Hong Kong: Actions to take under critical infrastructure cybersecurity regime
Designated operators face immediate compliance deadlines
August 13, 2026
Hong Kong: Actions to take under critical infrastructure cybersecurity regimeDesignated operators face immediate compliance deadlinesAugust 13, 2026 Why should I read this?Hong Kong’s Protection of Critical Infrastructures (Computer Systems) Ordinance came into effect on January 1, 2026. It is designed to protect critical infrastructure from cyber threats that could disrupt essential services, including power, banking, telecoms, healthcare and transport. The regime is now operational. A new Commissioner of Critical Infrastructure (Computer-system Security) has been appointed, codes of practice have been issued across several sectors and the process of designating critical infrastructure operators (CIOs) is underway. Businesses in the covered sectors should act now. Even if an organization has not yet been formally designated, pre-designation inquiries have begun. Once designated, CIOs face strict compliance deadlines, including for cybersecurity plans, risk assessments, audits and incident reporting. Who does it apply to?The Ordinance applies to CIOs. These are organizations that run infrastructure that Hong Kong relies on for essential services. The regime covers sectors such as energy, IT, banking and financial services, air transport, land transport, maritime transport, healthcare services, and telecommunications and broadcasting. Infrastructure may also fall within the regime if a computer system failure could substantially affect Hong Kong’s critical societal or economic activities. This could include, for example, major sports and performance venues or research and development parks. The list of designated CIOs and critical computer systems will not be made public. Designations are being made in phases from mid-2026 and the focus is mainly on privately operated infrastructure. Government-run infrastructure and non-designated entities are outside scope. Once designated, CIOs must comply with three categories of obligations:
Failure to comply can lead to significant fines. Penalties apply to the organization, not to individuals. What guidance has been issued?Codes of practice have been issued to guide operators on compliance. These include practical guidance, standards and specifications. Although the codes are not legally binding, failure to follow them may still have consequences. The Commissioner may issue written directions by reference to the codes and failure to comply with those directions is an offence. Codes have already been issued for all sectors generally, as well as for energy, banking and financial services, payment system infrastructure operators, stored value facility licensees and land transport. The Communications Authority has adopted the generic code for telecoms and broadcasting. An Appeal Panel has also been established. It gives CIOs a route to appeal a designation or written direction. Actions for boardsBoards of designated CIOs (or those likely to be designated) should prepare for the following:
What comes next?Expect the following developments:
Instead of waiting for formal designation, businesses in the covered sectors should begin preparing now so they are ready when the deadlines begin to apply. Latest InsightsLatest News
Latest Events
legal updates August 13, 2026 Hong Kong: Actions to take under critical infrastructure cybersecurity regi... legal updates August 11, 2026 Global Sustainability & ESG Insights - July 2026 legal updates August 11, 2026 EU Packaging and Packaging Waste Regulation guides and reports August 11, 2026 EU: Packaging and Packaging Waste Regulation Compliance Guide client news August 13, 2026 Eversheds Sutherland advises H.I.G. Capital on investment in Phoenix ME client news August 13, 2026 Eversheds Sutherland reappointed to Government Commercial Agency legal serv... firm news August 12, 2026 William A. Nelson, Former Investment Adviser Association Policy Leader, Joi... client news July 30, 2026 Eversheds Sutherland Advises Johnson Matthey on Acquisition of CORMETECH In... virtual UAE - Employment law in the Dubai International Financial Centre September 10, 2026 9.30am - 1.30pm (GMT) Virtual in-person Managing AI use in the workplace: what every UK HR team needs to know September 10, 2026 9.30am - 1.00pm (BST) London, United Kingdom in-person Basic foundations of US employment law September 17, 2026 9.30am - 4.30pm (GMT) London, United Kingdom in-person 2026 BDC Roundtable September 23, 2026 Washington DC, United States |