Cyber security compliance in Papua New Guinea
Papua New Guinea's cyber rules are in transition. The Digital Government Act 2022 already sets binding rules for public bodies and the vendors who serve them, including where government data may be hosted. In August 2026 the government opened consultation on a Cybersecurity Bill and a Data Governance and Data Protection Bill, which would extend obligations to critical infrastructure and to personal data. This page sets out what is law today and what is proposed.
- Frameworks listed7
- Issuing bodies5
- Framework pages1
- Platform languagesEnglish and Arabic
- DeploymentSaaS, private cloud or on-premises
Cybersecurity and data protection frameworks in Papua New Guinea
Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.
Digital Government Act 2022
Public bodies. Government data in the in-country government cloud unless approved otherwise. Vendors running public networks outside the approved cloud commit an offence
Cybercrime Code Act 2016
Everyone
National Cyber Security Policy 2021
National policy setting up the cyber governance structure. It does not itself impose obligations on businesses
Cybersecurity Bill 2026 (draft)
Proposed: critical infrastructure designation, security plans, audits and 24-hour incident notification. Consultation opened August 2026
Data Governance and Data Protection Bill 2026 (draft)
Proposed: breach notification, cross-border transfer rules and sovereign hosting. Consultation in August 2026
Prudential standards BPS 251 (Business Continuity) and BPS 252 (Outsourcing)
Authorised financial institutions under the Banks and Financial Institutions Act 2000
ISO/IEC 27001
The reference standard most organisations use to structure a security programme while PNG's own regime develops
Open the framework page →Which cybersecurity rules apply in Papua New Guinea today?
For government and its suppliers, the Digital Government Act 2022. For everyone, the Cybercrime Code Act 2016. For banks and financial institutions, the Bank of Papua New Guinea's prudential standards, including business continuity and outsourcing, and a technology risk management guide the Bank published in 2025. The National Cyber Security Policy 2021 sets out the governance structure but does not itself bind businesses.
Where can government data be hosted?
In Papua New Guinea by default. Under the Digital Government Act 2022, the government's private cloud must be located in the country, and public bodies may store data offshore only with written approval. Operating a public body's network outside the approved government cloud without approval is an offence, with fines of up to K1,000,000 for a company, which reaches private vendors as well as agencies.
What is proposed for 2026?
Two draft bills went to consultation in August 2026. The Cybersecurity Bill 2026 would designate critical infrastructure and require security plans, audits and incident notification within 24 hours, with protections for banks, insurers and payment providers and NICTA as the interim national authority. The Data Governance and Data Protection Bill 2026 would add breach notification, cross-border transfer rules and sovereign hosting. Neither had been passed as of late September 2026.
Does PNG have a data protection law?
Not yet. The Constitution protects a right to reasonable privacy, and the draft Data Governance and Data Protection Bill 2026 would be the first dedicated statute. Sources describing an existing PNG data protection law are wrong.
Who handles cyber incidents?
Two bodies with different roles. The National Cyber Security Centre, set up under the Digital Government Act and overseen by DICT, protects government networks. PNGCERT, facilitated through NICTA, is the national CERT whose members include banks and mobile operators. Papua New Guinea also became a Party to the Budapest Convention on Cybercrime in 2026.
How GRCLens supports organisations in Papua New Guinea
GRCLens runs the Digital Government Act's hosting and security duties, Bank of PNG standards and ISO/IEC 27001 on one control model, and can add the Cybersecurity Bill's requirements as soon as they are final. It can be deployed fully on-premises inside Papua New Guinea, which fits the government cloud and sovereign hosting direction.
Official portals and publications
Cyber compliance in Papua New Guinea: common questions
Does Papua New Guinea have a data protection law?
Not yet. A Data Governance and Data Protection Bill 2026 went to consultation in August 2026 but had not been enacted as of September 2026.
Is PNG's Cybersecurity Bill 2026 law?
No, it is a draft. Consultation opened in August 2026, and we could not confirm it had passed as of September 2026.
Can government data be stored outside Papua New Guinea?
Only with written approval. Under the Digital Government Act 2022 the government cloud must be in PNG.
What is the difference between PNG's NCSC and PNGCERT?
The NCSC protects government networks under the Digital Government Act. PNGCERT is the national CERT, facilitated through NICTA, with banks and mobile operators among its members.
Sources
Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.

Run Papua New Guinea's frameworks on one platform
See GRCLens with your own frameworks loaded. Need hands-on help? Cyber security services in Fiji and the Pacific from Security Solution Consultants.