Ali Zuweid's Political Programme
Proposed draft law · Digital State, Data, Artificial Intelligence and Cybersecurity
Cybersecurity and Critical Information Infrastructure Protection Law
A national legislative framework elevating digital and critical infrastructure protection from instructions and policies to risk-based legal obligations, unifying governance, reporting and response while protecting privacy and communications confidentiality.
Executive summary
Iraq's institutional structure is now more advanced than several years ago: the Cybersecurity Strategy 2022–2025 was adopted, and Prime Minister's Office Formations and Functions Instructions No. (1) of 2025 organised the National Cybersecurity Centre, assigning policies and standards, compliance assessment, risk management, early warning, incident response and critical digital infrastructure protection. These essential functions nevertheless remain distributed among an expired strategy, administrative instructions and technical standards, without a national framework law precisely defining regulated entities, duties, oversight, safeguards, sanctions and appeals.
The proposal creates no parallel authority. It gives statutory recognition to the existing National Cybersecurity Centre in the Prime Minister's Office as the competent national body and establishes risk-based designation of critical information infrastructure and classification of essential and important entities. Entities must implement governance, asset, vulnerability and supply-chain management, identity, encryption, logging, backup and recovery controls, and specific operational technology and cloud requirements, with independent assessment and periodic exercises and tests.
The Law also establishes staged incident reporting, immediately for critical incidents and within four hours for high-severity incidents, followed by updates and final reports, and proportionate corrective and enforcement powers. Conversely, it separates cybersecurity from content surveillance: it does not permit general interception, weakening encryption or regulating opinion and speech, and confirms that private communications interception requires law and constitutional judicial safeguards.
First — Constitutional and legal context
The proposal rests on the State's duty to protect national security and continuity of facilities and services, and constitutional rights and freedoms. Article (40) directly guarantees communications and correspondence freedom, including electronic communications, prohibiting monitoring, interception or disclosure except for legal and security necessity and by judicial decision. Cybersecurity law therefore cannot rest on vague content-interception or general-surveillance powers.
The Ministerial Council for National Security adopted the Cybersecurity Strategy 2022–2025 in February 2022. On 10 November 2025, Iraqi Official Gazette issue (4847) published Prime Minister's Office Formations and Functions Instructions No. (1) of 2025. These gave the Centre broad functions: proposing strategy, policies and standards; assessing system and digital-service security and compliance; maintaining a national risk and threat register; critical infrastructure protection plans; early warning; major incident response; technical analysis; training; and international cooperation.
This structure matters but rests on administrative instructions insufficient alone to impose extensive private-sector duties, fines, inspection and audit rules or statutory limits on executive power. The International Telecommunication Union's Global Cybersecurity Index 2024 placed Iraq in the T4: Evolving category, with relative strength in organisational measures and remaining development needs in legal and technical measures, capacity building and cooperation. A national framework law addresses precisely this gap.
Second — Legislative gap
The problem is not absent government cybersecurity activity but a missing unified legal layer. A national body, incident standards and some response mechanisms exist, yet no law conclusively defines critical entities, mandatory reporting, minimum supplier, cloud and operational technology risk controls, classification appeals, emergency orders or limits on technical data collection preventing security monitoring from becoming content surveillance.
Expanding digital government, payments, communications, data centres and industrial systems make cyberattacks capable of physical, economic and service disruption, beyond lost files. Focus must therefore shift from device security to institutional resilience: governance, inventories, interdependencies, continuity, recovery, supply chains, exercises and leadership accountability.
Third — Proposed legislative policy
| Issue | Legislative choice | Purpose |
|---|---|---|
| National body | Use the existing National Cybersecurity Centre with statutory powers | Avoid a parallel authority and improve legal stability |
| Obligation scope | Risk-based essential and important entity classification | Focus oversight on actual impact |
| Standards | A national baseline with stricter sectoral requirements where needed | Prevent fragmentation while respecting sector differences |
| Incidents | Staged reporting according to severity | Prompt reporting without waiting for full investigation |
| Rights | Prohibit general content surveillance and universal backdoors | Protect privacy and communications confidentiality |
| Enforcement | Notice and remediation followed by graduated, appealable orders and fines | Effective, proportionate enforcement subject to judicial review |
| Transition | Continue current instructions and standards pending alignment | Avoid gaps in national response |
Fourth — Draft law text
In the name of the people
Presidency of the Republic
Pursuant to enactment by the Council of Representatives and ratification by the President under item (First) of Article (61) and item (Third) of Article (73) of the Constitution, the following Law is issued:
Law No. ( ) of 2026
Cybersecurity and Critical Information Infrastructure Protection Law
Chapter One — General provisions
Article (1) — Definitions
For this Law, the following expressions have the meanings assigned:
First — Centre: The National Cybersecurity Centre in the Prime Minister's Office.
Second — Cybersecurity: Protection of networks, systems, software, data and digital services against incidents and acts compromising confidentiality, integrity, availability, authenticity or continuity.
Third — Critical information infrastructure: Any system, network, platform or digital or operational facility relying on information, communications or control technology whose disruption, compromise or destruction seriously affects national security, public safety, the economy, health, environment or essential-service continuity.
