[Home](/)/[Resources](/resources)/HK Cybersecurity Ordinance for Products

Hong KongCybersecurity

# HK Protection of Critical Infrastructures (Computer Systems) Ordinance: IoT Product Implications

Hong Kong's 2024 PCICO changes the procurement calculus for every IoT device, industrial controller, and network appliance sold into the city's critical sectors. Your customers — energy utilities, banks, hospital networks, telecoms — now have statutory supply chain security obligations. If you cannot satisfy their compliance requirements, you are off the shortlist.

Copy Link[Share on WhatsApp](https://wa.me/?text=https%3A%2F%2Fkrono-labs.com%2Fguides%2Fhong-kong-cybersecurity-ordinance-products)

At a glance

Ordinance

Protection of CI (Computer Systems) Ordinance (2024)

Sectors

8 critical infrastructure sectors

Incident report

12 hours (initial) / 48 hours (full)

Regulator

Commissioner of Police — Cybersecurity Division

## PCICO Framework: What Product Suppliers Need to Understand

### Protection of Critical Infrastructures (Computer Systems) Ordinance — Scope and Eight Sectors

Hong Kong's Protection of Critical Infrastructures (Computer Systems) Ordinance (PCICO), enacted in 2024, establishes a mandatory cybersecurity framework for operators of critical infrastructure across eight designated sectors: energy, information technology, banking and finance, land transport, air transport, maritime, healthcare, and communications. The Ordinance is modelled on international critical infrastructure protection frameworks including Singapore's Cybersecurity Act and the EU NIS2 Directive, adapted to Hong Kong's regulatory architecture. Each sector has a designated regulatory authority that interfaces with the Commissioner of Police Cybersecurity Division — for example, the Hong Kong Monetary Authority (HKMA) for banking and finance, and the Office of the Communications Authority (OFCA) for communications. Hardware and software suppliers serving organisations in these sectors are directly affected by their customers' new statutory obligations.

### Critical Computer Systems and Critical Infrastructure Operators: Definitions That Matter

The Ordinance introduces two definitions that product suppliers must understand. A Critical Computer System (CCS) is a computer system designated by the Chief Executive or a sector regulator as essential to the continuous operation of critical infrastructure — this covers not just servers and networks but also operational technology (OT) systems, industrial control systems (ICS), and supervisory control and data acquisition (SCADA) systems. A Critical Infrastructure Operator (CIO) is an entity that owns or operates a CCS. CIOs are placed on a register maintained by the Commissioner of Police Cybersecurity Division and are subject to the full suite of PCICO obligations. If your IoT devices, embedded controllers, or network equipment are integrated into systems that a CIO designates as a CCS, your products fall within the scope of their supply chain security obligations.

### CIO Incident Reporting Obligations and the Downstream Pressure on Suppliers

CIOs face legally mandated incident reporting timelines that create urgent downstream requirements for their suppliers. On becoming aware of a cybersecurity incident affecting a CCS, a CIO must submit an initial notification to the Commissioner of Police Cybersecurity Division within 12 hours, followed by a full incident report within 48 hours. These compressed timelines mean that CIOs cannot afford delayed information from hardware or firmware vendors. Product suppliers should expect contractual requirements to maintain 24/7 incident response contacts, commit to notification windows for discovered vulnerabilities, and provide root-cause analysis support within the CIO's 48-hour reporting window. Suppliers who cannot meet these requirements will be disadvantaged in procurement decisions for CI-connected projects.

### Supply Chain Security Obligations: What CIOs Must Now Require from Hardware Vendors

The PCICO explicitly requires CIOs to assess and manage cybersecurity risks arising from their supply chains, including hardware vendors, software providers, and managed service providers. This obligation is not advisory — failure to conduct adequate supply chain risk assessment is a compliance gap that can be cited in enforcement action by the Commissioner of Police Cybersecurity Division. In practice, this translates into formal vendor security assessments, questionnaire-based due diligence, contractual cybersecurity representations, and for high-criticality systems, independent security audits of supplier products. IoT device manufacturers, embedded systems vendors, and industrial hardware suppliers selling into HK critical infrastructure sectors should proactively prepare supply chain security documentation packages to satisfy CIO procurement requirements.

