Servicios de Compliance Legal en Ciberseguridad - Anguita Osorio
Implementación de Marcos de Ciberseguridad, Auditorías e Investigaciones
General Framework Analysis of the Cybersecurity Law N° 21.663
Law N° 21.663, in force since 1 January 2025, changes how cybersecurity is governed in Chile. Boards now bear a non-delegable duty to define risk appetite and oversee the management system, while the ANCI has been granted supervisory and sanctioning authority comparable to that of the CMF or the SMA. This analysis addresses what that shift means for senior management and for the compliance programs already in place.
Last updated:
This page brings together the essentials of Law 21.663 for companies: the new regulatory landscape and the institutional architecture led by the ANCI, the entities subject to the law and their obligations, the implementation status and the pending regulation, and the concurrence with sector regulators. At the close are the frequently asked questions and the official sources.
The New Cybersecurity Regulatory Scenario
Law N° 21.663 is Chile's Framework Law on Cybersecurity and Critical Information Infrastructure, published on April 8, 2024. Together with the creation of the National Cybersecurity Agency (ANCI), it reorganizes Chilean cybersecurity regulation along lines the market had not seen before: a sectoral authority with direct enforcement powers, mandatory incident reporting to a central body, and tiered obligations that distinguish ordinary Essential Services (ES) from Operators of Vital Importance (OVI). The first OVI qualification procedure opened in May 2025, and its outcome will determine which organizations operate under the heavier compliance regime.
Regulatory Framework in Development
The implementation of the law is articulated through supreme decrees and ANCI resolutions:
- Supreme Decree N° 285/2024: Regulation of the OVI qualification procedure
- Supreme Decree N° 295/2024: Regulation of cybersecurity incident reports
- ANCI Resolution N° 024/2025: Initiates first OVI qualification procedure (May 2025)
- ANCI Resolution N° 7/2025: Official taxonomy of cybersecurity incidents
- General Instruction N° 1: Registration of ES in reporting platform
Designation and Registration Obligations
ES must designate a Reporting Officer responsible for registration on the ANCI platform and incident notification. OVI, additionally, require a Cybersecurity Officer with technical coordination functions. All entities must register on the official incident reporting platform according to General Instruction N°1 ANCI.
That institutional framework then defines which organizations fall under the law.
Entities Subject to Law 21.663
According to Article 2° of the law, Essential Services (ES) are those provided by:
Public Agencies
- State Administration agencies
- National Electric Coordinator
- Providers under public service concession
Private Institutions in Specific Activities
- Energy: Generation, transmission or electrical distribution
- Fuels: Transportation, storage or fuel distribution
- Water: Drinking water supply or sanitation
- Telecommunications
- Digital infrastructure
- Digital and IT services: Managed by third parties
- Transport: Land, air, rail or maritime, as well as infrastructure operation
- Financial: Banking, financial services and payment methods
- Social security: Benefit administration
- Postal: Postal and courier services
- Health: Institutional provision by hospitals, clinics, medical centers
- Pharmaceutical: Production and/or research of pharmaceutical products
Other Services
ANCI may qualify other services as essential through reasoned resolution when their disruption could cause serious harm to:
- Life or physical integrity of the population
- Population supply
- Relevant sectors of economic activities
- Environment
- Normal functioning of society and/or State Administration
- National defense
- Security and public order
Operators of Vital Importance (OVI)
Subset of ES with greater national criticality. ANCI will identify through exempt resolution the specific infrastructures, processes or functions that will be qualified as OVI, subject to additional obligations under Article 8°.
Oversight of those entities rests with the authority described next.
National Cybersecurity Agency (ANCI)
The ANCI was established by Law 21.663 as the sectoral authority for cybersecurity in Chile. Unlike the advisory bodies that preceded it, it is not consultative in nature: it issues binding regulations, supervises Essential Services and Operators of Vital Importance, and can impose fines of up to 40,000 UTM for serious infractions.
Powers and main functions
- Issuing binding technical regulations on cybersecurity duties (the first ANCI Resolution N° 024/2025 has already been published).