Fourth — Regulated entity: A public body or private-sector legal person subject to this Law or classified under it.
Fifth — Essential entity: An entity on which an essential service or critical infrastructure depends, whose disruption causes serious national or sectoral effects.
Sixth — Important entity: An entity providing a highly important service or an essential dependency for an essential entity or vital sector, without reaching essential-entity status.
Seventh — Cyber incident: An event actually or reasonably likely to affect network, system, service or data security.
Eighth — Major incident: An incident causing or potentially causing significant interruption, widespread loss, compromise of sovereign or sensitive data, multi-entity or multi-sector impact, or danger to national security or public safety.
Ninth — Response team: A national, sectoral or institutional cyber incident response team.
Tenth — Cyber risk: The likelihood of cyber-incident loss or harm combined with its impact.
Eleventh — Managed services: Third-party technical or security services operating, managing or monitoring systems, networks or security functions.
Twelfth — Digital supply chain: Persons, products, services, software, components and processes supporting digital system or service operation.
Thirteenth — Operational technology systems: Industrial control, measurement, supervisory control and other digital systems managing physical or industrial processes.
Fourteenth — Vulnerability: A weakness or flaw exploitable to compromise system, network or service security.
Fifteenth — Technical threat indicators: Technical data on malicious or suspicious activity, such as digital fingerprints, connection addresses and behaviour patterns, limited to detection, prevention or response needs.
Sixteenth — Sectoral regulator: A body legally authorised to regulate a relevant economic or service sector.
Article (2) — Objectives
This Law aims to:
First — Improve national cyber resilience and security through risk management.
Second — Protect critical information infrastructure and essential-service continuity.
Third — Define national and sectoral powers and prevent regulatory duplication.
Fourth — Impose measurable, enforceable governance and risk-management requirements on essential and important entities.
Fifth — Unify incident reporting, response and technical information sharing.
Sixth — Strengthen supply-chain, cloud, managed-service and operational technology security.
Seventh — Protect privacy, communications confidentiality, expression and other constitutional rights in cybersecurity measures.
Eighth — Develop national capacity, personnel, research and international cooperation.
Article (3) — Scope
First — This Law applies to ministries, bodies not affiliated with ministries, independent authorities, governorates, public bodies and companies, and private essential and important entities operating or providing services in Iraq or whose digital infrastructure is substantially directed at services within Iraq.
Second — National provisions concerning security, cross-sector response and nationally connected infrastructure shall respect constitutional powers among federal authorities, Kurdistan Region and governorates not incorporated into a region. Centre–regional coordination and operating arrangements shall prevent response or protection gaps in nationally connected infrastructure.
Third — Defence, security and intelligence systems shall follow protection, risk-management and response requirements compatible with classification. Special instructions shall govern audit and information exchange without compromising operational secrets or command structures.
Fourth — Constitutional authorities and constitutionally independent bodies shall comply with national protection requirements while retaining independence. Their oversight or technical units shall verify compliance through Centre coordination arrangements granting no access to deliberations, files or content protected by institutional independence or judicial or legislative confidentiality.
Article (4) — Governing principles
Covered bodies shall observe lawfulness, risk management, proportionality, security by design, resilience and continuity, least privilege, data minimisation, technological neutrality, accountability, separation of regulation and operation where needed, and proportionate requirements for small enterprises.
Article (5) — Sectoral legislation
First — More protective sectoral cybersecurity provisions apply unless inconsistent with this Law. The Centre and sectoral regulators shall establish a unified national baseline; regulators may add requirements justified by sector risks.
Second — This Law shall not abolish statutory Central Bank, Communications and Media Commission or other regulatory and oversight powers. Coordination shall prevent duplicate requests, audits and sanctions for the same event.
Article (6) — Rights and freedoms
First — All powers shall respect constitutional rights and freedoms, particularly privacy, communications confidentiality, opinion, expression, press, publication and due process.
Second — Cybersecurity alone does not justify communications-content monitoring, general speech surveillance or compelled disclosure of private content. Interception, tapping or disclosure remains subject to constitutional and statutory legal and judicial safeguards.
Article (7) — Risk-based approach
Requirements, oversight and priorities shall reflect incident likelihood and impact, service and data nature, interdependencies, current threats and recovery capacity. Formal equality among entities shall not replace actual risk assessment.
Article (8) — Senior management responsibility
Boards or senior officials shall approve and review cyber risk frameworks, provide appropriate resources and oversee material incidents and remediation. Ultimate supervisory accountability shall not be delegated to external providers or contractors.
Chapter Two — National governance and powers
Article (9) — National Cybersecurity Centre
First — The existing Centre in the Prime Minister's Office continues as the national body coordinating cybersecurity policy, critical information infrastructure protection and statutory functions, without a parallel authority.
Second — The Centre exercises technical functions with professional independence. Regulatory decisions and sanctions are subject to statutory grievances and appeals.
Article (10) — Centre functions
In coordination with relevant bodies, the Centre shall:
First — Prepare, update and monitor the national cybersecurity strategy.
Second — Issue national policies, standards, baselines and binding technical controls within this Law.
Third — Manage the national cyber risk and threat register and periodic assessments.
Fourth — Identify critical information infrastructure and classify regulated entities.
