The Law on Cybersecurity was published on the Lao Official Gazette on March 20, 2026, and is now in force. This follows a draft circulated earlier in 2025. The final version is almost identical to the draft.
Cybersecurity as a National Policy Priority
The Law introduces new concepts into the Lao legislative landscape. From critical national information infrastructure to the National Cybersecurity Operations System, and the declaration of a state of cyber emergency, the law affects national institutions and underlines the importance of cybersecurity as a top national priority.
New Obligations for Local Operators
The Law affects local operators with the introduction of an incident reporting obligation that applies to all legal entities and organizations operating in Laos. Should a cyber incident cause damage to an operator, or spread to other sectors, that operator has the obligation to report it. This comes in addition to annual reporting on the implementation of a cybersecurity plan, and mandatory cybersecurity training on a regular basis.
The law also introduces a cybersecurity registration requirement to ensure security and transparency in the protection of data. This requirement applies to certain categories of entities, though the scope is broad and raises interpretative questions that will be examined further below.
What the Law Does Not Do
The law does not set technical standards. While the law requires operators to have effective cybersecurity measures in place, no clear standards of reference are identified (e.g., ISO certification). The law recognizes preventive measures such as risk assessment, access control, encryption, and network security, but leaves the Ministry of Technology and Communications to determine the appropriate details in subsequent regulations.
The sections below provide an overview of the key highlights of the Law.
I. Key terms and Supervising Authority
A. Key Terms
The Law establishes a series of defined terms and expressions (Articles 2-3) which will certainly serve as definitions of reference for future regulations, embedding these into the Lao legislative landscape. Below are some examples.
1. Cybersecurity
The term cybersecurity is defined as follows (Article 2):
Cybersecurity means the protection of information and communication technology systems from cyber attacks or damage arising from cyber threats, including the maintenance of the integrity of systems and networks and the assurance of the availability of such systems for use.
No prior law defined this term, including the Law on Combating and Preventing Computer Crime, which was until now the primary legislative reference for threats and offenses related to computers and cyberspace.
2. “Critical National Information Infrastructure Entities” and “Critical National Information Infrastructure”
The Law also definesCritical National Information Infrastructure Entities (ໜ່ວຍງານໂຄງລ່າງພື້ນຖານ ຂໍ້ມູນ ຂ່າວສານ ທີ່ສໍາຄັນຂອງຊາດ) as follows (Article 3(2)):
Critical Information Infrastructure means a legal entity, organization, or body that owns, operates, or administers systems that are critical to the nation, the disruption or destruction of which would seriously affect the security and socio-economic conditions of the Lao PDR.
A note on the English translation: The law provides an English translation of this term as “Critical Information Infrastructure”, omitting “entity” (ໜ່ວຍງານ) and “national” (ທີ່ສຳຄັນຂອງຊາດ). The Lao original is more precisely translated as “Critical National Information Infrastructure Entity.” Additionally, the term “ໜ່ວຍງານ” (nouay ngaan) is usually translated as “unit”. In the context of this law, and for the purpose of this article, “entity” was preferred as a better fit, because the law refers to actual legal persons and organizations, rather than mere subdivisions of entities.
The Law separately defines “Critical National Information Infrastructure” to designate the actual infrastructure (Article 14):
Critical national information infrastructure means systems, assets, facilities, and networks that are of great importance to the national security, peace, safety, socio-economy, science, technology, and foreign affairs of the Lao PDR, the disruption or destruction of which causes serious direct impact on the nation.
3. Revision of Previous Defined Terms
Interestingly, the Law also revisits the definition of “personal data“, previously defined under the Law on Electronic Data Protection (2018) as “electronic data of individual, legal entity” (Article 3(12)). The Law on Cybersecurity adopts a definition closer to international standards:
Personal data means any data that can be used to identify an individual, whether directly or indirectly.
The Law on Electronic Data Protection was a positive sign of the Lao government’s commitment to electronic data protection, but the definition it used fell short of international standards. The new definition gets closer to these international standards.
B. Supervising Authority: The Ministry of Technology and Communications
The Ministry of Technology and Communications (MTC) is the central authority for coordinating cybersecurity across all administrations and institutions, including the determination of Critical National Information Infrastructure entities, proposing to the Government the declaration of a state of cyber emergency, and acting as the primary interlocutor for the private sector. All reporting obligations and registration requirements are directed to the MTC.
II. Cybersecurity as a Matter of National Policy
A. Critical National Information Infrastructure
The Law recognizes the importance of certain infrastructures, labelled “critical national information infrastructure” (see Key Terms, Section I.A above).