### Software Bill of Materials (SBOM) as an Emerging Expectation

While PCICO does not yet mandate SBOM submission by name, the supply chain security risk assessment obligation creates the practical conditions where CIOs will demand component-level visibility into firmware and software embedded in their critical systems. SBOM — a machine-readable inventory of all software components, libraries, and dependencies in a product — has become the standard mechanism for demonstrating supply chain transparency in the US (via Executive Order 14028) and is referenced in the EU Cyber Resilience Act. Hong Kong critical infrastructure operators, particularly those operating in banking (HKMA-regulated) and communications (OFCA-regulated) sectors, are already extending their vendor questionnaires to request SBOM documentation. Suppliers who cannot produce an SBOM for their firmware stack are increasingly flagged as high-risk vendors in CI procurement evaluations.

### Commissioner of Police Cybersecurity Division: Regulatory Authority and Enforcement Powers

The PCICO vests regulatory authority in the Commissioner of Police, acting through a dedicated Cybersecurity Division. This is a notable structural choice — unlike other jurisdictions that establish an independent cybersecurity agency (such as Singapore's CSA or the UK's NCSC), Hong Kong routes critical infrastructure cybersecurity oversight through the police apparatus. The Commissioner has powers to designate CCSs, register CIOs, issue directions on cybersecurity risk management, receive incident reports, conduct inspections of CIOs' cybersecurity arrangements, and impose financial penalties for non-compliance. The Cybersecurity Division also acts as the national CERT-equivalent for critical infrastructure, which means that vulnerability reports from product vendors may be routed through or notified to the Division when they affect CCSs. Product suppliers should be aware that disclosures involving CCS-connected products may attract law enforcement interest.

## Preparing Your Products for HK Critical Infrastructure Procurement

01

Map your product portfolio against the eight PCICO critical infrastructure sectors — identify which products are sold into energy, banking, communications, healthcare, transport, or IT infrastructure in Hong Kong, and flag those customer accounts for enhanced compliance engagement.

02

Review the PCICO CIO obligations in detail — specifically the supply chain security risk assessment requirement — and prepare a gap analysis of what cybersecurity documentation your current sales and support processes can produce on request.

03

Prepare a cybersecurity documentation package for critical infrastructure customers: security architecture overview, network segmentation guidance, vulnerability management policy (including patch release timelines), supported end-of-life dates, and known-vulnerability status against current CVE databases.

04

Develop and publish a Software Bill of Materials (SBOM) for firmware and embedded software components in your products, formatted in a machine-readable standard (SPDX or CycloneDX) — this positions your products ahead of the SBOM disclosure curve in HK CI procurement.

05

Establish a coordinated vulnerability disclosure (CVD) program with a published security advisory policy, a dedicated security contact address (e.g. security@yourdomain.com), and defined response timelines — CIO customers will need to know how quickly you respond to newly discovered vulnerabilities.

06

Brief your sales, key account, and pre-sales engineering teams on the PCICO CIO cybersecurity questionnaire requirements that customers in regulated sectors will now present — ensure the team can provide accurate, documented answers rather than ad hoc responses.

07

Review your own incident response plan to ensure it covers cybersecurity events affecting products deployed in HK critical infrastructure — establish internal escalation procedures and a documented process for notifying affected CIO customers within a timeline compatible with their 12-hour / 48-hour regulatory reporting obligation.

08

Document your security testing methodology for products deployed in CI environments: penetration testing scope and frequency, static application security testing (SAST) and dynamic analysis (DAST) processes, third-party security audit history, and certification history (e.g. IEC 62443 for industrial control systems).