Fifth — Operate early warning and coordinate major-incident response nationally.
Sixth — Monitor compliance by public, essential and important entities and conduct or commission qualified audits.
Seventh — Coordinate national, sectoral and institutional response teams.
Eighth — Organise exchange of threat indicators and reliable technical information.
Ninth — Approve national assessment, testing and exercise frameworks.
Tenth — Develop capacity, training, awareness, research and innovation.
Eleventh — Represent Iraq in technical international cybersecurity cooperation with Foreign Affairs and competent bodies.
Twelfth — Propose regulations, instructions and legislation developing the national system.
Article (11) — National strategy
First — The Centre shall prepare a strategy for no more than five years for Council of Ministers approval, with measurable goals and indicators, responsibilities, critical infrastructure priorities, capacity, supply chains, crisis management and international cooperation.
Second — Strategy shall be reviewed annually and may be updated early after material changes in risks or technical or security conditions.
Article (12) — National coordination committee
First — The Prime Minister shall form a standing committee chaired by the Centre's head, with appropriately senior representatives of security, defence, finance, communications, energy, transport, health, water, digital transformation and sectoral regulators. Private representatives and experts may advise.
Second — The committee has no separate legal personality. It resolves operational conflicts and coordinates cross-sector plans, exercises and priorities without replacing statutory powers.
Article (13) — National incident response team
The Centre shall organise a national team as the major-incident contact point, receiving reports and providing technical coordination, warning, analysis, assistance and sectoral and international liaison. It has no criminal investigation powers beyond those established by separate law.
Article (14) — Sectoral and institutional teams
The Centre and sectoral bodies shall require vital sectors and major public entities to establish qualified response teams or equivalent contracted services, ensuring availability and independent technical decisions in emergencies. National standards shall set minimum qualifications, coverage hours and escalation procedures.
Article (15) — Sectoral regulators
Regulators shall integrate the national baseline into licensing, instructions and oversight, share relevant audits and incidents with the Centre under confidentiality rules, and participate in classification and sectoral prioritisation.
Article (16) — Information-sharing network
The Centre shall establish a trusted national network sharing threat indicators, alerts and lessons among competent bodies and regulated entities, limited to necessary information, with classification and protection of sources, personal data and trade secrets.
Article (17) — Annual national report
First — The Centre shall publish annual cybersecurity reports on principal trends, incident types, compliance and strategy implementation, without disclosing exploitable vulnerabilities, security or trade secrets or personal data.
Second — A detailed classified version shall go to the Prime Minister and competent oversight bodies. The relevant parliamentary committee may receive confidential briefings under applicable rules.
Article (18) — National standards
First — National standards shall align appropriately with recognised international standards, focus on outcomes and risks and restrict specific technologies only where necessary for security or interoperability.
Second — Recognised international or sectoral standards may provide partial compliance evidence but do not exempt legal requirements or environment-specific risks.
Article (19) — International cooperation
With Foreign Affairs and competent bodies, the Centre may conclude non-binding international technical arrangements, exchange warnings and indicators and assist response, respecting reciprocity, information protection, sovereignty and Iraqi law. Treaties and international agreements remain subject to constitutional and legal procedures.
Chapter Three — Critical infrastructure and entity classification
Article (20) — Priority sectors
Priority sectors include government and digital public services; defence, security and emergencies; energy, oil, gas and electricity; water and sanitation; communications and digital services; banking, payments and financial markets; transport, airports, ports and railways; health; nationally significant food and logistics; data centres, cloud computing and domain-name services; and other sectors designated under Article (21).
Article (21) — Critical infrastructure criteria
Designation shall consider:
First — Numbers of people or entities affected by disruption.
Second — Dependencies of other sectors or services.
Third — Expected national security, public safety, economic, health or environmental impact.
Fourth — Tolerable downtime and service alternatives.
Fifth — Data sensitivity and associated sovereign functions.
Sixth — Geographic, inter-governorate or cross-border dimensions.
Seventh — Potential physical consequences for facilities or people.
Eighth — Market concentration or absence of practical supplier or service alternatives.
Article (22) — Classification decisions
First — After consulting regulators and entities, the Centre shall issue reasoned essential or important classifications, notifying entities of duties, deadlines and competent oversight bodies.
Second — Urgent national risks may justify temporary classification for up to ninety days. Assessment and entity comments shall be completed before extension or permanent classification.
Article (23) — Essential and important entities
First — Essential status applies where interruption or compromise can seriously affect national or sectoral operations, human safety or multiple critical infrastructures.
Second — Important status applies to high-impact entities or suppliers not rapidly replaceable for an essential entity.
Third — Instructions shall set additional quantitative and qualitative sector criteria, considering size and dependency-chain position. Small enterprises shall not bear essential-entity duties unless their service nature or uniqueness justifies them.
Article (24) — National critical infrastructure register
The Centre shall maintain a non-public register of critical information infrastructure, essential and important entities, material dependencies and contacts. It is protected information, publishable only where the Centre determines no security risk arises.
Article (25) — Critical providers and supply chains
First — Cloud, data centre, managed-service, software-component, network, communications or security providers may be classified where widespread reliance creates common failure points or systemic effects.
