received no designation notice;

•          is a service provider to an operator — although a section 18 information demand can be addressed to it, with a fine of up to HK$500,000.

Professional review is warranted in the following situations.

On an M&A transaction involving an asset in one of the eight sectors. The duty to notify a change of operator under section 20 runs for one month and carries a fine of up to HK$5,000,000. Where the deal is structured as a share transfer, it must be established separately whether the operator of the infrastructure changes for the purposes of the Ordinance; the corporate steps in such a transfer, including stamp duty on the share transfer and the significant controllers register, run in parallel and do not substitute for the Cap. 653 notification.

When mapping critical computer systems across a cross-border IT estate. The section 13 test does not track ordinary assumptions about ownership and hosting.

When drafting a security management plan in a sector with no dedicated code of practice. Six of the eight sectors work from the generic code, and applying it to a particular technology environment requires reasoning that will stand up in evidence.

When reconciling Cap. 653 with requirements in other jurisdictions. Singapore’s two hours, Hong Kong’s twelve and Europe’s twenty-four cannot be collapsed into one internal procedure without losing either compliance or workability.

Frequently Asked Questions

When did Hong Kong’s cybersecurity law, Cap. 653, come into force?

The Ordinance came into force on 1 January 2026 by L.N. 144 of 2025, signed by the Secretary for Security on 18 June 2025 and gazetted on 27 June 2025. The Ordinance itself was passed by the Legislative Council on 19 March 2025 and gazetted on 28 March 2025 as Ord. No. 4 of 2025.

Which eight critical infrastructure sectors does the Ordinance list?

Schedule 1 lists: energy; information technology; banking and financial services; air transport; land transport; maritime transport; healthcare services; telecommunications and broadcasting services. The Schedule is headed “Sectors”, and the three transport modes appear as separate items, with air transport before land transport.

How does a company find out whether it has been designated a CI operator?

Only from a written designation notice issued by the regulating authority. The Commissioner’s Office explains: “Organizations designated as CI operators will receive written notice from the regulating authorities, setting out the effective date and the critical computer systems covered.” There is no other route to that knowledge.

Is the list of Hong Kong CI operators published?

No. The Commissioner’s Office states the position directly: “To prevent CIs from becoming targets of attacks, the legislation only sets out the sectors of CIs, instead of disclosing the full list.” At the same time, “The Ordinance does not prohibit individual operators from disclosing their identities” — there is no statutory bar on an operator disclosing its own status.

Is the incident notification deadline 12 hours or 48 hours?

12 hours where the incident has disrupted, is disrupting or is likely to disrupt the core function of the critical infrastructure; 48 hours in all other cases. In addition: 48 hours for the written record of the notification and 14 days for the full written report. These deadlines are set by section 28 and Schedule 6.

What is the maximum fine under the Ordinance?

HK$5,000,000 on indictment. That figure applies to failure to comply with a direction, failure to notify a change of operator, failure to take part in a drill, failure to notify an incident, and an operator’s failure to furnish information. Most other offences carry a maximum of HK$500,000 plus HK$50,000 for each day the contravention continues.

Does the Ordinance provide for imprisonment?

Only under section 58(3), and only for unlawful disclosure of information obtained in the administration of the Ordinance — up to six months summarily and up to two years on indictment, together with a fine of up to HK$1,000,000. No operator obligation is punishable by imprisonment.

Does the Ordinance reach servers hosted outside Hong Kong?

Yes, where the system is accessible to the operator in or from Hong Kong and is essential to the core function of the critical infrastructure. Section 13 applies a test of accessibility and essentiality rather than physical location, and expressly covers systems “whether under the control of the operator or not”.

Does the Mainland critical information infrastructure regime apply in Hong Kong?

No. The PRC Regulations on the Security Protection of Critical Information Infrastructure, promulgated on 27 April 2021 and effective 1 September 2021, together with articles 31 to 39 of the PRC Cybersecurity Law, operate in Mainland China. Hong Kong applies Cap. 653 — two independent regimes with different regulators and different clocks.

Does Cap. 653 regulate personal data?

No. The Ordinance contains no substantive personal data provisions; the phrase “personal data” appears only inside two proper names — the Personal Data (Privacy) Ordinance (Cap. 486) and the Privacy Commissioner for Personal Data. There are two points of contact, both procedural: a disclosure gateway to the Privacy Commissioner (s. 57(3)(a)(viii)) and the saving in section 57(8) for section 13(3) of Cap. 397 and section 44(8) of Cap. 486. Equally, Cap. 653 contains no provision carving personal data out of its scope — the only subject-matter carve-out is legal professional privilege (s. 61).

For a bank, is the regulator the Monetary Authority or the Commissioner?

Both, for different categories of obligation. For categories 1 and 2, the regulating authority for an authorized institution is the Monetary Authority (s. 5, Part 2 of Schedule 2). Category 3 obligations — drills, the emergency response plan and incident notification — are reserved to the Commissioner by section 6, without exception.

Is a code of practice mandatory?