- Supervising Essential Services and Operators of Vital Importance, with powers of inspection, information requests, and audits.
- Conducting sanctioning procedures and imposing fines for infractions of Law 21.663 and its regulations.
- Coordinating the National CSIRT and acting as the central point for cybersecurity incident reporting.
- Representing Chile before international cybersecurity organizations.
Registration and reporting to the ANCI
Essential Services must register on the ANCI platform under General Instruction N° 1 and designate a Reporting Officer. Critical incidents must be notified to the National CSIRT within the first three hours of detection. This reporting duty coexists with —and does not replace— sectoral obligations before the CMF, the SEC, and other authorities.
With the authority defined, the concrete duties the law imposes come next.
Fundamental Obligations for Regulated Entities
The law defines a set of permanent duties that form the basis of compliance, which are intensified for organizations qualified as OVI.
General Duties (Applicable to ES and OVI)
- Continuous Risk Management: Implement and maintain technical and organizational measures to manage risks affecting network and system security.
- Response Capabilities: Develop necessary capabilities to prevent, detect, manage and respond to cybersecurity incidents.
- Mandatory Incident Reporting: Notify the National CSIRT of significant incidents within strict deadlines (initial alert in less than 3 hours, detailed report in 72 hours, final report in 30 days).
Specific Duties for Operators of Vital Importance (OVI)
The most critical organizations for the country must, additionally:
- Implement an Information Security Management System (ISMS).
- Develop and certify Operational Continuity and Cybersecurity Plans.
- Conduct periodic audits, evaluations and drills.
- Designate a Cybersecurity Delegate.
Those duties roll out at a pace set by the law's implementation status.
Current Implementation Status
Law 21.663 is in active implementation process with specific deadlines for different obligations:
OVI Qualification Process Underway
Through Exempt Resolution N° 024 of May 2025, ANCI initiated the first qualification procedure for Operators of Vital Importance. This process:
- Is governed by Supreme Decree N° 285/2024
- Has a 90-day deadline from entry into force
- Must be reviewed every 3 years according to Article 6° of the law
- Determines which ES remain subject to additional obligations under Article 8°
Official Incident Taxonomy
ANCI Resolution N° 7/2025 established the official taxonomy with four alert categories:
- Forgery alerts: Sites impersonating others
- Incident alerts: Vulnerabilities under active exploitation
- Compromise indicators: Malware, phishing, vishing, smishing
- Vulnerability alerts: Software and application flaws
Operational Platforms
ANCI systems are operational through:
- National CSIRT: csirt.gob.cl
- Institutional ANCI: anci.gob.cl
- Registration platform: For registration according to General Instruction N° 1
Much of that implementation also depends on the law's regulation.
Regulations to Law 21.663 (Reglamento)
The Regulations to Law 21.663 are currently in process. Once published in the Diario Oficial, this section will incorporate the technical analysis of its provisions, the adaptation deadlines for Essential Services and Operators of Vital Importance, and the interactions with Supreme Decrees N° 285/2024 and N° 295/2024.
Status: Pending official publication
Anguita Osorio updates this analysis within 48 hours of official publication.
The law's reach is best seen sector by sector.
Sectoral Analysis: Regulatory Concurrence
Law 21.663 operates as a general framework, but its greatest complexity arises in sectors that already have their own cybersecurity regulation, creating regulatory concurrence scenarios.
Financial Sector
The main challenge is the coexistence of CMF and ANCI. Entities must harmonize compliance with regulations such as RAN 20-10 with the new duties of Law 21.663.
Energy Sector
Electric companies must navigate a framework with up to four regulators (SEC, CNE, CEN, ANCI), protecting critical OT/IT infrastructure under multiple standards.
Corporate Compliance
For all companies, cybersecurity is linked to Law 21.595 on computer crimes, making it imperative to integrate these risks into the Crime Prevention Model.
National Cybersecurity Policy
Sets strategic pillars, governance, and coordination with the ANCI, framing obligations for critical infrastructure and incident reporting under Law 21,663.