Second — Classification does not prohibit foreign providers, subject to appropriate risk, access, data, continuity and safe-exit controls.
Article (26) — High-importance government systems
With the National Digital Transformation Centre and competent bodies, the Centre shall classify high-importance government systems and sovereign data and set additional hosting, backup, key management, privileged access, audit and state-continuity requirements.
Article (27) — Operational technology
Industrial and operational controls for energy, water, oil, gas, transport, industry and physical infrastructure shall reflect safety, continuity, long equipment life and shutdown and update difficulties. Immediate updates shall not be required where operational risk would increase; compensating measures and time-bound remediation shall apply.
Article (28) — Foreign entities and representatives
Classified foreign entities providing essential or important services in Iraq without permanent establishments shall appoint Iraqi legal representatives and contact points for reporting, oversight and notices, without prejudice to investment, tax and company laws.
Article (29) — Classification review
Classifications shall be reviewed at least every two years or after material service, ownership, dependency or risk changes. Entities may seek reconsideration if grounds cease or materially change. Reasoned decisions shall issue within sixty days of complete applications.
Chapter Four — Risk management and baseline controls
Article (30) — General risk-management duty
Essential and important entities shall adopt proportionate technical, organisational and administrative measures to manage risks, prevent incidents or reduce likelihood and impact, and ensure continuity and recovery. Measures shall be documented and periodically reviewed against threats and technical change.
Article (31) — Cybersecurity governance
First — Boards or senior officials shall approve written policies, designate executives with adequate authority and resources and review risks, compliance, major incidents and remediation at least annually.
Second — Senior management shall receive periodic training appropriate to cyber, supply-chain and continuity responsibilities.
Article (32) — Information security management system
Essential entities shall establish information security management systems covering relevant people, processes, technologies, suppliers and locations. The Centre may accept an internationally recognised framework, such as ISO/IEC 27001 or an equivalent, as the organisational basis with necessary national and sectoral additions.
Article (33) — Asset inventory and classification
Entities shall maintain current registers of assets, systems, services, software, accounts, connections and external dependencies, classified by importance, sensitivity and acceptable downtime, with security controls linked to classification.
Article (34) — Identity and access management
Strong controls shall include least privilege, separation of sensitive duties, multi-factor authentication for privileged accounts, remote access and critical systems where appropriate, periodic account and permission review and prompt revocation when unnecessary.
Article (35) — Encryption and key management
First — Encryption and key management shall suit sensitivity and risk. National standards shall define algorithms, key lifecycles and physical or logical protection in critical systems.
Second — This Law shall not impose universal backdoors or systematic encryption weakening. Access to encrypted content requires an individual case under applicable law and judicial decision where constitutionally or legally required.
Article (36) — Network architecture and segregation
Essential entities shall minimise lateral movement and compromise propagation through risk-based environment separation, critical-system isolation, restricted administrative paths, monitoring supplier and internet connections and appropriate zero-trust principles without rigid technological mandates.
Article (37) — Vulnerability and update management
First — Continuous processes shall discover, assess, prioritise and remediate vulnerabilities, including software-version and patch inventories and national target deadlines based on severity and exploitability.
Second — Where safety or continuity prevents critical or operational updates, reasons shall be documented, compensating controls applied and a deadline set for underlying remediation.
Article (38) — Secure development, acquisition and change
Cybersecurity shall be integrated into system, software and service design, development, purchase and change management, including necessary code or component review, pre-release security testing, open-source management, software-secret controls and verification of update integrity and provenance.
Article (39) — Logging and monitoring
Entities shall retain risk-proportionate technical logs sufficient for detection, technical investigation and response, ensuring time synchronisation, integrity, tamper protection and restricted access. Retention follows security needs and specific laws, without excessive personal data.
Article (40) — Backup, recovery and continuity
Essential entities shall maintain continuity and recovery plans with protected, isolated backups where needed, defined service and data recovery objectives, periodic restoration and alternative-operation tests, and feasible manual or alternative procedures during digital failure.
Article (41) — Supply-chain risks
First — Entities shall assess relevant supplier, product and service risks and contract for appropriate security, incident and vulnerability notification, access management, audit, continuity and data return or deletion at termination.
Second — The Centre may prescribe additional measures for systemic suppliers. General supplier or product bans require reasoned decisions based on national risk assessment and legal competence, respecting competition and market continuity.
Article (42) — Cloud and managed services
First — Contracts for cloud or managed technical or security services shall allocate security duties and specify data, branch and backup locations, audit logs, key management, incident notification, portability and exit rights, continuity and backups.
Second — Outsourcing alone does not transfer regulated entities' legal risk-management responsibility to providers.
Article (43) — Operational and industrial security
Operational environments shall control remote access, isolate control networks, verify firmware integrity, manage removable media, monitor changes and coordinate safety, operations and cybersecurity teams, prioritising life, environment and facility safety.
Article (44) — Personnel security and awareness
Entities shall lawfully vet sensitive-role personnel, manage onboarding, role changes and access termination, and train staff on phishing, social engineering, data and incidents. Specialist training is mandatory for critical technical and leadership roles.
