Skip to content
POL-88

This is a proposal for discussion, not an enacted law.

Ali Zuweid's Political Programme

Proposed draft law · Digital State, Data, Artificial Intelligence and Cybersecurity

Cybersecurity and Critical Information Infrastructure Protection Law

A national legislative framework elevating digital and critical infrastructure protection from instructions and policies to risk-based legal obligations, unifying governance, reporting and response while protecting privacy and communications confidentiality.

Document number
POL-88
Version
1.0
Publication/last updated
5 October 2026
Scope
Republic of Iraq

Executive summary

Iraq's institutional structure is now more advanced than several years ago: the Cybersecurity Strategy 2022–2025 was adopted, and Prime Minister's Office Formations and Functions Instructions No. (1) of 2025 organised the National Cybersecurity Centre, assigning policies and standards, compliance assessment, risk management, early warning, incident response and critical digital infrastructure protection. These essential functions nevertheless remain distributed among an expired strategy, administrative instructions and technical standards, without a national framework law precisely defining regulated entities, duties, oversight, safeguards, sanctions and appeals.

The proposal creates no parallel authority. It gives statutory recognition to the existing National Cybersecurity Centre in the Prime Minister's Office as the competent national body and establishes risk-based designation of critical information infrastructure and classification of essential and important entities. Entities must implement governance, asset, vulnerability and supply-chain management, identity, encryption, logging, backup and recovery controls, and specific operational technology and cloud requirements, with independent assessment and periodic exercises and tests.

The Law also establishes staged incident reporting, immediately for critical incidents and within four hours for high-severity incidents, followed by updates and final reports, and proportionate corrective and enforcement powers. Conversely, it separates cybersecurity from content surveillance: it does not permit general interception, weakening encryption or regulating opinion and speech, and confirms that private communications interception requires law and constitutional judicial safeguards.

Second — Legislative gap

The problem is not absent government cybersecurity activity but a missing unified legal layer. A national body, incident standards and some response mechanisms exist, yet no law conclusively defines critical entities, mandatory reporting, minimum supplier, cloud and operational technology risk controls, classification appeals, emergency orders or limits on technical data collection preventing security monitoring from becoming content surveillance.

Expanding digital government, payments, communications, data centres and industrial systems make cyberattacks capable of physical, economic and service disruption, beyond lost files. Focus must therefore shift from device security to institutional resilience: governance, inventories, interdependencies, continuity, recovery, supply chains, exercises and leadership accountability.

Third — Proposed legislative policy

Core choices
IssueLegislative choicePurpose
National bodyUse the existing National Cybersecurity Centre with statutory powersAvoid a parallel authority and improve legal stability
Obligation scopeRisk-based essential and important entity classificationFocus oversight on actual impact
StandardsA national baseline with stricter sectoral requirements where neededPrevent fragmentation while respecting sector differences
IncidentsStaged reporting according to severityPrompt reporting without waiting for full investigation
RightsProhibit general content surveillance and universal backdoorsProtect privacy and communications confidentiality
EnforcementNotice and remediation followed by graduated, appealable orders and finesEffective, proportionate enforcement subject to judicial review
TransitionContinue current instructions and standards pending alignmentAvoid gaps in national response

Fourth — Draft law text

Proposed enactment formula:
In the name of the people
Presidency of the Republic
Pursuant to enactment by the Council of Representatives and ratification by the President under item (First) of Article (61) and item (Third) of Article (73) of the Constitution, the following Law is issued:
Law No. ( ) of 2026
Cybersecurity and Critical Information Infrastructure Protection Law

Fifth — Reasons for enactment

To establish a unified Iraqi cybersecurity legal basis; protect critical information infrastructure and essential services; elevate existing Centre powers from administrative to statutory status; regulate classification, risk management, reporting, audits and enforcement; develop national response and sectoral and international cooperation; and protect constitutional privacy, communications confidentiality, rights and freedoms in exercising these powers, this Law is enacted.