Artificial intelligence implications for corporate cybersecurity →
With that sector map in view, the working frameworks are best organized by entity type.
Implementation Frameworks
Law 21.663 establishes functional obligations without prescribing specific technical frameworks. Applicable standards will be defined by sectoral regulation:
Essential Services (ES)
- Risk management: Technical and organizational measures (frameworks like NIST CSF can serve as reference).
- ANCI Registration: Mandatory registration according to General Instruction N°1.
- Reporting Officer: Designation for coordination with ANCI.
Operators of Vital Importance (OVI)
- ISMS: Information security management system (ISO 27001 is example of recognized standard).
- Certified plans: Operational continuity and cybersecurity with independent evaluation.
- Cybersecurity Officer: Technical functions according to pending regulation.
- Periodic evaluations: Audits and drills according to methodology to be defined.
Frequently Asked Questions about Law 21.663
Summary of the most common inquiries about Chile's Cybersecurity Law.
What is Law 21.663?
Law 21.663 is Chile's Framework Law on Cybersecurity and Critical Information Infrastructure, published on April 8, 2024. It establishes the institutional cybersecurity framework, sets duties for Essential Services and Operators of Vital Importance, and creates the National Cybersecurity Agency (ANCI).
Who does Law 21.663 apply to?
The law applies to Essential Services in the financial, telecommunications, energy, health and other strategic sectors. It also applies to Operators of Vital Importance qualified as such by ANCI through reasoned resolution, and subsidiarily to public-sector bodies.
What obligations does Law 21.663 impose?
The law requires implementation of an information security management system, reporting of incidents to ANCI within set deadlines, designation of a Cybersecurity Delegate, and adoption of minimum operational continuity and resilience measures.
What sanctions apply for non-compliance?
ANCI imposes fines that scale from minor infractions (up to 5,000 UTM) to very serious infractions (up to 40,000 UTM), following an administrative procedure. Repeated or particularly serious infringements may lead to temporary closure of the service.
How does Law 21.663 interact with CMF regulation?
Financial services under CMF supervision (RAN 20-10, NCG 454, NCG 502) must harmonize sectoral compliance with ANCI requirements. Coordination between the two regulators avoids duplicated reporting and ensures a coherent risk-management framework.
What deadlines does Supreme Decree N° 285/2024 set for VIO qualification?
DS N° 285/2024 establishes a ninety-day period from entry into force to begin the qualification of Operators of Vital Importance. The qualification is reviewed every three years under article 6 of Law 21.663, and determines which Essential Services become subject to the additional obligations of article 8.
Within what timeframe must a cybersecurity incident be reported to ANCI?
Essential Services and Operators of Vital Importance must notify critical incidents to the National CSIRT within the first three hours of detection. Reporting is filed via the ANCI platform under General Instruction N° 1, and coexists with sectoral obligations before the CMF, the SEC and other authorities.
Official sources
Related services
Explore complementary practice areas and regulatory analysis from our team.
Vital Importance Operators
OIV qualification: criteria, reinforced obligations and challenge routes.
OIV list
Who was qualified as OIV and what being on the list entails.
Does it apply without being an OIV?
Essential services owe duties even without OIV status (Articles 7 and 9).
National Cybersecurity Policy
The 2023-2028 policy pillars and their relation to Law 21.663.
Cybersecurity: financial sector
How Law 21.663 coexists with CMF regulation for supervised entities.
Cybersecurity: energy sector
Cybersecurity obligations for energy infrastructure.
Cybersecurity: corporate sector
The company’s criminal and organizational exposure to cyber incidents.
Cybersecurity practice
Regulatory cybersecurity counsel and incident response support.
Law 21.719 Data Protection
The framework enforceable from December 1, 2026: principles, rights, duties and sanctions.
RAN 20-10: banking cybersecurity
Information security and cybersecurity management for banks.
Transform Your Legal Challenges into Competitive Advantages
Discover how our innovative approach can drive your business