Legal.geLegal.ge
SpecialistsLibraryPricing
More
AboutBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Download on the App StoreLegal.ge for iPhone

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Cybersecurity Law
  4. Cybersecurity Compliance
  5. Security Audit Requirements

Services

0 services available

Loading...

Cybersecurity Compliance

Security Audit Requirements

Does an international certificate replace the statutory audit?

No. Certification is voluntary and has no force under Georgian law. For a subject of a critical information system the audit is required by law, and compliance with the requirements of its conclusion is mandatory.

Who conducts the information security audit?

By category: first — the Operational-Technical Agency (primary audit free of charge) or an organization authorized by the Digital Governance Agency; second — the same agency or an authorized organization; third — the Digital Governance Agency or an authorized organization; defence sphere — the Cyber Security Bureau.

What happens after the audit if defects are found?

The subject analyses them and defines an action plan with a schedule, submitted within 1 month of completion for approval to the respective agency. The agency assesses the plan and issues recommendations or binding instructions, and monitors implementation.

How is an auditor verified?

To conduct an audit or penetration test an organization must hold authorization from the Digital Governance Agency, and the employee personally conducting it must have passed a security check under the established procedure.

5 min·8 Feb 2026

Certification or the statutory audit

International certification standards for information security management systems are, in Georgia, a private and voluntary instrument: a certificate issued under them acquires no force whatsoever under the country's legislation. For a subject of a critical information system the audit is mandatory not because of a certificate but because of the law — the Law of Georgia on Information Security establishes the obligation to conduct a primary and periodic information security audit and a penetration test of the information system, the authorization regime for those who conduct them, and the mechanism for acting on their conclusions. On this page we explain what is legally required and what role voluntary certification can play alongside it.

The core concepts on which the audit is built

The law itself defines the concepts against which an audit conclusion is assessed. Information security is the activity ensuring the protection of the accessibility, integrity, authentication, confidentiality and continuous operation of information and information systems. The information security policy is the totality of norms and principles provided by the law, other normative acts and international agreements, corresponding to the international standards established in the field of protection. A cyberattack is an action where an electronic device or a network connected to it is used to violate, disrupt or destroy the integrity of systems, property or functions within a critical information system, or to obtain information unlawfully. A computer incident is an action carried out using information technology that causes or aims to cause a violation of the confidentiality, integrity or accessibility of information. A critical information system is an information system whose continuous functioning is significant for the country's defence or economic security, or for the normal functioning of state power or society.

Who must undergo the audit: the scope of the law

The law applies to the subject of a critical information system and to any organisation subordinate to or connected with the subject through employment, internship, contractual or other relations that, within those relations, ensures access to an information asset. The list of subjects is approved by a government decree which classifies them according to defined criteria: the severity and scale of the probable consequences of the system's disruption or failure; the probable economic loss for the subjects or the state; the necessity of the service provided by the system for the normal functioning of society; the number of users of the system; and the subject's material condition and probable costs. The law does not apply to mass media, editorial offices of publishers, scientific, educational, religious and public organisations and political parties. Any legal entity that is not a subject has the right voluntarily to assume the obligations arising from the law — a route that creates a stricter legal regime than voluntary certification. A commercial bank that is not a subject is governed by the rules and requirements established by the National Bank.

The audit and the penetration test: who, how and afterwards

The subject is obliged to conduct a primary and a periodic information security audit — an assessment of the conformity of the security management system with the minimum standards. After the audit a conclusion is drawn, the requirements of which are mandatory. The conduct of the audit is distributed across categories: for a first-category subject the primary audit is conducted free of charge by the Operational-Technical Agency, and the periodic audit selectively by the same agency or by an organisation authorized by the Digital Governance Agency (payment, securities settlement and reserve management systems, and critical systems used for monetary and currency operations, are excepted from this requirement); for a second-category subject the audit is conducted by the Operational-Technical Agency or an authorized organization; for a third-category subject — by the Digital Governance Agency or an authorized organization; and in the defence sphere — by the Cyber Security Bureau. The procedure and periodicity of the audit are established by orders of the respective agencies, and the fee by contract.

In parallel, the subject must ensure that a penetration test is conducted according to a pre-planned and documented task; after the test a conclusion is drawn whose requirements are likewise mandatory. Where the audit reveals nonconformity, or the test reveals weaknesses, the subject analyses them and defines an action plan with a schedule, which is submitted within 1 month of completion for approval to the respective agency — commercial banks submit the plan to the National Bank. The agencies ensure the assessment of the plan, the elaboration of recommendations or binding instructions, and monitoring of the agreed plan's implementation. An audit or test is conducted in cooperation and coordination with the information security manager or the computer security specialist.

The authorization regime for auditors

A private organization has the right to conduct an audit or a penetration test only if it has passed authorization at the Digital Governance Agency under the procedure established by the chairperson's order; the fee for passing authorization is set under a separate law. The employee who personally conducts the audit or test must have passed a security check under the procedure established by a normative act of the head of the State Security Service. A candidate organization must satisfy the security requirements and employ staff holding the corresponding authority. For commercial banks an additional list of organizations authorized to conduct audits may also exist, which the National Bank submits to the Digital Governance Agency.

Our service

If your organization is a subject of a critical information system or intends voluntarily to assume the obligations, we help you choose the correct regime: we determine which audit is mandatory and who is entitled to conduct it, verify the auditor's authorization, and assist in responding to conclusions and action plans within the established terms. A decision on voluntary certification we assess alongside the statutory requirements — so that it is not a redundant expense but a supplement.

Updated: 18 Sep 2026

Find a Specialist

Professionals working in this field

Technology & Digital Law LawyerTechnology & Digital Law AttorneyTechnology & Digital Law Personal data protection officer