Article (45) — Tests and exercises
First — Essential entities shall periodically conduct risk-proportionate vulnerability scans, penetration tests, tabletop or technical exercises and recovery tests safely and with authorisation, preserving service continuity.
Second — High risks may justify mandatory national or sector exercises or independent tests, with entity and regulator notice unless the exercise's nature requires otherwise.
Article (46) — Independent assessment
First — Essential entities shall receive independent cybersecurity assessments at least every two years, more frequently according to risk. Important entities may use sample-based or Centre-requested assessments absent high-risk indicators.
Second — The Centre shall set auditor qualification, independence and conflict criteria and may recognise credible international certificates and reports while requesting additional evidence.
Chapter Five — Incident management, reporting and response
Article (47) — Incident classification
The Centre shall issue a national matrix based on impact scope, affected data and systems, service disruption, propagation or recurrence potential, national security and public safety, defining critical, high, medium and low levels and escalation.
Article (48) — Reporting duty
Essential and important entities shall report major incidents and those meeting national mandatory thresholds to the Centre and relevant sector response team, without delay for incomplete investigations or uncertainty over cause or actor.
Article (49) — Reporting stages and deadlines
First — At minimum:
(a) Critical incidents: immediate notification upon reasonable verification.
(b) High-severity incidents: initial notification within four hours of reasonable verification.
(c) Other major incidents not reported above: early warning within twenty-four hours of awareness.
(d) Initial report or material update within seventy-two hours, including available scope, impact, actions and compromise indicators.
(e) Final report within thirty days of closure, or an interim report if continuing followed by a final report after closure.
Second — Instructions may adjust detailed medium- and low-level deadlines consistently with classification, but shall not extend this Article's critical and major incident deadlines.
Article (50) — Report contents
Reports shall include available descriptions, detection time, affected services and systems, downtime, sensitive data or functions, expected impact, containment, contacts and lawfully shareable technical indicators. The Centre shall not request unnecessary communications content or personal data.
Article (51) — Technical evidence preservation
Entities shall preserve relevant logs and technical traces with integrity and chain of custody under instructions, separating response from criminal investigation. This Law does not make the Centre a criminal investigative body; evidence referral follows relevant laws.
Article (52) — Emergency directions
First — Where an imminent threat could cause a serious national or sectoral incident, the Centre may issue temporary, specific technical directions to essential entities for necessary, proportionate action, such as isolating a connection, disabling compromised credentials or applying an emergency control.
Second — Directions shall be written, reasoned and time-limited where possible. They shall not intercept content or widely disable public services without specific legal authority and competent approval. Entities may seek urgent review by the Centre's head without suspending action against imminent danger.
Article (53) — National cyber crisis management
Where incidents exceed an entity's or sector's capacity or affect multiple sectors, the Prime Minister, on Centre and competent security recommendations, shall activate the national cyber crisis plan, defining command, coordination, priorities, public communication and resources, without affecting emergency powers requiring independent constitutional or legal grounds.
Article (54) — Notification of affected persons and the public
First — Where incidents may seriously harm users, customers or public safety, entities shall coordinate with the Centre and regulator to notify affected persons promptly with practical protective information, unless immediate notice increases a specific security risk.
Second — Some details may be delayed for limited, reasoned periods. Cybersecurity shall not conceal incidents solely to protect commercial or administrative reputation.
Article (55) — Cross-border incidents
The Centre shall coordinate with foreign and international contacts, protecting Iraqi interests, sovereignty and confidentiality. Data transfer, judicial cooperation and applicable treaty rules govern according to information and action type.
Article (56) — Information sharing and liability protection
First — Entities may share threat indicators, vulnerabilities, attack methods and defensive measures in good faith through approved channels. Sharing alone creates no civil liability where limited to cybersecurity necessity, respectful of confidentiality, competition and data protection, and free of deception or gross negligence.
Second — The Centre shall not use voluntarily supplied information competitively or commercially or identify providers without consent or legal obligation.
Article (57) — Coordinated vulnerability disclosure
First — The Centre shall establish a national coordinated disclosure framework, requiring essential entities to provide clear technical-reporting channels and risk-proportionate response times.
Second — Authorised security research programmes may define testing scope, conditions and safeguards. Acts within explicit written authorisation are authorised for this Law, while criminal laws remain applicable outside scope or where criminal intent exists.
Chapter Six — Rights and confidentiality safeguards
Article (58) — Communications confidentiality
Nothing here authorises the Centre or entities to monitor, intercept or record private content beyond constitutional and statutory limits. Legally permitted interception or disclosure requires judicial decisions within their scope, duration and purpose.
Article (59) — Separating security from content regulation
Centre measures are limited to network, system, service and data integrity and technical threat response. This Law grants no power to classify or block lawful opinions, news or speech because of content, or regulate media or political content.
Article (60) — Data minimisation
Technical collection for monitoring or response shall be limited to security necessity, using logical separation, anonymisation or aggregation where feasible and retention based on need, risk and law.
Article (61) — Personal information
Cybersecurity personal-data processing follows applicable privacy and protection rules. Urgently necessary processing to protect networks or prevent or respond to incidents is permissible where lawful, proportionate and purpose-limited, with stronger safeguards upon dedicated data protection legislation.
