The House of Representatives has approved on second reading a bill seeking to establish a National Cybersecurity Agency (NCSA) and impose cybersecurity requirements on government institutions and operators of critical information infrastructure.
House Bill No. 9605, or the proposed “National Cybersecurity and Critical Information Infrastructure Protection Act of 2026,” cleared second reading on July 28, according to the House’s legislative records.
The measure would place the NCSA under the Office of the President and transfer to it the cybersecurity functions, personnel, assets, records, and funding of the Department of Information and Communications Technology’s Cybersecurity Bureau.
The proposed agency would serve as the government’s primary policy-making, coordinating, implementing, and administrative body for cybersecurity. It would be authorized to issue baseline operational directives and compel covered entities to act on cybersecurity concerns.
HB 9605 would cover national government agencies, government-owned and controlled corporations, government financial institutions, state universities and colleges, local government units, and public and private operators of critical information infrastructure.
Entities supplying cybersecurity products, services, or solutions to the government or critical infrastructure operators would also fall within the measure’s coverage.
The NCSA would identify and designate critical information infrastructure using a risk-based approach. A designation would remain effective for five years unless withdrawn earlier.
Critical infrastructure operators would be required to conduct cybersecurity risk assessments at least once every three years and submit an authenticated audit and risk assessment report from an NCSA-recognized firm at least once every two years. They would also be required to maintain continuous monitoring, asset management, and vulnerability management processes.
Operators must notify their government regulator and the NCSA, through the National Computer Emergency Response Team, upon discovering critical or high-risk cybersecurity incidents. Moderate-risk incidents must likewise be reported, while data breaches must be referred to the National Privacy Commission.
The bill would also require operators affected by attacks that restrict access to ICT systems or data to disclose whether they paid a ransom or complied with the attacker’s demands.
Government agencies, GOCCs, and LGUs would be required to adopt risk-based cybersecurity measures aligned with internationally recognized standards, including ISO/IEC information security and resilience standards.
Covered entities would also have to create or designate a chief information security officer to oversee their cybersecurity programs and lead their respective government computer emergency response teams. The NCSA and DICT may designate regional or group CISOs for agencies unable to create a dedicated position.
The bill authorizes the NCSA to develop a cybersecurity certification and scoring system for services, suppliers, and technologies. It would also establish a National Vulnerability Disclosure Program through which security researchers could responsibly report weaknesses in government systems.
Unauthorized disclosure of confidential information involving critical infrastructure would be punishable by imprisonment of six years and one day to 12 years, a fine of at least P2 million, or both.
Critical infrastructure operators that willfully or negligently violate NCSA orders or cybersecurity requirements could face administrative fines. Depending on their annual income and the violation, penalties may reach P5 million or between 1% and 2% of gross annual income.
The bill states that its provisions must be interpreted with “the highest respect for human dignity, human rights, and individual privacy.” It also expressly excludes content regulation, opinion monitoring, and speech analysis from the NCSA’s authority to collect open-source information for technical threat intelligence.
HB 9605 was recommended under Committee Report No. 423 as a substitute for 28 cybersecurity and critical infrastructure measures filed in the 20th Congress. It must still secure approval on third and final reading before it can be transmitted to the Senate.


