ISO/IEC 27001:2022 · Law 21,663

Information
Security

The management system certified by ISO 27001 is the same one Law 21,663 requires of an Operator of Vital Importance. You build it once.

The programme in four minutes

What it includes and how it is priced

The three requirements a single system resolves, the deadlines an incident opens up, the five phases of the work and how to request your proposal from this very page.

1080p · 3:57 · with voice-over and subtitles Download the video

Why this programme

The law no longer asks whether you want a management system

Until 2024, implementing ISO 27001 in Chile was a commercial decision: it opened tenders and reassured corporate clients. Law 21,663 changed that for part of the market. Its article 8(a) requires Operators of Vital Importance to implement «a continuous information security management system». It is not a recommendation or a good practice: it is a duty whose infringement the law itself classifies as serious.

 1,154 organisations already designated as Operators of Vital Importance

The ANCI closed its first qualification process in two stages: 915 entities in December 2025 and 239 more in July 2026, among them companies in energy, fuels, water, transport, banking, health and telecommunications. The qualification is neither applied for nor refused: it arrives by resolution published in the Diario Oficial, and the deadlines start running that day.

And here is the part almost nobody says out loud: the law does not require ISO 27001. It names neither that standard nor any other — we checked it against the official text, its regulations and the ANCI's four general instructions. What it demands is the system, not the certificate. ISO 27001 is the most recognised way of building it and evidencing it, which is why we work with it; but certification does not replace it, and anyone who promises you otherwise is selling you peace of mind, not compliance.

What a single system covers

The standard

ISO/IEC 27001:2022 — clauses 4 to 10 and 93 Annex A controls
ISO/IEC 27002:2022 — implementation guidance for those controls
ISO/IEC 27005 — risk management methodology

The legal duties that rest on it

Law 21,663, art. 8(a) — the continuous ISMS
Law 21,663, art. 8(c) — continuity and cybersecurity plans
Law 21,663, art. 8(i) — cybersecurity officer
Law 21,663, art. 9 — incident reporting to the ANCI

The personal data layer

Annex A, control 5.34 — privacy and PII protection
Law 21,719, art. 14 quinquies — security measures
For the full privacy system, see ISO 27701

What leaves no room for improvisation

The Deadlines of Article 9

An incident with significant effect triggers four obligations against the clock. If the protocol, the roles and the channels are not defined and rehearsed before, failure to comply is almost inevitable.

  1. 3 horas

    Alerta temprana

    All obliged entities

    art. 9 a)
  2. 72 horas

    Segundo reporte

    All obliged entities

    It drops to 24 hours if an Operator of Vital Importance sees the delivery of its essential service affected.

    art. 9 b)
  3. 7 días corridos

    Action plan

    Operators of Vital Importance only

    It is the deadline most often published wrongly: it is not 15 days, and it does not apply to everyone.

    art. 9, inc. penúltimo
  4. 15 días corridos

    Informe final

    All obliged entities

    They are counted from the early warning, not from the incident.

    art. 9 c)
The reporting threshold is lower than it looks
Article 27 of the law defines «significant effect» as interrupting an essential service, affecting people's health or compromising systems holding personal data. But the article 3 of Supreme Decree 295 adds two further cases: affecting the integrity or confidentiality of IT assets, and unauthorised entry into networks or systems — «even where this does not immediately affect the provision of the service». In practice, you have to report considerably more than reading the law alone suggests.
The third law

The Personal Data Layer

Law 21,719 does not live in a separate folder. Its security duty — article 14 quinquies — asks for exactly what Annex A already builds, so it is covered from inside the same ISMS. What it does not cover, we say below.

What the law requires

The pseudonymisation and encryption of personal data, which letter a) of the article names expressly

What holds it up
  • 8.11 data masking
  • 8.24 use of cryptography

The only two controls that Chilean law mentions by name, so excluding them in the Statement of Applicability has to be justified very well.

What the law requires

Permanent confidentiality, integrity, availability and resilience of the processing systems and services

What holds it up
  • 5.12 and 5.13 classification and labelling
  • 5.15 to 5.18 access control
  • 8.12 data leakage prevention
  • 5.14 information transfer

Classify first in order to protect proportionately: without classification, everything is protected the same and nothing is protected well.

What the law requires

The ability to restore availability and access quickly after a physical or technical incident

What holds it up
  • 8.13 information backup
  • 8.14 redundancia
  • 5.29 et seq. continuity

The same plans that are already tested for article 9 of Law 21,663. They are rehearsed once and serve both laws.

What the law requires

Regular verification, evaluation and assessment of the effectiveness of the technical and organisational measures

What holds it up
  • Clause 9: monitoring and measurement
  • Auditoría interna
  • Management review

It is the cycle that produces dated evidence, and without a date evidence proves nothing.