Article (62) — Secrets and protected information
First — Centre and sectoral staff, auditors and experts shall protect security, commercial, professional and personal information accessed at work, disclosing only as legally required, necessary to prevent serious harm or to execute judgments.
Second — Confidentiality continues after employment or contract termination.
Article (63) — Good-faith reporting protection
Employment or contractual retaliation for good-faith lawful reporting of dangerous vulnerabilities, material non-compliance or concealed incidents is prohibited, respecting secrets and avoiding publication of exploitable details. More favourable whistleblower laws apply.
Article (64) — Authorised security research
Public and essential entities shall encourage responsible research and authorised testing. Instructions shall model authorisation, scope, data management and disclosure. Permission shall not include data destruction, service disruption or access unnecessary to demonstrate vulnerabilities.
Article (65) — Transparency and fair procedure
Individual regulatory decisions shall be written, reasoned, notified and subject to grievances and appeals. Temporarily withholding some reasons to protect classified information requires a stated legal basis and maximum disclosure compatible with security.
Chapter Seven — Oversight, enforcement and grievances
Article (66) — Oversight and audit
First — The Centre, or a regulator under written arrangements, may request necessary technical records and conduct or commission proportionate audits or tests, defining scope beforehand and avoiding unrelated personal data or secrets.
Second — Sensitive-system access or active testing requires entity consent and safe plans except specific statutory emergency powers. Audit authority is not general authority to inspect communications content.
Article (67) — Non-compliance notices and remediation
For breaches without imminent risk, the Centre shall notify violations, evidence and requirements and allow reasonable time for a remediation plan and implementation, considering risk, system complexity and alternatives.
Article (68) — Compliance orders
First — After hearing entities except in urgency, the Centre may order breach removal, risk mitigation, tests, stronger controls or cessation of specific technical practices demonstrably exposing critical infrastructure to unacceptable risk.
Second — Orders shall choose the least restrictive effective measure and specify grounds, duration and completion indicators.
Article (69) — Urgent preventive measures
For established imminent national security, public safety or essential-service risks, the Centre may impose preventive measures for up to seven days, extendable by reasoned Prime Minister or delegated decision within law, with immediate entity and regulator notice and urgent review routes.
Article (70) — Administrative violations
Violations include:
First — Unjustified failure or serious delay in mandatory reporting.
Second — Failure to implement final compliance orders.
Third — Materially misleading supervisory information.
Fourth — Gross negligence in risk-management requirements after warning.
Fifth — Obstructing lawful audit or destroying records needed for incident or compliance verification.
Sixth — Repeated violations creating serious essential-service risks.
Article (71) — Administrative fines
First — After hearing procedures, private entities may be fined within these limits:
(a) (5,000,000) five million to (50,000,000) fifty million dinars for procedural breaches without serious risk.
(b) (25,000,000) twenty-five million to (250,000,000) two hundred and fifty million dinars for failure to implement material risk-management or reporting requirements after warning.
(c) (100,000,000) one hundred million to (1,000,000,000) one billion dinars for deliberate or repeated breaches seriously endangering critical infrastructure or essential services.
Second — Fines shall reflect size, severity, duration, negligence, remediation cooperation, gains and history, and shall not cause worse essential-service disruption than the breach.
Third — The Council of Ministers may periodically propose inflation-related adjustments, which require legislation.
Article (72) — Public-body violations
The Centre shall issue corrective orders to heads of violating public bodies, record breaches in oversight reports and refer gross negligence or deliberate non-compliance to competent oversight or disciplinary bodies. Public status does not exempt standards or remediation.
Article (73) — Aggravating and mitigating factors
Aggravation includes concealing major incidents, repetition, endangering lives or national security, destroying evidence and unjustified failure to remedy known critical vulnerabilities. Mitigation includes early self-disclosure, full cooperation, rapid containment and genuine pre-existing compliance programmes.
Article (74) — Grievances
First — Classification, compliance orders and fines may be challenged before a functionally independent Prime Minister's Office grievance committee within fifteen working days of notice. Reasoned decisions shall issue within thirty working days.
Second — Grievances do not suspend imminent-risk measures. Committees or courts may wholly or partly stay them when urgency ceases or implementation harm outweighs risk.
Article (75) — Judicial appeal
Final decisions are appealable before competent administrative courts under applicable rules and deadlines. Confidential evidence shall remain accessible to courts through procedures preserving confidentiality and defence rights where possible.
Article (76) — No duplicate sanctions
The same regulator shall not impose multiple administrative fines for the same occurrence under the same classification. Comparable sectoral sanctions require coordination to avoid duplication, without prejudice to civil or criminal liability established under other laws.
Article (77) — Civil and criminal liability
This Law creates no new information-technology crimes and does not replace specialised criminal or digital-evidence rules. Civil liability remains under applicable laws, considering compliance with statutory duties of care.
Chapter Eight — Transitional and final provisions
Article (78) — Implementing regulations and instructions
On Centre proposals after consultation, the Council of Ministers shall issue implementing regulations. The Centre shall issue technical instructions and standards within its competence no later than one hundred and eighty days after publication.
