Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Corporate & Commercial Law
  3. Business Compliance
  4. Risk Management
  5. Cyber Risk Management

Loading...

Risk Management

Cyber Risk Management

Who does the information security law apply to?

Subjects of critical information systems and connected organisations that ensure the availability of an information asset within their relationship; the list is approved by the government.

What does the law require of a subject?

A security policy meeting minimum requirements, asset inventory and classification, periodic audits, penetration testing, designation of a manager and a specialist, and incident response.

Can a non-subject apply these rules?

Yes, voluntarily — the law expressly allows assuming the obligations, a documented path to best practice.

What happens to defects found in an audit?

A remediation action plan with a schedule is submitted to the competent authority within one month; the audit conclusions are mandatory.

5 min·...

Cyber risk management in Georgia is no longer purely a private-sector discretion: the Law of Georgia on Information Security imposes mandatory organisational measures on defined subjects — from policy and asset classification to audit, penetration testing and incident response. The first and most consequential question every company must ask is a verification question: does it fall within the scope of this law at all? This page is built around that logic: first the scope, then the obligations, and finally the architecture of responsibility.

Who the Law Covers — the Verification Question

Under Article 3, the law applies to a subject of a critical information system, and to any organisation or agency subordinate or connected to such a subject through employment, internship, contractual or other relations, where within those relations it ensures the availability of an information asset.

The list of critical information system subjects and their criticality classification are approved by government decree, guided by criteria including the severity and scale of the consequences of the system’s disruption or failure, the expected economic loss, the necessity of the services the system provides for the normal functioning of society, and the number of users. The law does not extend to mass media, editorial offices of publishing houses, scientific, educational, religious and public organisations or political parties. At the same time, any legal entity or state authority that is not a subject may voluntarily assume the obligations arising from the law — for many companies this is precisely the route by which best practice becomes a competitive standard.

Policy and Minimum Requirements

Article 4 obliges the subject to adopt internal rules for the use of information security, which define the organisation’s information security policy. The policy must satisfy minimum requirements established with regard to internationally recognised standards, by orders of the competent authorities according to categories. The adopted rules are submitted for review to the competent authority, which analyses the documents and issues binding instructions or recommendations to remedy the defects identified; any change to the rules is likewise notified.

Asset Inventory and Classification

Article 5 governs the first step of risk-based management: the subject inventories its information systems to record every information asset, assigning each a criticality class — confidential or for internal use — while the rest counts as open information. The record describes each asset’s significance, value and existing level of protection, and when an asset is created its class is determined by the author or the responsible person.

Audit and Penetration Testing

Article 6 obliges the subject to conduct an initial and periodic information security audit — an assessment of the management system’s compliance with the minimum standards. The audit concludes with findings whose requirements are mandatory. The same article requires the subject to ensure penetration testing of the information system according to a pre-planned, documented task; the conclusions of that test are equally binding.

Where the audit or the test reveals non-compliance or weaknesses, the subject analyses them and draws up an action plan with a schedule, submitted to the competent authority for agreement within one month of completion. The audit and the test are carried out in cooperation and coordination with the information security manager and the computer security specialist.

People and Incidents

Article 7 requires the subject to designate an information security manager — the person responsible for daily monitoring of the policy, describing assets and access, preparing internal documentation, collecting incident information and organising training. The manager is accountable to the head of the subject or an authorised collegiate body and reports annually.

Article 9 establishes the computer security specialist, who monitors computer systems daily, is available at any time including outside working hours, and immediately passes incident information to the computer incident response team. Article 10 governs the identification of incidents themselves: the subject studies, describes and responds to the incident, while the configuration of the network sensor must exclude any possibility of access to the content data of communications. The subject must respond to the response team’s binding instructions within a reasonable period. Data-protection incident duties form a separate regime on their own page.

Frequently Asked Questions

Below are the questions companies ask most often when planning cybersecurity, answered from the norms of the Law of Georgia on Information Security.

How do I check whether my company is covered?

Decisive under Article 3 are the government-approved list of critical information system subjects and the circle of connected organisations. Checking that list and your relations is the first step.

Can the obligations be assumed voluntarily?

Yes — an entity that is not a subject may voluntarily take on the obligations, which signals seriousness to customers and partners.

What is a penetration test and why is it mandatory?

A test of the system’s penetrability, run to a pre-planned, documented task; the conclusions’ requirements are mandatory for the subject.

Who is responsible for cybersecurity inside the organisation?

Two figures: the information security manager at policy level and the computer security specialist at the daily technical level, who must be reachable at any time.

How We Help on Legal.ge

The lawyers of Legal.ge guide cyber risk management through the full cycle: determining whether your company falls within the law’s scope, building the policy and asset classification system, preparing for audit and penetration testing, and drafting the incident response procedure. Contact us — and your cybersecurity will become part of the routine instead of a leap of faith.

Updated: ...

Verified against current law: 09/07/2026

Legal basis:

  • საქართველოს სისხლის სამართლის კოდექსი
  • ინფორმაციული უსაფრთხოების შესახებ
  • პერსონალურ მონაცემთა დაცვის შესახებ

Find a Specialist

Professionals working in this field

Corporate & Commercial Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law Occupational health and safety specialistCorporate & Commercial Law Personal data protection officer