A code is not subsidiary legislation, and failure to observe it creates no liability of itself. Section 8(8) states: “A code of practice is not subsidiary legislation.” But under section 9 a code is admissible in evidence, and compliance with it is taken into account in assessing whether a statutory duty has been discharged. Six codes had been issued as at August 2026.

Can an operator be exempted from Cap. 653 obligations?

Yes, under section 55 — but by obligation rather than by category of data. The Commissioner may by written notice exempt an operator from a category 1, 2 or 3 obligation where satisfied that it is in the public interest, and must consider whether the operator is subject to a substantially corresponding obligation under another Ordinance, code of practice, direction or requirement. A refusal to exempt is not among the decisions appealable under section 48(1).

Which regulatory decisions can be appealed?

Only the five listed in section 48(1): a direction under section 7, a designation under section 12, a designation under section 13, a requirement for an ad hoc risk assessment under section 24(5), and a requirement for an ad hoc audit under section 25(4) or (6). A notice of appeal is lodged with the chairperson of the appeal panel within one month of receiving notice of the decision, and lodging it does not of itself stay the decision.

Key Takeaways

•          Cap. 653 is Hong Kong’s first dedicated cybersecurity statute. The Protection of Critical Infrastructures (Computer Systems) Ordinance, Ord. No. 4 of 2025, was passed on 19 March 2025, gazetted on 28 March 2025 and brought into force on 1 January 2026 by L.N. 144 of 2025.

•          Schedule 1 lists eight sectors: energy; information technology; banking and financial services; air transport; land transport; maritime transport; healthcare services; telecommunications and broadcasting services.

•          Obligations arise from an individual written designation, not from sector membership. The list of operators is not published; the Ordinance does not prohibit an operator from disclosing its own status.

•          The definition of critical infrastructure has a second limb that is not confined to the eight sectors — any other infrastructure whose failure may substantially affect the maintenance of critical societal or economic activities in Hong Kong.

•          There may be two regulators. The Monetary Authority and the Communications Authority take categories 1 and 2 for the organisations listed in Part 2 of Schedule 2; category 3 remains with the Commissioner in every case.

•          Incident notification runs to 12 and 48 hours, the written record to 48 hours and the full report to 14 days. The twelve-hour clock attaches to disruption, or likely disruption, of the core function.

•          The maximum fine is HK$5,000,000 on indictment. Imprisonment appears in a single provision — section 58(3) on unlawful disclosure — and does not touch operator obligations at all.

•          A code of practice is not subsidiary legislation but is admissible in evidence. Six codes have been issued; six of the eight sectors work from the generic code.

•          The Ordinance contains almost no carve-outs by category of information. The words “content”, “Mainland” and “trade secret” do not appear at all, and “personal data” only inside proper names. The single subject-matter carve-out is legal professional privilege (s. 61); the other limits are procedural — a magistrate’s warrant subject to the section 40 exception, the conditions in section 36 and the secrecy duty in section 57.

•          Relief runs by obligation, not by data. Section 55 lets the Commissioner exempt an operator from an obligation of any category, taking into account a substantially corresponding obligation under another regime; a refusal is not appealable.

•          Only five categories of decision are appealable (s. 48(1)), within one month, and lodging an appeal does not stay the decision.

•          Section 65 provides a complete defence where the cause was beyond the defendant’s control and all due diligence was exercised.

•          The regulator’s establishment is 32 staff for eight sectors, which points to supervision through codes of practice, designations and reporting rather than continuous oversight. No enforcement had been published as at August 2026.

Summary 

The Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653, Ord. No. 4 of 2025) is Hong Kong’s first dedicated critical infrastructure cybersecurity statute; it was passed by the Legislative Council on 19 March 2025, gazetted on 28 March 2025 and came into force on 1 January 2026 by L.N. 144 of 2025. Schedule 1 fixes eight sectors: energy; information technology; banking and financial services; air transport; land transport; maritime transport; healthcare services; and telecommunications and broadcasting services. Obligations arise only from an individual written designation of an organisation as a CI operator, and the list of designated operators is not published. The regulator is the Commissioner of Critical Infrastructure (Computer-system Security) — Mr Francis Chan Wing-on, appointed from 1 January 2026 — with an office establishment of 32 staff; for categories 1 and 2, the Hong Kong Monetary Authority and the Communications Authority are the regulating authorities for the organisations listed in Part 2 of Schedule 2, while category 3 obligations are reserved to the Commissioner without exception. The key deadlines are: one month for the office address and notifications; three months for the security management plan and the emergency response plan; twelve months for the first risk assessment; twenty-four months for the first security audit; 12 hours for incident notification where the core function is disrupted and 48 hours otherwise; and 14 days for the full written report. The maximum fine is HK$5,000,000 on indictment, and imprisonment is provided only by section 58(3) for unlawful disclosure of information. The Ordinance contains no substantive personal data provisions; its only subject-matter carve-out is legal professional privilege under section 61, and its other limits are procedural, resting on a magistrate’s warrant (subject to the emergency entry exception in section 40), the conditions in section 36 and the secrecy duty in section 57. Exemption from a particular obligation is available under section 55, five categories of decision are appealable under section 48(1) within one month, and section 65 provides a complete defence where all due diligence was exercised.

