Hong Kong's Critical Infrastructure Cybersecurity Regime: Does PCICSO Apply to Your Business?

Author: Chloe Lau, Associate Solicitor
The Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) ("PCICSO") came into effect on 1 January 2026, marking Hong Kong's first dedicated cybersecurity legislation aimed specifically at protecting critical infrastructure and essential computer systems.

With the new regime now in force, many businesses are asking a simple question: Does it apply to us?
What is the PCICSO?
The PCICSO is designed to strengthen the cybersecurity resilience of infrastructures that are essential to the normal functioning of Hong Kong society and its economy. The legislation seeks to minimise the risks posed by cyberattacks, ransomware incidents, system intrusions, data compromise and disruptions to essential services.
The regime primarily targets operators within sectors such as:
energy;
information technology;
banking and financial services;
air, land and maritime transport;
healthcare services; and
telecommunications and broadcasting.
The legislation may also extend to other infrastructures where a cyber incident could have a significant impact on Hong Kong's critical societal or economic activities.
Who is subject to the PCICSO?
Importantly, the PCICSO is not a generally applicable cybersecurity law for all businesses operating in Hong Kong.
Instead, the statutory obligations apply only to organisations that have been formally designated as Critical Infrastructure Operators ("CI Operators") by the relevant Hong Kong authority.
Under section 12 of the Ordinance, an organisation may be designated where it operates infrastructure that falls within the statutory definition of critical infrastructure. The authorities have also made clear that the regime is principally intended for organisations operating essential or systemically important infrastructures, and that small and medium-sized enterprises and the general public are not intended to be affected.
For security reasons, Hong Kong does not maintain a public register of designated CI Operators. Rather, designation is made directly to the relevant organisation by way of formal written notice. Accordingly, an organisation would generally be aware that it is subject to the regime because it would receive an official designation from the relevant authority.
Key Compliance Obligations
Designated CI Operators are subject to a range of cybersecurity obligations, which broadly fall into three categories:
Organisational obligations
Maintaining an office in Hong Kong; and
Establishing a dedicated computer-system security management unit.
Preventive obligations
Implementing cybersecurity management plans;
Conducting regular risk assessments and security audits; and
Notifying the authorities of material changes affecting critical computer systems.
Incident reporting and response obligations
Maintaining emergency response plans;
Participating in cybersecurity drills; and
Reporting specified cybersecurity incidents within prescribed timeframes.
The Commissioner has also issued a Code of Practice providing practical guidance on compliance expectations.
Is Data Breach Reporting Mandatory?
The answer is highly dependent on whether an organisation falls within the scope of the PCICSO.
For designated CI Operators, the PCICSO imposes mandatory cybersecurity incident reporting obligations. CI Operators are required to maintain incident response mechanisms and report specified computer-system security incidents to the Commissioner within the prescribed timeframes.
For organisations outside the scope of the PCICSO, the existing position under the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") remains unchanged. At present, it does not impose a mandatory statutory obligation to report personal data breaches to the Office of the Privacy Commissioner for Personal Data ("PCPD"). While the PCPD recommends voluntary notification as a matter of best practice, particularly where there is a real risk of harm to affected individuals, such reporting remains non-mandatory under the current legislative framework.
Key Takeaways
Businesses should not assume that the PCICSO automatically applies simply because they operate in Hong Kong or maintain significant IT systems. The regime is specifically targeted at organisations that have been formally designated as Critical Infrastructure Operators, primarily within sectors that provide essential or systemically important services.
For businesses outside the designation regime, the new legislation does not create additional statutory cybersecurity or data breach reporting obligations. Nevertheless, maintaining appropriate cybersecurity governance, incident response procedures and internal controls remains an important aspect of good corporate governance and risk management. Further, organisations should continue to observe their obligations under other applicable data privacy and cybersecurity laws, including but not limited to the PDPO, regardless of whether they fall within the scope of the PCICSO.
How Ravenscroft & Schmierer Can Help?
Ravenscroft & Schmierer advises clients on cybersecurity regulation, critical infrastructure compliance, and data governance in Hong Kong. The firm assists organisations in assessing whether regulatory regimes apply, reviewing internal cybersecurity frameworks, and ensuring alignment with applicable legal requirements.
For further guidance on how the PCICSO may affect your business, or for support in implementing appropriate compliance measures, please contact us.
FAQ: PCICSO Hong Kong
What is the PCICSO in Hong Kong?
The PCICSO is legislation governing cybersecurity obligations for designated operators of critical infrastructure.
Does the PCICSO apply to all businesses?
No. It applies only to organisations formally designated as Critical Infrastructure Operators.
How will a business know if it is designated?
Designation is made through formal written notice from the relevant authority.
Are SMEs affected by the PCICSO?
No. The regime is intended primarily for essential infrastructure operators and not for SMEs.
Is data breach reporting mandatory in Hong Kong?
Mandatory reporting applies only under the PCICSO. Otherwise, reporting under the PDPO remains voluntary.
How can Ravenscroft and Schmierer assist with cybersecurity compliance?
The firm provides guidance on cybersecurity regulation, compliance frameworks and risk management in Hong Kong.
Why work with Ravenscroft and Schmierer on cybersecurity matters?
The firm provides practical legal guidance on navigating regulatory requirements and managing cybersecurity risks.
Disclaimer: Whilst every effort has been made to ensure the accuracy of this article it is general in nature and does not constitute legal advice of any kind. You should seek your own personal legal advice before taking legal action. We accept no liability whatsoever for loss arising out of the use or misuse of this article.
For specific advice about your situation, please contact:
Associate
+852 2388 3899

Comments