Article (79) — Financial and implementation plan
First — Within one hundred and twenty days, the Centre shall prepare a five-year implementation and financial plan inventorying existing capabilities and assets before requesting new ones, separating Centre, sector-team, public-body compliance, training, capital and recurring operating costs.
Second — The Council of Ministers shall approve the plan within available budgets. This Law alone shall not authorise unfunded commitments outside lawful budget and contracting procedures.
Article (80) — Centre and function continuity
Existing Centre structures, staff, functions, records, plans and reporting channels continue uninterrupted. This Law provides their statutory basis within its subject matter.
Article (81) — Existing policies and standards
Existing cybersecurity policies, standards, technical instructions and decisions remain effective insofar as compatible until amended or replaced. Legislative transition shall not suspend reporting or response channels.
Article (82) — Entity inventory and classification
With sectoral bodies, the Centre shall complete initial infrastructure identification and essential/important classification within six months of commencement, notifying entities of decisions and transitional requirements.
Article (83) — Compliance transition periods
First — Essential entities have up to twelve months from notification to meet the baseline; important entities up to eighteen months.
Second — Legacy operational systems may receive extensions to twenty-four months upon risk assessments, compensating controls and replacement or remediation plans.
Third — These periods exclude incident reporting and emergency duties, effective upon the relevant instructions' commencement.
Article (84) — Government bodies
Within six months, ministries and public bodies shall prepare asset and cyber risk registers and approved remediation plans, completing baseline requirements within twelve months, prioritising public-facing, sovereign-data and critical-infrastructure-connected systems.
Article (85) — Kurdistan Region and governorate coordination
Within ninety days, the Centre shall invite competent regional and governorate authorities to establish common warning, reporting, response, indicator-sharing and interdependency arrangements, under constitutional powers and ensuring national network and service continuity.
Article (86) — National capacity development
Competent bodies, with the Centre, Higher Education and Scientific Research and Education ministries and business, shall develop cybersecurity, response, analysis, operational technology and risk-management skills, encouraging laboratories, research, professional certification and joint exercises without legally mandating a particular commercial certificate.
Article (87) — Prime Minister's Office instructions alignment
Centre provisions in Formations and Functions Instructions No. (1) of 2025 shall be reviewed within one hundred and eighty days of commencement and amended or replaced consistently, remaining effective during transition insofar as compatible.
Article (88) — Conflicting provisions
Conflicting lower-ranking regulations, instructions or decisions shall be repealed or amended upon replacement or transition expiry as applicable. No sectoral law is repealed without express legislation.
Article (89) — Entry into force
This Law takes effect ninety days after Official Gazette publication, except provisions with specific transition periods.
Fifth — Reasons for enactment
To establish a unified Iraqi cybersecurity legal basis; protect critical information infrastructure and essential services; elevate existing Centre powers from administrative to statutory status; regulate classification, risk management, reporting, audits and enforcement; develop national response and sectoral and international cooperation; and protect constitutional privacy, communications confidentiality, rights and freedoms in exercising these powers, this Law is enacted.
Sixth — Explanatory memorandum
1. Why does Iraq need a framework law?
Existing structures show that institutional foundations have been laid: a national centre, incident plans and standards, early warning and coordination exist. Administrative instructions alone cannot authorise fines on private vital-sector companies, general audit duties or appeal routes. These require legislation defining rights, duties, powers and safeguards.
2. Why no new authority?
The Centre already exists in the Prime Minister's Office. Instructions No. (1) of 2025 assign the required strategy, standards, compliance, risk, warning, response, training and cooperation functions. A parallel authority would recreate overlapping powers. The proposal preserves the Centre and gives its work a statutory basis.
3. Essential and important entity philosophy
Not every shop, office or website is critical infrastructure. Strong duties should focus on bodies whose failure widely affects the State, society or economy and suppliers creating common dependencies. This avoids overregulation and directs public inspection and resources to highest risks.
4. Responsibility begins with management, not IT
Major incidents often reflect institutional decisions: ageing systems, single suppliers, inadequate backups, weak segmentation or excessive privileges. Boards or senior officials therefore oversee risks and resources without every incident automatically creating personal liability.
5. Early staged reporting
Current Iraqi government standards distinguish critical, high, medium and low incidents, requiring immediate critical reports, high reports within four hours, medium within twenty-four and low within forty-eight. The proposal builds on this with prompt notice, technical updates and final reporting, preventing full investigation from delaying a national containment opportunity.
6. Supply chains and operational technology
Risk may originate outside an entity—in cloud providers, maintenance firms, updates, supplier accounts or shared platforms. Energy, water, oil and transport controls differ from desktop computers; immediate shutdown or updates may threaten safety. Supplier management and compensating controls for legacy operational systems are therefore required where immediate updating is riskier than temporary continued use.
7. Encryption and privacy
Cybersecurity does not justify permanent encryption weaknesses. The proposal prohibits universal backdoors and systematic weakening, leaving targeted access to legally permissible cases with judicial safeguards. It also minimises technical-indicator data and prevents content or speech regulation through Centre powers.
8. Graduated enforcement
Without imminent risk, remediation precedes punishment: notice, remedial plans and compliance orders. Fines address refusal, repetition or serious risk. Public bodies instead face corrective orders and disciplinary and supervisory referral, because transfers between state accounts do not achieve the same purpose as private fines.