Mapping the regulatory perimeter of a Hong Kong structure — from corporate requirements to sectoral supervision — is work better done before a designation notice arrives than after. UPPERSETUP advises on Hong Kong company incorporation and ongoing maintenance, including related matters such as confirming tax residence statusand corporate reporting.

Sources

Primary sources — legislation and subsidiary instruments

•          Protection of Critical Infrastructures (Computer Systems) Ordinance, Cap. 653 — consolidated text on Hong Kong e-Legislation

•          L.N. 144 of 2025 — commencement notice bringing Cap. 653 into operation on 1 January 2026

•          Ordinance No. 4 of 2025 — the Ordinance as enacted

•          Personal Data (Privacy) Ordinance, Cap. 486

•          The Government of the HKSAR Gazette (e-Gazette)

Primary sources — the legislative process

•          Protection of Critical Infrastructures (Computer Systems) Bill, gazetted 6 December 2024

•          Legislative Council Brief, SBCR 1/3231/2022 Pt. 5, 4 December 2024

•          Bills Committee bc56

•          Legislative Council Panel on Security, LC Paper CB(2)773/2025(03), 6 May 2025 — establishment and post costs of the Commissioner’s Office

•          Panel on Security agenda, 6 May 2025

Primary sources — regulators

•          Office of the Commissioner of Critical Infrastructure (Computer-system Security)

•          Legislative intent and principles — the Commissioner’s Office

•          Frequently asked questions — the Commissioner’s Office

•          Codes of practice

•          Forms CICS001 to CICS006

•          Announcements of the Commissioner’s Office

•          Code of Practice for authorized institutions designated by the Monetary Authority

•          Code of Practice for payment system infrastructure operators

•          Code of Practice for stored value facility licensees

•          Hong Kong Monetary Authority regulatory repository — entry for the code of practice for authorized institutions, 2 June 2026

•          Communications Authority — Cap. 653 page

•          Communications Authority — Cap. 653 frequently asked questions

•          Security Bureau of the HKSAR

•          Government announcement of the Commissioner’s appointment

•          Securities and Futures Commission of Hong Kong

•          Privacy Commissioner for Personal Data

Primary sources — comparable jurisdictions and law reform

•          Directive (EU) 2022/2555 (NIS2)

•          Singapore Cybersecurity Act 2018, Act 9 of 2018

•          Cyber Security Agency of Singapore

•          Law Reform Commission of Hong Kong — report “Cyber-Dependent Crimes and Jurisdictional Issues”, 9 January 2026 · full report

Notes on Verification

The whole of Cap. 653, including Schedules 1 to 7, was checked word for word against the consolidated version on Hong Kong e-Legislation (version as at 1 January 2026), obtained in RTF format because the portal is closed to automated access. All seventy-one sections and seven Schedules were read line by line, and every statement about the content of a provision was reconciled with its text. The definitions, deadlines and penalties stated in this article reproduce the statutory text; where a passage is quoted, it is quoted in the language of the original.

How confirmed facts are separated. The dates of passage, gazettal and commencement, the numbering of sections and Schedules, the levels of penalty, the compliance deadlines and the list of sectors are confirmed from primary sources — the Ordinance itself and the commencement notice. The establishment and post costs of the Commissioner’s Office are confirmed from Legislative Council Panel on Security papers. The dates on which the codes of practice were issued are confirmed from the Commissioner’s Office. The position that the Ordinance does not target personal data and business secrets is confirmed from the Commissioner’s Office guidance and the Government’s LegCo Brief, but does not appear in the statutory text — a distinction drawn expressly in the article.

On the absence of enforcement data. As at August 2026, the Commissioner’s Office, the Monetary Authority and the Communications Authority had published no directions, prosecutions or penalties under Cap. 653. Absence of publication is not the same as absence of enforcement; the article records the absence of public information, and nothing more.

On provisions not yet in operation. The Law Draftsman’s information note to Cap. 653 states: “Provisions Not Yet In Operation — Nil. Amendments Not Yet In Operation — Nil.” As at the date of publication the whole Ordinance is in force, with no deferred provisions and no unapplied amendments.

Information current as at August 2026.

Disclaimer

This material is provided for information purposes only and does not constitute legal, tax, financial, investment or consulting advice. Before making any decision, individual professional advice should be obtained, taking into account the specific situation, jurisdiction, status of the company and the current requirements of the relevant regulators.

Published: August 2026.

Read more on the topic

All services on the platform

Everything you need to start and run a business - in one place

  • 2–10 days

    Company Setup

    Hong Kong company with a complete set of incorporation documents


    Start
  • Monthly

    Accounting and Tax Services

    Accounting services in accordance with HKFRS, including monthly reporting.


  • 4–8 weeks

    Visa Services

    Visa services for company owners, employees, and their family members.


  • 7–30 days

    Banking Services

    Corporate Bank Accounts in Hong Kong and Payment Services


  • Custom timeline

    Legal Services

    Tax and Corporate Law Services


  • Custom timeline

    Corporate Services

    Licensed Company Secretary for Corporate Administration