Sixth — Explanatory memorandum

1. Why does Iraq need a framework law?

Existing structures show that institutional foundations have been laid: a national centre, incident plans and standards, early warning and coordination exist. Administrative instructions alone cannot authorise fines on private vital-sector companies, general audit duties or appeal routes. These require legislation defining rights, duties, powers and safeguards.

2. Why no new authority?

The Centre already exists in the Prime Minister's Office. Instructions No. (1) of 2025 assign the required strategy, standards, compliance, risk, warning, response, training and cooperation functions. A parallel authority would recreate overlapping powers. The proposal preserves the Centre and gives its work a statutory basis.

3. Essential and important entity philosophy

Not every shop, office or website is critical infrastructure. Strong duties should focus on bodies whose failure widely affects the State, society or economy and suppliers creating common dependencies. This avoids overregulation and directs public inspection and resources to highest risks.

4. Responsibility begins with management, not IT

Major incidents often reflect institutional decisions: ageing systems, single suppliers, inadequate backups, weak segmentation or excessive privileges. Boards or senior officials therefore oversee risks and resources without every incident automatically creating personal liability.

5. Early staged reporting

Current Iraqi government standards distinguish critical, high, medium and low incidents, requiring immediate critical reports, high reports within four hours, medium within twenty-four and low within forty-eight. The proposal builds on this with prompt notice, technical updates and final reporting, preventing full investigation from delaying a national containment opportunity.

6. Supply chains and operational technology

Risk may originate outside an entity—in cloud providers, maintenance firms, updates, supplier accounts or shared platforms. Energy, water, oil and transport controls differ from desktop computers; immediate shutdown or updates may threaten safety. Supplier management and compensating controls for legacy operational systems are therefore required where immediate updating is riskier than temporary continued use.

7. Encryption and privacy

Cybersecurity does not justify permanent encryption weaknesses. The proposal prohibits universal backdoors and systematic weakening, leaving targeted access to legally permissible cases with judicial safeguards. It also minimises technical-indicator data and prevents content or speech regulation through Centre powers.

8. Graduated enforcement

Without imminent risk, remediation precedes punishment: notice, remedial plans and compliance orders. Fines address refusal, repetition or serious risk. Public bodies instead face corrective orders and disciplinary and supervisory referral, because transfers between state accounts do not achieve the same purpose as private fines.

9. Relationship to cybercrime enforcement

This is preventive regulatory legislation, not a criminalisation and prosecution law. It creates no new technology crimes or general Centre investigative powers. Logs and technical evidence support response and documentation; suspected crimes go to investigators under specialised legislation. This separates resilience regulation from criminal enforcement.

10. Federalism and national coordination

Cyber threats require rapid national contact across governorate and regional boundaries, while constitutional powers must be respected. The proposal therefore combines national standards and cross-sector security and infrastructure response with operating arrangements for Kurdistan Region and governorates, rather than assuming unlimited federal administrative authority over digital matters.

Seventh — Alignment with related legislation and files

Legislative alignment map
AreaRelationshipAction
Prime Minister's Office Formations and Functions Instructions No. (1) of 2025Defines current Centre powers and structureTemporary continuation and alignment within 180 days; the Law becomes the superior basis for powers within its subject
Constitutional privacy and communications confidentialityLimits monitoring, interception and content accessExpress judicial safeguards and prohibition of general surveillance
Banking, communications, energy, transport and health legislationContains sectoral oversight and specific requirementsUnified national baseline, stricter sectoral measures and no duplicate supervision
POL-85 Personal Data Protection and Digital PrivacyGoverns lawful personal-data processing and subject rightsSeparate cybersecurity purposes from secondary data uses
POL-86 Digital Government and InteroperabilityIncreases reliance on shared systems and digital servicesClassify high-importance government systems and continuity duties
POL-87 Digital Identity and Trust ServicesProvides identity verification, signatures and trusted servicesApply key, access and incident requirements without regulatory duplication
POL-89 Information Technology Crimes and Digital EvidenceAddresses criminalisation, investigation and evidenceKeep POL-88 preventive and regulatory without parallel crimes
POL-91 Telecommunications and Digital ServicesOverlaps in networks, providers and spectrumCoordinate network standards and reporting with the communications regulator
POL-92 Disaster Risk Management and State ContinuityOverlaps in crises and continuityConnect cyber crises to continuity without replacing emergency or disaster law
POL-93 Accession to the Budapest ConventionConcerns international cybercrime and evidence cooperationSeparate technical from cross-border judicial and criminal cooperation

