Proposed Cybersecurity Bill 2026
PUBLIC CONSULTATION PORTAL
Proposed Cybersecurity Bill 2026
Have your say on Papua New Guinea’s proposed national cybersecurity framework
Welcome
The Government of Papua New Guinea invites public authorities, operators of essential services and critical infrastructure, financial institutions, telecommunications and digital service providers, cybersecurity professionals, law enforcement agencies, civil society organisations, academic institutions, development partners and members of the public to comment on the proposed Cybersecurity Bill 2026.
This portal is the official channel for submitting written comments on the Bill. It allows you to upload a submission, track what you have sent, and access the supporting consultation documents in one place.
About the Bill
The proposed Bill provides a comprehensive national framework for cybersecurity governance, protection of critical information infrastructure, cyber incident prevention and response, cybercrime investigation, online safety, and the regulation of cybersecurity services. It supports the objectives of the National Cyber Security Strategy 2024-2030.
The Bill adopts a risk-based approach: systems and services essential to national security, economic stability, public health, safety or continuity of government may be designated as critical information infrastructure and made subject to enhanced security, audit, incident-reporting and cooperation requirements. It also addresses protection of financial systems, child online safety and platform obligations, cybercrime investigation and digital evidence, incident reporting and emergency powers, and licensing of cybersecurity services.
Who should participate
We welcome submissions from anyone with an interest in the Bill, including:
- Government agencies and public authorities
- Operators of essential services and critical infrastructure
- Financial institutions and payment and mobile-money providers
- Telecommunications and digital service providers, and online platforms
- Cybersecurity professionals and service providers (auditing, penetration testing, digital forensics, managed security)
- Law enforcement agencies
- Civil society organisations and child-protection advocates
- Academic and research institutions
- Development partners
- Members of the public
What we would like your views on
Stakeholders are encouraged to comment on the practical effect of the proposed provisions, including their suitability for Papua New Guinea’s legal, constitutional, institutional, economic, social and technical circumstances. Submissions should be read alongside the Draft Cybersecurity Bill 2026 and the relevant drafting instructions, available for download below.
Key matters for comment include:
- Scope and application – whether the Bill clearly identifies the persons, systems, services, conduct and entities to which it applies, its territorial and extraterritorial reach, treatment of cloud and third-party environments, and whether key definitions are sufficiently precise.
- Institutional governance and accountability – whether the functions of the Minister, NICTA as interim Authority, the Board and CEO, the national coordination committee, PNGCERT, the Cybersecurity Operations Centre, the Child Online Safety Commissioner and the Royal Papua New Guinea Constabulary are clearly separated and capable of effective coordination.
- Critical information infrastructure – whether the designation process, security plans, minimum controls, audits, risk assessments and incident-reporting duties are proportionate and workable, including for supply-chain and cloud risks.
- Protection of financial systems – whether the proposed protections for banks, insurers, savings and loan societies, micro-finance institutions and payment providers align with the Bank of Papua New Guinea’s supervisory role and existing financial-crime frameworks.
- Child online safety and platform obligations – whether the restriction on social media accounts for children under 16, age-assurance requirements, limits on profiling and behavioural advertising, and harmful-content reporting and removal arrangements are clear, effective and proportionate.
- Cybercrime investigation powers and digital evidence – whether vesting investigation functions in the Constabulary’s Cybercrime Investigation Unit, alongside search and seizure, preservation orders, interception, chain of custody and admissibility safeguards, appropriately protects constitutional rights.
- Incident reporting and emergency powers – whether the proposed reporting thresholds and timeframes (including 24-hour notification) and the grounds, scope and oversight of emergency directions are workable, necessary and proportionate.
- Licensing of cybersecurity services – whether licensing should apply to all cybersecurity auditing, penetration testing, digital forensics and managed security services, or be limited initially to the most sensitive services, and whether the proposed eligibility and compliance requirements are proportionate.
- Implementation and legislative coherence – what commencement periods, transitional arrangements, regulations and capacity-development measures are required, and how the Bill interacts with the Constitution, the Cybercrime Code Bill 2016, the Evidence Bill 1975, the NICTA Act, financial-sector and child-protection laws, and the proposed Data Governance and Data Protection Bill 2026.
A central governance question is also open for comment: whether NICTA should perform the functions of National Cybersecurity Authority at commencement, which functions should be incubated within NICTA, and the safeguards, transition triggers and conditions that should apply before a standalone National Cybersecurity Authority is established.
How to Prepare your submission
To help us consider your comments effectively, please:
- Identify the specific provision, clause or subject you are addressing
- State your position clearly (support, oppose, or propose amendment)
- Explain the likely legal, operational, financial, technical or social effect of the proposal
- Where possible, suggest alternative wording or implementation options, including cost information or relevant international experience
- Provide supporting evidence or examples from your sector, where relevant
- Include your name or organisation, contact details, and whether your submission may be published or referenced
- Clearly mark any information you consider confidential, and explain why
How to submit your comments
- Register or sign in to the ICT Legislative Review Submission Portal using your name and email address.
- Select “New Submission” and choose the stakeholder category that best describes you.
- Upload your written submission (PDF or Word format) or complete the online comment form.
- Review your submission and confirm any confidentiality request.
- You will receive an email confirmation with a reference number for your records.
If you are unable to use the portal, submissions may be sent directly by email to ictsector_reset@nicta.gov.pg. Please quote the reference: Draft Cybersecurity Bill 2026 Consultation.
Key Dates
| Reference | Closing date for submissions |
| Draft Cybersecurity Bill 2026 Consultation | 19 August 2026 |
Submissions received after the closing date may not be considered. Late submissions can be sent to the contacts below with an explanation for the delay.
Confidentiality and use of submissions
Unless confidentiality is specifically requested and accepted, submissions may be treated as public consultation material and may be summarised, published or referred to in the final consultation report. If you wish any part of your submission to be treated as confidential, mark it clearly and provide reasons.
Personal information you provide will be handled in accordance with applicable privacy requirements and used only for the purposes of this consultation.
Related Documents
- Draft Cybersecurity Bill 2026
- Drafting instructions for the proposed Cybersecurity Bill 2026
- Papua New Guinea National Cyber Security Strategy 2024-2030
- Public Consultation Notice – Introductory Statement and Matters for Stakeholder Comment
Documents are available for download in the “Resources” section of this portal.
Submissions and enquiries
A joint Technical Working Group has been established by the Department of Information and Communications Technology (DICT) and the National Information and Communications Technology Authority (NICTA) to assess, review and develop the policies, strategies, legislation and regulatory instruments required to support the broader ICT sector reform programme. The current legislative review and drafting process is coordinated through the Technical Working Group.
All submissions, enquiries and requests for clarification should be directed through the ICT Legislative Review Submission Portal, or by email:
Email submissions and enquiries: ictsector_reset@nicta.gov.pg
NICTA contact
Ms Lillian Smith — Manager, Research and Emerging Technology
Email: lsmith@nicta.gov.pg
Department of ICT contacts
Mr Thomson Simon — Manager, Policy Development
Email: thomson.simon@ict.gov.pg
Mr Pokana Nouari — Manager, Policy Planning and Implementation
Email: pokana.nouari@ict.gov.pg
This notice has been prepared principally with reference to the drafting instructions and policy framework for the proposed Cybersecurity Bill 2026, and the Papua New Guinea National Cyber Security Strategy 2024-2030.
