National Cybersecurity Enhancement Act of 2026
Filed on March 9, 2026, and referred to the Committee on Science and Technology; it has been pending in committee since then with no recorded action.
The bill addresses the increasing threat of cyberattacks in the Philippines, which has seen a significant rise in incidents.
The bill responds to the urgent need for improved cybersecurity measures due to rising cyber threats.
National Cybersecurity Enhancement Act of 2026
The National Cybersecurity Enhancement Act of 2026 aims to establish the Philippine Cybersecurity Council and enhance the national cybersecurity framework to protect against cyber threats and attacks.
Compared with current law:
No formal cybersecurity council exists.
Creates the National Cybersecurity Council to oversee cybersecurity policies.
Cybersecurity breaches are reported inconsistently.
Mandates immediate reporting of breaches to the Council.
No structured mechanism for public awareness of cyber threats.
Establishes a public advisory system for major cyber threats.
The Act aims to establish the Philippine Cybersecurity Council and enhance the national cybersecurity framework to protect against cyber threats and attacks, ensuring public safety and national security.
Source · full text✦ Dashed tags are AI-suggested nuance; solid tags follow the committee taxonomy.
Stalled: the bill has sat in the committee for over six months with no action since its referral on March 10, 2026.
No floor deliberations yet — this measure has not reached plenary. Its committee-stage actions appear under Legislative history above.
Senate 5 offer of the ducatarp TWENTIETH CONGRESS OF THE REPUBLIC OF THE PHILIPPINES ) ) 26 MAR -9 P4:12 First Regular Session RECEIVED BY: SENATE S. No.1946 Introduced by Senator JV Ejercito AN ACT ESTABLISHING THE PHILIPPINE CYBERSECURITY COUNCIL AND ENHANCING THE NATIONAL CYBERSECURITY FRAMEWORK EXPLANATORY NOTE It is widely recognized that the Philippines lacks a robust cybersecurity system, leaving both government agencies and businesses vulnerable to cyberattacks. According to the ASEAN Innovation Business Platform (AIBP), the country faces significant challenges, including phishing attacks, malware and ransomware threats, inadequate protection of data and user privacy, and outdated technology. A critical factor exacerbating these issues is the shortage of skilled cybersecurity professionals, which limits the country's ability to prevent, detect, and respond effectively to cyber threats!. Notably, the Philippines has experienced a dramatic surge in cyberattacks and cybercrimes, with a 432.75% increase in Philippine-based websites affected between 2021 and 20222. In Metro Manila alone, it rose to 152% in the first half of 2023. According to DICT, the majority of these incidents targeted government emergency response systems (61%), the academe (13%), and the telecommunications sector ' Koh, E. (2025, April 18). Cybersecurity talent shortages in the Philippines - ASEAN Innovation Business Platform - AIBP. ASEAN Innovation Business Platform - AIBP. https://www.aibp.sg/articles/strengthening-cybersecurity-in- the-philippines 2 Department of Information and Communications Technology [DICT]. (2024, February). National Cyber Security Plan 2023 - 2028. Department of Information and Communications Technology. Retrieved February 5, 2026, from https://dict.gov.ph/national-cyber-security-plan?q=national%20cybersecurity%20plan
(8%). Studies show that the country is specifically at risk of cyberattacks due to the extensive use of the internet, low cybersecurity awareness, and an underdeveloped cybersecurity infrastructure?. To address these threats, the DICT is mandated to formulate and implement the National Cybersecurity Plan (NCSP), which has helped mitigate some of these issues since its initial publication. Nevertheless, significant cybersecurity gaps remain between the Philippines and its regional counterparts, highlighting the urgent need for strengthened policies, improved infrastructure, and the development of a skilled cybersecurity workforce to better protect the nation from evolving digital threats. Despite improvements in the country's Global Cybersecurity Index (GCI) ranking, fraudulent threats are still experienced by many Filipinos. A report states that the rankings depict significant improvement, but the threats are evolving faster than the nation's cyber defenses. Provided that the Cybercrime Prevention Act of 2012 penalizes offenses committed in cyberspace and the Data Privacy Act of 2012 protects the information of Filipinos, these are insufficient in preventing cyberattacks. Given these circumstances, this bill seeks to strengthen the country's defenses against cyberattacks and cybercrimes by establishing the National Cybersecurity Council, empowered to lead inter-agency coordination and enhance the capacities of both the Department of Information and Communications Technology (DICT) and the Cybercrime Investigation and Coordinating Center (CICC). The measure also introduces a structured mechanism for reporting cybersecurity breaches and establishes a cyber incident registry to keep citizens informed of major threats or ongoing attacks that could compromise public welfare or critical services. Furthermore, the bill promotes transparency and accountability among government agencies by ensuring proper coordination in the prevention, monitoring, and response to cyber incidents, thereby safeguarding national digital infrastructure and public trust. The passage of this bill will not only enhance the protection of Filipino citizens but also strengthen the country's competitiveness in digital technology, ensuring that 3 Dacanay, David John & Quinto, Michael & Parayno, Juan & Fajutagana, Jeriel. (2024). A Comparative study of in a Global Cybersecurity Context and its Implications on Local Cybersecurity Practices. 10.13140/RG.2.2.30104.00008. 4 David, M. I. (2025, June 27). PH cybersecurity: How safe are we? Manila https://mb.com.ph/2025/06/25/ph-cybersecurity-how-safe-are-we
the state keeps pace with the rapid emergence of new cyber threats while promoting improvements in cybersecurity infrastructure and public awareness. In light of the foregoing, the immediate passage of this legislation is earnestly sought. JV EJERCITO
SenatE Difice of the Bructory TWENTIETH CONGRESS OF THE REPUBLIC OF THE PHILIPPINES ) 26 MAR -9 P4:12 First Regular Session ) SENATE RECEIVED BY: S. No. 1946 Introduced by Senator JV Ejercito AN ACT ESTABLISHING THE PHILIPPINE CYBERSECURITY COUNCIL AND ENHANCING THE NATIONAL CYBERSECURITY FRAMEWORK Be it enacted by the Senate and the House of Representatives of the Philippines in Congress assembled:
Section 1. Short title. - This Act shall be known as the National Cybersecurity
Enhancement Act of 2026.