9. Relationship to cybercrime enforcement
This is preventive regulatory legislation, not a criminalisation and prosecution law. It creates no new technology crimes or general Centre investigative powers. Logs and technical evidence support response and documentation; suspected crimes go to investigators under specialised legislation. This separates resilience regulation from criminal enforcement.
10. Federalism and national coordination
Cyber threats require rapid national contact across governorate and regional boundaries, while constitutional powers must be respected. The proposal therefore combines national standards and cross-sector security and infrastructure response with operating arrangements for Kurdistan Region and governorates, rather than assuming unlimited federal administrative authority over digital matters.
Seventh — Alignment with related legislation and files
| Area | Relationship | Action |
|---|---|---|
| Prime Minister's Office Formations and Functions Instructions No. (1) of 2025 | Defines current Centre powers and structure | Temporary continuation and alignment within 180 days; the Law becomes the superior basis for powers within its subject |
| Constitutional privacy and communications confidentiality | Limits monitoring, interception and content access | Express judicial safeguards and prohibition of general surveillance |
| Banking, communications, energy, transport and health legislation | Contains sectoral oversight and specific requirements | Unified national baseline, stricter sectoral measures and no duplicate supervision |
| POL-85 Personal Data Protection and Digital Privacy | Governs lawful personal-data processing and subject rights | Separate cybersecurity purposes from secondary data uses |
| POL-86 Digital Government and Interoperability | Increases reliance on shared systems and digital services | Classify high-importance government systems and continuity duties |
| POL-87 Digital Identity and Trust Services | Provides identity verification, signatures and trusted services | Apply key, access and incident requirements without regulatory duplication |
| POL-89 Information Technology Crimes and Digital Evidence | Addresses criminalisation, investigation and evidence | Keep POL-88 preventive and regulatory without parallel crimes |
| POL-91 Telecommunications and Digital Services | Overlaps in networks, providers and spectrum | Coordinate network standards and reporting with the communications regulator |
| POL-92 Disaster Risk Management and State Continuity | Overlaps in crises and continuity | Connect cyber crises to continuity without replacing emergency or disaster law |
| POL-93 Accession to the Budapest Convention | Concerns international cybercrime and evidence cooperation | Separate technical from cross-border judicial and criminal cooperation |
Eighth — Financial and implementation impact
No new centre or parallel apparatus is assumed, reducing institutional start-up costs. Effective compliance nevertheless needs resources at three levels: national monitoring, audit and response capacity; sectoral and institutional teams; and closing gaps within public bodies and critical infrastructure.
Private entities bear risk-proportionate compliance costs and may integrate security into ordinary technology investments rather than always creating separate projects. Public remediation belongs in prioritised budgets and investment programmes. This Law alone authorises no off-budget commitment.
Ninth — Useful international comparison
European Union — NIS2: Directive (EU) 2022/2555 illustrates combining national strategy, competent bodies and response teams with essential and important entity risk and reporting duties, oversight and enforcement. The proposal uses this functional structure without copying EU scope, fines or sector divisions literally.
NIST Cybersecurity Framework 2.0: The framework's Govern, Identify, Protect, Detect, Respond and Recover functions make cybersecurity part of enterprise risk management, reflected in leadership, inventory, protection, monitoring, response and recovery provisions.
ISO/IEC 27001:2022: Provides an international risk-based, continuously improving information security management standard. Commercial certification is not legally mandatory, but recognised frameworks may provide partial compliance evidence alongside national duties.
International Telecommunication Union: The Global Cybersecurity Index 2024 places Iraq in Tier Four, 'Evolving', with relative organisational strength and development gaps in legal, technical, capacity and cooperation measures. The Law therefore converts existing organisation into legal duties, enforcement and sustainable capability.
Tenth — Sources and references
- Iraqi Council of Representatives — Constitution of the Republic of Iraq
Constitutional rights, freedoms, electronic communications confidentiality and distribution of powers. - Ministry of Justice — Iraqi Official Gazette issue (4847), 10 November 2025
Contains Prime Minister's Office Formations and Functions Instructions No. (1) of 2025. - Iraqi Official Gazette issue 4847 — Official text of Instructions No. (1) of 2025
Centre functions and organisational provisions. - Iraqi News Agency — Cybersecurity Strategy 2022–2025 approved, 16 February 2022
Official reference for the previous national strategy. - National Cybersecurity Centre — Government Institution Cyber Incident Classification Standards
National reference for severity, classification and current reporting deadlines. - International Telecommunication Union — Global Cybersecurity Index 2024
Iraq profile measuring legal, technical, organisational, capacity and cooperation measures. - European Union — Directive (EU) 2022/2555 (NIS2)
Comparative governance, risk management, reporting, essential/important entity and oversight reference. - US National Institute of Standards and Technology — Cybersecurity Framework 2.0
Risk management through Govern, Identify, Protect, Detect, Respond and Recover. - International Organization for Standardization — ISO/IEC 27001:2022
Risk-based information security management and continuous improvement reference.
External references support documentation and comparison; foreign or international standards become applicable Iraqi rules only where adopted under this Law or competent Iraqi legislation.
Ali Zuweid's Political Programme · POL-88