What the law requires

To prove, in an incident and in court, that the measures existed and worked — the burden of proof lies with the controller

What holds it up
  • 5.28 collection of evidence
  • 5.33 protection of records
  • 8.15 event logging

Without dated records, the defence comes down to a statement of intent.

What the law requires

To process the data only for as long as the purpose lasts, and to delete or anonymise it afterwards (art. 14 letter d)

What holds it up
  • 8.10 information deletion
  • 8.11 data masking
  • 8.33 test information

8.33 is the one most often overlooked: it is where real client data almost always turns up in test environments that nobody audits.

What the law requires

To extend the duty of secrecy to those who process data on behalf of the controller (art. 14 bis)

What holds it up
  • 5.19 to 5.22 supplier chain

Require it in the contract, verify it during the relationship and be able to end it if it stops being met.

Where ISO 27001 ends

Annex A control 5.34 requires identifying and meeting the applicable privacy and PII protection requirements. It is the door through which Law 21,719 enters the ISMS, and it is why the system cannot ignore it.

But a security control does not publish a processing policy, does not handle data subject rights within 30 calendar days, and does not run an impact assessment before starting to process. Those three duties — articles 14 ter, 11 and 15 ter — are privacy management, not security, and they do not come out of Annex A however hard you press it.

And where ISO 27701 begins

If the organisation processes personal data as part of its business — and not merely its own payroll — full compliance with Law 21,719 is built in the privacy programme, which sits on top of this same management system and reuses its context, its roles, its document control and its internal audit. One system, not two.

See the privacy and Law 21,719 programme
How we work

Five Phases, One Single System

They run through clauses 4 to 10 of the standard and, with them, the duties of article 8. Estimated duration of 4 to 8 months depending on the size and complexity of the organisation.

  1. Fase 1 of 5 Context and scope

    Analysis of the context and the interested parties, formal ISMS scope and a security policy approved by top management. Roles, committee and —if the organisation is an Operator of Vital Importance— appointment of the cybersecurity officer with the profile required by ANCI General Instruction No. 3, which expressly prohibits the role being held by whoever runs the IT area.

  2. Fase 2 of 5 Risks and Statement of Applicability

    Risk methodology in line with ISO 27005, inventory and valuation of information assets, risk assessment and treatment plan. The Statement of Applicability justifies every Annex A control that is excluded, and without it there is no certification.

  3. Fase 3 of 5 Annex A controls

    Policies and procedures across the four domains —organisational, people, physical and technological—, supplier management, access and asset management, secure development and control 5.34 on privacy and PII protection, which is the personal data layer inside the system.

  4. Fase 4 of 5 Continuity and incidents

    Operational and cybersecurity continuity plans, a reporting protocol with the four deadlines of article 9 and the containment measures of General Instruction No. 4. Timed drills: the 3-hour deadline is not met by reading a procedure for the first time.

  5. Fase 5 of 5 Performance, improvement and certification

    ISMS indicators, internal audit, management review with minutes and agreements, management of non-conformities and support through stages 1 and 2 of the certification audit, which is carried out by an independent accredited body.

What you can engage

Scopes of the Programme

The gap assessment can be engaged on its own. Below, the option of implementing all three regulations as a single management system, which costs less than running them apart.

ISO/IEC 27001:2022

Information Security

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%
Promotion

All three regulations

ISO 27001 + Law 21,663 + Law 21,719

One single project, not 3 por separado

  • Gap assessment Gap assessment
    −21%
  • Regulatory implementation Gap closure and evidence
    −20%
  • Gap assessment + implementation Both services, together
    −15%

How the value is determined

Proposals are quoted in UF, plus VAT. The value of each project comes from four factors:

  • Scope: which standards are included, and how many processes, systems and suppliers fall inside the management system.
  • Size and sites: people to interview, number of locations, and whether the scope spans more than one country.
  • Maturity: how much already exists —policies, records, controls in operation— and how much has to be built from scratch.
  • Timeline: the certification or compliance date you need, and the effort it takes to sustain it.
Find out what yours costs, today

Build your scope in the quote builder and get the proposal with figures in UF within 24 business hours. No meeting first, and no details needed until the end.

Build my quote
Next step

Let Us Discuss Your Scope

A 30-minute call, at no cost. If your organisation has been designated an Operator of Vital Importance, the first thing is to check which deadlines are already running — some are counted from publication of the list in the Official Gazette, not from the day you find out.

See Privacy Governance
Basket 0 products

Your basket is empty

Add regulatory documentation packs or plans
Complete purchase
Contact and payment details
1Contact
2Summary
3Payment
Add to basket?