The Purpose of the Law and the Information Security Framework
The Georgian law on information security was adopted to promote the effective and efficient protection of information security, to establish the rights and duties of the public and private sectors in this sphere, and to define the mechanisms of state control over information security policy. In practical terms, the state determines who counts as a subject of a critical information system, what obligations attach to that status, and how specialized response groups react to computer incidents. For companies dependent on digital infrastructure, knowledge of this law is the foundation of managing compliance risk.
The law applies to a subject of a critical information system and to any organization connected with it through employment, internship, contractual or other relations that ensure the availability of an information asset. It does not apply to the mass media, the editorial offices of publishers, or scientific, educational, religious and public organizations and political parties, regardless of the significance of their activity, and it does not affect the norms regulating freedom of information, the processing of personal data and the protection of state, commercial and personal secrets.
Categories of Criticality and the Registry
The list of subjects of critical information systems is approved, and the criticality classification of a respective subject is established, by a decree of the Government of Georgia, whose draft is presented to the government by the Ministry of Justice in agreement with the Ministry of Defense, the Ministry of Internal Affairs and the State Security Service. In compiling the list, the following criteria are taken into account: the severity and scale of the expected consequences of the disruption or failure of the system; the expected economic damage; the necessity of the service for the normal functioning of society; the number of users; and the material condition of the subject together with the expected costs of the obligations imposed by this law.
The distribution among categories matters in practice: the rules attached to subjects of the first, second and third categories — from sensor configuration to the response group receiving notifications — differ. A commercial bank that is not a subject is guided by the rules of the National Bank, and a legal entity or state authority that is not a subject may voluntarily assume the obligations arising from this law.
Incident Identification and Notification
A subject of a critical information system carries out the identification of a computer incident, which includes the study and description of the incident and the response to it; for this purpose the subject uses a network sensor. The configuration rules for the network sensor are established, for a subject of the first or second category, by an order of the head of the Operational-Technical Agency; for a subject of the third category, by an order of the chair of the Digital Governance Agency; and for a subject within the defense sphere, by an order of the Minister of Defense. The configuration rules must exclude access to the content data of the subject's communications.
On the identification of an incident in a subject of the first or second category, the computer incident response group of the Operational-Technical Agency is notified immediately; in a subject of the third category — the response group of the Digital Governance Agency; in the defense sphere — the response group of the Cybersecurity Bureau. The group studies and describes the incident, responds to it, and submits binding instructions to the subject for execution; such an instruction may not provide for an obligation of access to the sensor, information asset or system of a subject of the second or third category, and the subject must respond within a reasonable term and report on the measures taken. An ongoing incident in the network of a first-category subject is identified by the response group of the Operational-Technical Agency or by the subject's computer security specialist; the same group holds the right of access to that category's network sensor — except where the data identifying the traffic contains information on banking transfers.
Administrative Liability and Fines
The law attaches administrative liability to breaches of the requirements connected with the identification of computer incidents. The failure of a subject of the first category to notify, the failure to fulfill a binding instruction issued by the Operational-Technical Agency, or the failure to submit information on the measures taken entails a warning or a fine in the amount of 5 000 lari. The same act committed by a subject on whom an administrative penalty has already been imposed for this violation within 1 year entails a fine in the amount of 10 000 lari.
An analogous rule applies to subjects of the third category vis-à-vis the instructions of the Digital Governance Agency: a warning or a fine of 5 000 lari, and for a repeated violation within 1 year a fine of 10 000 lari. To avoid these penalties, a subject needs a clear internal procedure: who registers an incident, who notifies the response group, who executes the instructions, and how the documentation is stored — in an audit it is the record that counts.
Building Compliance and Practical Recommendations
For a subject, a compliance programme combines the deployment and configuration of the network sensor, the registration and notification of incidents, a procedure for responding to binding instructions, reporting on measures and personnel training. The systems for payment, securities settlement and reserve management, and the critical systems used for monetary and currency operations, are not subject to these identification requirements — an exemption to be reflected in the design of the framework rather than discovered during an inspection.
The response groups create a unified platform for sharing information on computer incidents, while the classification rule is defined by a government decree — variables to be tracked in the compliance documentation, since changes in the rules directly affect the subject's processes.
Frequently Asked Questions
Who does the information security law apply to?
To subjects of critical information systems and to organizations connected with them through employment, internship or contractual relations ensuring the availability of information assets; the mass media, religious, educational, scientific and public organizations and political parties are not subject to it.
What is the fine for concealing an incident?
For subjects of the first and third categories, failure to notify, failure to fulfill an instruction or failure to submit information entails a warning or a fine of 5 000 lari; a repeated violation within 1 year — a fine of 10 000 lari.
Who is notified about a computer incident?
A subject of the first or second category immediately notifies the computer incident response group of the Operational-Technical Agency, a subject of the third category — the group of the Digital Governance Agency, and a subject in the defense sphere — the group of the Cybersecurity Bureau.
Can communication content be accessed?
No — the configuration rules of the network sensor must exclude access to the content data of the subject's communications, and even the right of access to the sensor does not extend to data identifying banking transfers.
How We Help on Legal.ge
On Legal.ge you can find cybersecurity and technology law lawyers who will help with assessing the status of a subject, developing incident response procedures, documenting relations with the response groups and managing disputes over fines — a compliance plan tailored to your infrastructure.

