Start with applicability
The Protection of Critical Infrastructures (Computer Systems) Ordinance came into operation on 1 January 2026. The Commissioner’s published FAQ describes how authorities approach organisations that may be designated. Do not assume that every Hong Kong business has the same duties; confirm designation and scope with the responsible authority or legal adviser.
Prepare a supplier incident handoff
In this operational example, a software supplier supports a customer whose system is under review. The supplier records facts and escalates through the agreed channel. The table does not assign legal status, reporting thresholds or statutory deadlines.
| Handoff item | Evidence to prepare |
|---|---|
| Affected service | System name, environment, customer contact and current impact |
| Known event timeline | Detection time, observed changes and actions already taken |
| Access and recovery | Authorised responders, preserved logs and tested recovery options |
Separate an operator’s duties from vendor work
A software supplier may be asked to support a customer’s security, evidence or incident procedures. The contract should state which systems are covered, what access is permitted and how incidents are escalated. A vendor questionnaire does not by itself establish the supplier’s legal status under the regime.
Prepare an operational evidence trail
Use the applicable requirements to identify system owners, access records, changes, recovery procedures and incident contacts. Test how that information can be retrieved during a real problem. Reporting duties and deadlines require the current official materials and legal assessment, rather than a generic timer copied into an engineering plan.
Before you proceed
- Confirm whether and how the organisation is within scope.
- Read the current Code of Practice with the responsible adviser.
- Align vendor access and incident responsibilities in writing.