## Frequently asked questions

### What is the HK Protection of Critical Infrastructures Ordinance?

The Protection of Critical Infrastructures (Computer Systems) Ordinance (PCICO) is Hong Kong legislation enacted in 2024 that establishes mandatory cybersecurity obligations for operators of critical infrastructure in eight designated sectors: energy, IT, banking and finance, land transport, air transport, maritime, healthcare, and communications. CIOs must register with the Commissioner of Police Cybersecurity Division, implement cybersecurity risk management measures, report cybersecurity incidents within 12 hours (initial notification) and 48 hours (full report), and conduct supply chain security risk assessments covering their hardware and software vendors.

### Does the HK Cybersecurity Ordinance apply to hardware suppliers?

The PCICO directly regulates Critical Infrastructure Operators (CIOs), not their vendors. However, the Ordinance's supply chain security requirements mean that CIOs must now formally assess and manage cybersecurity risks from third-party suppliers including hardware manufacturers, IoT device vendors, and industrial control system suppliers. This creates indirect but significant compliance pressure on suppliers: expect contractual cybersecurity representations, vendor security questionnaires, SBOM requests, and security audit requirements as conditions of doing business with CIO customers in Hong Kong's regulated sectors.

### What is the incident reporting timeline under the HK CIO Ordinance?

CIOs must submit an initial incident notification to the Commissioner of Police Cybersecurity Division within 12 hours of becoming aware of a cybersecurity incident affecting a Critical Computer System. A full incident report must follow within 48 hours. These timelines are among the most compressed of any critical infrastructure cybersecurity regime globally and impose urgent requirements on CIO customers to receive timely information from their hardware and software vendors. Product suppliers to CI sectors should design their incident response processes to support these windows.

### What cybersecurity documentation do HK critical infrastructure operators require from vendors?

Based on PCICO supply chain security obligations and emerging procurement practice in HK CI sectors, CIOs typically require from hardware vendors: a security architecture overview of the product, a vulnerability management and patch policy (including end-of-support dates), a current SBOM or component inventory for firmware, evidence of security testing (penetration test scope and date, SAST/DAST processes), a coordinated vulnerability disclosure policy with security contact details, and contractual commitments on vulnerability notification timelines. Vendors supplying industrial control systems may also be asked for IEC 62443 conformance evidence.

**Disclaimer:** Educational resource only. Regulatory requirements change. Consult a qualified compliance specialist before making decisions.

🇭🇰 Hong Kong roadmap for your product

Every standard, document, and test that applies — free, no account required.

See your free roadmap

Learn this properly

In-depth course that teaches the full process, not just this one answer.

[Start the course — $149](/courses/62-hong-kong-ofca-radio-equipment-certification)[Prefer to read? Get the book — $34.99](/books/62-hong-kong-ofca-radio-equipment-certification)

Related guides

*   [HK Critical Infrastructure CybersecurityHong Kong Protection of Critical Infrastructures (Computer Systems) Ordinance (PCICO) 2024: 8 critical sectors, CI operator obligations, supply chain security under CIRMP, Commissioner of Police enforcement, and what electronics hardware suppliers into HK CI need to know.](/guides/hong-kong-critical-infrastructure-cybersecurity)
*   [Hong Kong PDPOHong Kong PDPO Cap. 486 for connected hardware: the six Data Protection Principles, direct marketing restrictions, and cross-border transfer obligations.](/guides/hong-kong-data-privacy-pdpo)
*   [Hong Kong Telecommunications OrdinanceHong Kong Telecommunications Ordinance Cap. 106: dealer licensing and OFCA type approval for network terminal equipment.](/guides/hong-kong-telecommunications-ordinance)
*   [Japan IoT Cybersecurity for Connected ProductsJapan's IoT security framework for connected hardware: METI IoT-SSF, MIC guidelines, Telecommunications Business Act terminal obligations, default password and firmware update rules, and JPCERT/CC vulnerability disclosure.](/guides/japan-cybersecurity-iot-connected-products)
*   [EU NIS2 Directive for HardwareNIS2 Directive (EU) 2022/2555 extends cybersecurity obligations to manufacturers of connected products and critical infrastruct…](/guides/eu-nis2-directive-hardware)