Friday, August 14, 2026

House approves bill creating National Cybersecurity Agency

The House of Representatives has approved on third and final reading a bill creating a National Cybersecurity Agency (NCSA) and imposing cybersecurity requirements on government institutions and operators of critical information infrastructure.

House Bill No. 9605, or the proposed “National Cybersecurity and Critical Information Infrastructure Protection Act of 2026,” secured final House approval on Aug. 12, two weeks after the opening of the second regular session of the 20th Congress.

The measure, identified as a priority of the Legislative-Executive Development Advisory Council, will now be transmitted to the Senate for consideration.

The proposed NCSA would be placed under the Office of the President and serve as the government’s primary policy-making, planning, coordinating, implementing, and administrative body for cybersecurity.

It would absorb the cybersecurity functions, personnel, assets, records, and funding of the Department of Information and Communications Technology’s Cybersecurity Bureau.

The agency would be authorized to issue baseline cybersecurity directives, coordinate the government’s response to cyberattacks, and require covered entities to address identified security risks.

HB 9605 covers national government agencies, government-owned and controlled corporations, government financial institutions, state universities and colleges, local government units, and public and private operators of critical information infrastructure.

It also covers suppliers of cybersecurity products, services, and solutions to the government and critical infrastructure operators.

The bill requires covered organizations to adopt cybersecurity standards and establishes certification systems for service providers, technologies, and cybersecurity professionals.

Critical infrastructure operators would have to conduct cybersecurity risk assessments at least once every three years and submit authenticated audit and risk assessment reports from NCSA-recognized firms at least once every two years.

They would also be required to maintain continuous monitoring, asset management, and vulnerability management systems and report critical, high-risk, and moderate-risk cybersecurity incidents to the appropriate regulator and the NCSA.

Operators affected by ransomware and similar attacks that restrict access to ICT systems or data must disclose whether they paid a ransom or complied with the attackers’ demands.

Government agencies and critical infrastructure operators would also be required to designate a chief information security officer to oversee their cybersecurity programs.

The bill authorizes the NCSA to establish a certification and scoring system for cybersecurity services, suppliers, and technologies, as well as a National Vulnerability Disclosure Program through which security researchers may report weaknesses in government systems.

Unauthorized disclosure of confidential information involving critical infrastructure would be punishable by imprisonment of six years and one day to 12 years, a fine of at least P2 million, or both.

Critical infrastructure operators that willfully or negligently violate cybersecurity requirements or NCSA orders may face administrative fines of as much as P5 million or between 1% and 2% of their gross annual income, depending on the violation.

The measure states that the NCSA’s powers must be exercised with respect for human rights, individual privacy, and human dignity. It also excludes content regulation, opinion monitoring, and speech analysis from the agency’s authority to collect open-source information for technical threat intelligence.

HB 9605 cleared second reading on July 28 and was recommended under Committee Report No. 423 as a substitute for 28 cybersecurity and critical infrastructure bills filed in the 20th Congress.

- Advertisement -spot_img

RELEVANT STORIES

spot_img

LATEST

- Advertisement -spot_img