The Department of Information and Communications Technology (DICT) has ordered government agencies to conduct cybersecurity assessments at least once a year as more public services move online.
Department Circular No. HRA-008, series of 2026, requires Vulnerability Assessment and Penetration Testing (VAPT) annually, as well as after major system changes or cybersecurity incidents.
The requirement applies to national government agencies, government-owned and controlled corporations and their subsidiaries, state universities and colleges, local governments of host cities, and other government instrumentalities.
Operators of Critical Information Infrastructure, whose systems support essential government functions and public services, face additional cybersecurity obligations under the circular.
VAPT involves identifying weaknesses in systems, applications, and networks and determining how attackers could exploit them. The assessment is intended to help agencies address vulnerabilities before they result in data breaches, service disruptions, or other cyber incidents.
Government entities may conduct the assessments internally, provided they comply with DICT requirements, or hire providers accredited under the DICT Trusted Assessment Provider program.
The circular also sets deadlines for addressing identified vulnerabilities. Critical flaws must be fixed within five business days, while medium- and low-risk findings must be resolved within 30 business days.
The DICT said the requirements are intended to establish continuous security testing and faster remediation across the public sector.
The department maintains a list of accredited assessment providers on its D-TAP portal.