The law does not identify specific infrastructures at this stage. The law does, however, identify the following sectors of critical national information infrastructure (Article 15):
- national defense and public security;
- technology and communications;
- finance and banking;
- energy;
- commerce, transport, and logistics.
This list is not exhaustive. The law includes an “other sectors” category, leaving room for the MTC to add sectors in the future.
Earlier versions of the draft law included more sectors, such as culture and tourism, education and sports, and agriculture and environment, among others. These were removed from the final version, though the list remains open and may be revisited in the future.
1. How Sectors of Critical National Information Infrastructure Are Determined
Several criteria apply when assessing whether a sector qualifies as critical national information infrastructure (Article 16):
- importance to the livelihood of the people;
- national development;
- risk of cyber attack or other disasters;
- impact resulting from the suspension or destruction of service provision.
Compared to the draft, the final version replaced the criterion “importance to the survival and development of the nation” with two separate criteria: “importance to the livelihood of the people” and “national development”.
2. Protection of Critical National Information Infrastructure
The sector classification provides useful insight into what the Lao government considers strategically important. It also raises the question of how these infrastructures are protected. Protection is the responsibility of critical national information infrastructure entities, identified and assessed by the MTC. The MTC is specifically tasked with studying, determining, and reviewing these entities for submission to the Government (Article 68(11)). The law does not yet identify those entities by name.
Specific measures apply to critical national information infrastructure (Articles 17-21): physical protection and access control, oversight of third-party service providers, the establishment of a cybersecurity reporting and notification system, immediate reporting of cyberthreats to the relevant State agencies, coordination with those agencies for infrastructure inspection, and immediate reporting of inspection results and assessments to the Government.
B. National Cybersecurity Operations System
The Law introduces the National Cybersecurity Operations System (ລະບົບປະຕິບັດການຄວາມປອດໄພໄຊເບີແຫ່ງຊາດ) (Articles 22-23). This system is a central pillar of Laos’s cybersecurity policy. Its purpose is to supervise information infrastructures through a system operating 24 hours a day, 7 days a week, to detect emerging threats. Upon detection of a cyber incident, a threat alert is issued. The information collected also feeds into the development of a response.
The law provides that the system relies on modern tools combining expert personnel with “big data analytics technology and artificial intelligence to detect and respond rapidly to threats.” The system is designed to coordinate with both public and private entities.
It is worth noting that Laos already operates LaoCERT, the national Computer Emergency Response Team under the MTC, whose duty is to prevent and manage cybersecurity incidents. No public information is currently available confirming whether the National Cybersecurity Operations System is already operational or is yet to be established. The relationship between LaoCERT and the new system is not addressed in the law.
C. Declaration of a State of Cyber Emergency
1. The Declaration
Upon the occurrence of a serious cyber emergency incident causing a major impact on the socio-economic development of the country, the Government, upon the proposal of the MTC, may declare a state of cyber emergency (ປະກາດພາວະສຸກເສີນທາງໄຊເບີຕ) (Article 33). The declaration requires an incident to have actually occurred. It cannot be made on a preventive basis in anticipation of an incoming threat.
2. Appointment of the Ad Hoc Committee
The appointment of an ad hoc committee, comprising representatives from ministries, organizations, and “relevant sectors”, is triggered by the same conditions as the declaration of a state of cyber emergency (Article 34): the occurrence of a “serious cyber emergency incident that causes a major impact on the socio-economic development of the nation.” The appointment is mandatory once those conditions are met. However, the law does not explicitly link the two mechanisms. It does not state that the appointment of the committee follows automatically from a declaration of state of cyber emergency. From a plain reading of the law, both are triggered by the same factual conditions but could operate independently, though further clarification from the authorities on this point would be welcome.
III. Impact on Local Operators
A. Obligations for Existing Operators
1. Cybersecurity Registration
The Law introduces a “cybersecurity registration” requirement to ensure “security and transparency” (Article 59). The law provides that this requirement applies to “individuals, legal entities, and organizations that provide services, distribute, supply, and disseminate information through the internet system in the Lao PDR,” before identifying two categories of targets (Article 60):
- Individuals or entities providing “services, distributing, supplying, and disseminating information through the internet system on a non-profit basis.” The law mentions database services and cybersecurity system services as illustrative examples; and
- Service providers in cybersecurity-related services, including website hosting services, digital payment system services, and telecommunications services. These are assumed to be commercial providers, though the law includes no explicit profit qualifier.
Registration requires submission of the following information: name and address of the entity or individual, contact details of the person responsible for cybersecurity, and information on the type of service, data storage, and data processing.
