Chile's National Cybersecurity Agency published the second preliminary list of Vital Importance Operators, adding hundreds of entities to the enhanced regime of Law No. 21,663. Which sectors does it cover, what are the deadlines and what obligations does it entail?

On April 24, 2026, the National Cybersecurity Agency (ANCI) published in the Official Gazette (Diario Oficial) the resolution approving the second preliminary list of Vital Importance Operators (OIV), corresponding to the second stage of the first designation process begun in 2025. With it, the pool of organizations that could become subject to the enhanced cybersecurity regime of Law No. 21,663 (Ley N° 21.663) grows significantly: the preliminary list includes hundreds of public and private institutions that provide essential services.

For many companies, this is no longer a distant issue. Being placed on the list is not a minor formality: it marks the start of a demanding set of digital security obligations.

What is a Vital Importance Operator?

Law No. 21,663, which establishes the cybersecurity framework and creates ANCI, singles out essential services and, within them, Vital Importance Operators: entities whose disruption would have a significant impact on the security or functioning of the country. That designation is what triggers the highest standard of obligations.

Sectors added by the second list

The second stage covers essential services provided by entities in strategic sectors, including:

  • Transportation, storage or distribution of fuels.
  • Drinking water supply and sanitation.
  • Land, air, rail or maritime transportation and its infrastructure.
  • Public service concessionaires.
  • Administration of social security benefits.
  • Postal and courier services.
  • Production and research of pharmaceutical products.

Added to these are entities from sectors already covered in the first stage that had not been included before, such as power generation and distribution, telecommunications, digital infrastructure, IT services, healthcare providers and State agencies.

Deadlines: 30 days to submit comments, plus a public consultation

Entities included in the preliminary list have 30 calendar days from publication to submit comments and supporting records, as provided in the law’s implementing regulations, Supreme Decree No. 285 of 2024 (Decreto Supremo N° 285 de 2024). The resolution also orders the start of a public consultation on the list, for which ANCI is making an electronic platform available. This is the key moment for an organization that believes it should not be designated, or that needs clarifications, to assert its arguments before the final list is issued.

What designation as an OIV entails

Entities that are ultimately designated will be subject to enhanced cybersecurity obligations, including:

  • Implementing a cybersecurity risk management system.
  • Maintaining incident detection and response capabilities.
  • Adopting business continuity measures and the applicable certifications.
  • Reporting cybersecurity incidents to the National CSIRT within short deadlines.

Failure to comply with these obligations can lead to penalties, in addition to the operational and reputational risk posed by an unmanaged incident.

What to do now

If your organization belongs to any of these sectors, it is advisable to act without waiting for the final list: check whether it appears on the preliminary list, assess whether to submit comments within the 30-day window, and begin diagnosing the gap between current practices and what Law No. 21,663 requires. Acting early makes it possible to spread costs more evenly and to be prepared when the obligations take effect.

Official information about the process is available on the website of the National Cybersecurity Agency.

Through our Cybersecurity and Computer Crime practice we support companies preparing for this new standard, from diagnosis to incident management.


This article is general and informational in nature and does not constitute legal advice for any specific case. The regulations cited should be checked in their current version before making decisions.