Eighth — Financial and implementation impact

No new centre or parallel apparatus is assumed, reducing institutional start-up costs. Effective compliance nevertheless needs resources at three levels: national monitoring, audit and response capacity; sectoral and institutional teams; and closing gaps within public bodies and critical infrastructure.

Estimation method: Public data cannot support reliable national compliance costing without system, centre, contract, personnel and gap inventories across sectors. A five-year financial plan is therefore required within 120 days, separating capital, operating, training and sector-team costs and beginning with existing assets and capabilities to avoid duplication.

Private entities bear risk-proportionate compliance costs and may integrate security into ordinary technology investments rather than always creating separate projects. Public remediation belongs in prioritised budgets and investment programmes. This Law alone authorises no off-budget commitment.

Ninth — Useful international comparison

European Union — NIS2: Directive (EU) 2022/2555 illustrates combining national strategy, competent bodies and response teams with essential and important entity risk and reporting duties, oversight and enforcement. The proposal uses this functional structure without copying EU scope, fines or sector divisions literally.

NIST Cybersecurity Framework 2.0: The framework's Govern, Identify, Protect, Detect, Respond and Recover functions make cybersecurity part of enterprise risk management, reflected in leadership, inventory, protection, monitoring, response and recovery provisions.

ISO/IEC 27001:2022: Provides an international risk-based, continuously improving information security management standard. Commercial certification is not legally mandatory, but recognised frameworks may provide partial compliance evidence alongside national duties.

International Telecommunication Union: The Global Cybersecurity Index 2024 places Iraq in Tier Four, 'Evolving', with relative organisational strength and development gaps in legal, technical, capacity and cooperation measures. The Law therefore converts existing organisation into legal duties, enforcement and sustainable capability.

Tenth — Sources and references

  1. Iraqi Council of Representatives — Constitution of the Republic of Iraq
    Constitutional rights, freedoms, electronic communications confidentiality and distribution of powers.
  2. Ministry of Justice — Iraqi Official Gazette issue (4847), 10 November 2025
    Contains Prime Minister's Office Formations and Functions Instructions No. (1) of 2025.
  3. Iraqi Official Gazette issue 4847 — Official text of Instructions No. (1) of 2025
    Centre functions and organisational provisions.
  4. Iraqi News Agency — Cybersecurity Strategy 2022–2025 approved, 16 February 2022
    Official reference for the previous national strategy.
  5. National Cybersecurity Centre — Government Institution Cyber Incident Classification Standards
    National reference for severity, classification and current reporting deadlines.
  6. International Telecommunication Union — Global Cybersecurity Index 2024
    Iraq profile measuring legal, technical, organisational, capacity and cooperation measures.
  7. European Union — Directive (EU) 2022/2555 (NIS2)
    Comparative governance, risk management, reporting, essential/important entity and oversight reference.
  8. US National Institute of Standards and Technology — Cybersecurity Framework 2.0
    Risk management through Govern, Identify, Protect, Detect, Respond and Recover.
  9. International Organization for Standardization — ISO/IEC 27001:2022
    Risk-based information security management and continuous improvement reference.

External references support documentation and comparison; foreign or international standards become applicable Iraqi rules only where adopted under this Law or competent Iraqi legislation.

Ali Zuweid's Political Programme · POL-88

What are you looking for?

Search content published on the website.