Some Observations on the Targets
- For target (1), the examples provided create confusion rather than clarity. “Entities that provide services, distribute, supply, and disseminate information through the internet system on a non-profit basis” is a broad description that could cover almost any website or online platform. However, the examples given, namely database services and cybersecurity system services, are highly technical and infrastructure-level. They sit uncomfortably with both the non-profit qualifier and the broad opening phrase, creating a mismatch that makes the actual scope of the obligation difficult to determine.
- The law appears not to catch commercial entities providing general internet-based services that do not fall under target (2).
- For greater clarity, the law should include a profit qualifier for target (2) if the intention was to target commercial activities.
These ambiguities may be clarified later in subsequent regulations or announcements from the administration.
2. Cybersecurity Training
The law imposes an obligation to raise cybersecurity awareness (Article 47) and conduct cybersecurity training on a regular basis, covering basic cybersecurity understanding, skills to identify and respond to cyber incidents, and updates on emerging threats and technologies (Article 48).
This obligation applies to all entities, including the MTC itself and its relevant departments at provincial, district, and city level.
3. Reporting Requirements
Incident Reporting
All legal entities and organizations must immediately report any cybersecurity incident, including ransomware, malware, and DDoS attacks, to the relevant cybersecurity authority upon discovery, with sufficient information to assess the impact and respond in a timely manner (Article 40).
Information Exchange
The law requires information on cyberthreats and vulnerabilities to flow both ways: from the critical national information infrastructure sector cybersecurity authority to relevant legal entities and organizations, and from all legal entities and organizations to the MTC (Article 41).
Annual Reporting
All legal entities and organizations must submit an annual cybersecurity report to the MTC every January, covering implemented measures, incidents and responses, plan progress, discovered vulnerabilities, training activities, and plans for the following year. The MTC must then compile and report the results to the Government within thirty days (Article 44).
4. System Recovery Measures
All legal entities and organizations must establish procedures to handle cyber emergency incidents, back up data in cloud systems and/or hardware across multiple locations, and report to the ad hoc committee and the MTC (Articles 36-38).
Note on a drafting inconsistency: Article 37 requires reporting to the ad hoc committee for any emergency incident. However, as noted under Articles 33-34, the ad hoc committee is only appointed in cases of serious cyber emergency incidents causing major socio-economic impact (See Part II.C, section 2 above). For lower-level incidents, the committee may simply not exist. Clarification from the MTC on this point would be welcome. Regardless, the reporting obligation to the MTC itself remains.
B. Market Entry: Cybersecurity Business Licensing
The law introduces a dedicated licensing regime for cybersecurity businesses (Articles 49-54), covering a broad range of activities including consultancy, penetration testing, incident response, surveillance, and cloud security services.
Any entity wishing to operate in this space must first register with the industry and commerce sector, then apply for a separate license from the MTC. Key eligibility conditions include a permanent office in the Lao PDR, qualified technical personnel with a higher education degree in information and communication technology or a related field, a manager with at least two years of experience in information and communication technology, a stable financial position, and a clean criminal record. The MTC has fifteen days to process a new application and ten days to process a renewal.
Licenses are valid for one year, are renewable, and cannot be transferred or assigned to third parties. Further details on each business category are left to subsequent regulations.
Conclusion
The law marks a significant step in Lao legislation, raising cybersecurity to a top policy priority at the national level. The law provides a general framework introducing new concepts, while offering legislative tools for the Lao government to prevent, address, and respond to cyberthreats. The law also introduces new requirements for operators, as well as the key conditions for entities wishing to enter the Lao cybersecurity services market.
The law is not exhaustive by design. The current drafting anticipates that subsequent regulations will build on and provide further detail on several of the measures it introduces. The law also remains silent on the security standards that entities operating in Laos must meet, which will likely be addressed in those subsequent regulations. On sanctions, the law provides that violations may result in warnings, fines, civil liability, or criminal penalties (Article 76), but does not tie specific consequences to specific obligations. The details of the sanctions regime are likewise left to subsequent regulations.
Several open questions remain. The operational status of the National Cybersecurity Operations System, and its relationship with the existing Computer Emergency Response Team, are not addressed in the law and will be worth monitoring as implementation progresses. Similarly, the scope of the cybersecurity registration requirement and the identity of critical national information infrastructure entities will depend on clarifications from the MTC. These are areas where operators would benefit from early engagement with the authorities.
Disclaimer
This article is for general informational purposes only and does not constitute legal advice. For legal assistance or advice regarding law matters in Laos, readers must contact a qualified Lao lawyer.
Translation Note
This article is based on an independent reading of the official Lao text. This is not an official translation. While every effort has been made to ensure accurate and contextually appropriate terminology, some terms may be subject to refinement as legal usage and official interpretations evolve. If readers have a more accurate translation supported by reliable sources, comments are welcome, either in discussion or by private message.




