Digital Assets & Virtual Assets
Cryptocurrency Exchange Licensing in Hong Kong: The VASP Regime Explained
Hong Kong's Protection of Critical Infrastructures (Computer Systems) Ordinance is in force from 1 January 2026 — who's caught, the key duties, and a practical checklist.
Hong Kong's first dedicated critical-infrastructure cybersecurity statute is now in force. The Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) came into operation on 1 January 2026, creating binding obligations for designated operators of critical infrastructures in Hong Kong. Although the statutory duties fall primarily on designated CI operators, the regime will also affect technology, cloud, managed-service and other suppliers in practice, because CI operators are expected to manage cybersecurity risks in the systems and vendors that support their critical computer systems.
This guide explains who is caught, what the obligations are, the reporting deadlines that matter, and provides a practical compliance checklist.
The Ordinance establishes a Commissioner of Critical Infrastructure (Computer-system Security) with power to designate critical infrastructure operators (CI operators) and their critical computer systems (CCSs), and to enforce a statutory baseline of cyber-resilience obligations. It is supported by a Code of Practice issued in early 2026 that fleshes out how the obligations should be met.
Importantly, the regime regulates the security and continuity of computer systems — not personal data. It sits alongside, and does not replace, the Personal Data (Privacy) Ordinance. An organisation can be caught by both.
Two groups need to pay attention.
1. Designated CI operators. The regime focuses on essential services in eight sectors: energy; information technology; banking and financial services; air transport; land transport; maritime transport; healthcare services; and telecommunications and broadcasting services — as well as infrastructures for other critical societal or economic activities in Hong Kong. Designation is made by the Commissioner; being in one of these sectors does not automatically make you a CI operator, but organisations of scale in them should expect scrutiny and prepare.
2. Suppliers and service providers to CI operators. The statutory obligations fall primarily on designated CI operators, not on their suppliers directly. In practice, however, suppliers are affected — because CI operators are expected to manage the security of third parties whose systems support or connect with their critical computer systems, and the Code of Practice includes supply-chain and contractual expectations. If you sell technology, cloud or managed services to a CI operator, expect these obligations to reach you through your contracts, even though you are not directly regulated by the Ordinance.
A designated CI operator's duties fall into three groups.
The incident-reporting clock is short, and the timeline depends on severity:
Not every outage or data incident is reportable under the Ordinance. A reportable computer-system security incident must involve unauthorised access or another unauthorised act causing an actual adverse effect on a critical computer system. Pure technical failure, natural disaster, a mass power outage, a threat detected and contained in time, or a personal-data leak arising from human error are not, by themselves, computer-system security incidents — though separate PDPO or sectoral reporting obligations may still apply.
Meeting a 12-hour deadline is an operational discipline, not a drafting exercise. It requires pre-agreed escalation paths, a named accountable person, and templates ready before an incident — including coordination with any vendor whose system is involved.
Non-compliance can attract substantial fines — maximum fines of HK$500,000 or HK$5 million depending on the offence — with daily fines for certain continuing offences. Separate confidentiality offences may also attract criminal liability, including imprisonment. These sit alongside the Commissioner's investigation and direction powers. The reputational and operational consequences of a poorly handled incident typically exceed the fine.
Use the checklist below to assess readiness. CI operators should treat every item as a direct obligation; suppliers to CI operators should read it as the standard they will be contractually required to meet.
The most urgent groups are organisations likely to be designated CI operators, and technology, cloud and managed-service vendors that sell to them. For operators, the priority is governance, a Code-of-Practice-aligned security management plan, and a tested 12-hour incident-reporting capability. For suppliers, the priority is reviewing customer contracts now — before a renewal or an incident forces the issue — and understanding the obligations you are being asked to accept.
The most common gap is not technical: it is the inability to evidence governance and to meet the reporting clock. A security programme that cannot produce a report within 12 hours of a serious incident is not compliant in the way that counts.
Alan Wong LLP advises operators and their suppliers on critical-infrastructure cybersecurity compliance — readiness assessments, governance and security management plans, incident-response and reporting frameworks, and the supply-chain contract terms this regime drives in practice. We act both for businesses preparing for possible designation and for vendors negotiating these obligations into their customer agreements, including as part of our fractional in-house counsel service. To discuss your position or request a tailored version of this checklist, get in touch.
Disclaimer: This article is provided for general information only and does not constitute legal advice. It should not be relied upon as a substitute for specific legal advice on any particular matter. No solicitor-client relationship is created by your access to or use of this article. The law may change, and its application will depend on the specific facts and circumstances of each case. To the fullest extent permitted by law, we accept no responsibility for any loss or damage arising from reliance on this article.
A practical guide to AI governance and compliance in Hong Kong — the PCPD, HKMA and SFC expectations, plus a 13-point checklist for businesses adopting AI.

Hong Kong startup PDPO guide — privacy notices, direct marketing rules, employee data, cookies, breach response, and a practical compliance checklist for founders.