Sec 2. Declaration of Policy. - It is the policy of the State to protect the Filipino
people and the nation's institutions from all forms of cyber threats and attacks that endanger public safety, privacy, and national security. The State recognizes that access to safe and reliable cyberspace is a basic public right and a foundation of national progress. The State shall strengthen the country's capability to prevent, detect, and respond to cyber incidents by building a secure digital environment that upholds transparency, accountability, and the protection of personal data. It shall ensure that every Filipino whether an individual user, worker, or business is defended from online 12 abuse, fraud, exploitation, and misinformation. To this end, the government shall institutionalize a unified national 14 cybersecurity framework that promotes cooperation among public and private sectors, 15 enhances digital resilience, and guarantees that technology serves the welfare of the 16 people and the integrity of the Republic.
Sec 3. Creation of the National Cybersecurity Council. - There is hereby created
a National Cybersecurity Council, hereinafter referred to as the Council, which shall serve as the primary policy-making, coordinating, and monitoring body on all matters relating to cybersecurity, cyber-terrorism, and the protection of critical information infrastructure in the Philippines. The Council shall be attached to the Office of the President for policy direction and oversight and shall be chaired by the Secretary of the Department of Information and Communications Technology (DICT). The Executive Secretary and the Director 9 General of the National Intelligence Coordinating Agency (NICA) shall serve as Co- 10 Chairpersons. The Council shall be composed of the following members: a. Secretary of the Department of Foreign Affairs (DFA); b. Secretary of the Department of Science and Technology (DOST); C. Secretary of the Department of the Interior and Local Government (DILG); d. Secretary of the Department of Justice (DOJ; e. Secretary of the Department of National Defense (DND); f. Chairperson of the National Privacy Commission (NPC); g. Commissioner of the National Telecommunications Commission (NTC); h. Director of the National Bureau of Investigation (NBI); i. Chief of the Philippine National Police (PNP); and j. Executive Director of the Cybercrime Investigation and Coordinating Center (CICC). The Council shall coordinate closely with the Anti-Terrorism Council on matters involving cyber-terrorism and digital threats to national security, ensuring that preventive and investigative actions respect human rights and due process while maintaining the safety of the public and the integrity of the State. The Council may invite representatives from other public and private institutions, including the business sector, academe, and civil society organizations, to participate in meetings or consultations relevant to cybersecurity. The DICT Cybersecurity Bureau shall serve as the Secretariat of the Council and shall provide technical and administrative support necessary for the effective performance of its functions.
SEC. 4. Powers and Functions. - The Council shall formulate and implement a
2 unified national cybersecurity policy and ensure the protection of the country's information and communications technology systems, networks, and critical information infrastructure. It shall serve as the central authority for coordinating cybersecurity efforts across all government agencies and private institutions. In pursuit of this mandate, the Council shall have the following powers and functions: a. Policy Direction - Formulate, update, and oversee the implementation of the National Cybersecurity Plan and related strategies to strengthen digital resilience and public protection. b. Coordination and Monitoring - Coordinate all cybersecurity activities of national government agencies, local government units, government-owned or controlled corporations, and private sector partners, and monitor compliance with national cybersecurity standards. c. Cyber-Terrorism Prevention and Response - Coordinate with the Anti- Terrorism Council (ATC) and relevant law enforcement and defense agencies to prevent, detect, and respond to cyber-terrorism and digital threats that endanger public safety or national security. d. Incident Response - Oversee the establishment of a National Computer Emergency Response Team (NCERT) and ensure the continuous operation of the National Security Operations Center (NSOC) to respond to cybersecurity incidents. e. Capacity Building - Develop training, certification, and public education programs to raise cybersecurity awareness and skills among government employees, businesses, and the general public. f. Public Protection and Assistance - Establish a Public Cyber Complaint and Rapid Response Unit and a Cyber-Justice Assistance Desk to provide immediate help and free legal aid to citizens affected by cybercrimes, scams, and online exploitation. g. Partnerships and International Cooperation - Strengthen coordination with foreign governments, international organizations, and global cybersecurity networks for information exchange and joint capacity-building initiatives.
h. Standards and Accreditation - Recommend minimum cybersecurity standards, accreditation requirements, and risk-management protocols for both public and private ICT systems handling sensitive or personal data. i. Other Functions - Perform such other powers and duties as may be necessary to fulfill its mandate under this Act and other existing laws.
Sec 5. Meetings of the Council. - The Council shall meet at least once every
quarter to review the state of national cybersecurity, assess emerging threats, and evaluate the implementation of ongoing programs and policies. Special meetings may be convened by the Chairperson, or upon the written request 10 of any two (2) Co-Chairpersons, in cases of urgent cyber incidents, large-scale data 11 breaches, or threats to critical information infrastructure or national security. A majority of all the members of the Council shall constitute a quorum. Decisions shall be made by a majority vote of the members present. The Council may create technical working groups or subcommittees to focus on specific areas such as cyber-terrorism 15 prevention, data protection, financial security, or public complaint response. These 16 groups shall submit their reports and recommendations to the Council for approval. The Secretariat shall prepare the agenda, minutes, and documentation of all meetings and shall ensure that summaries of non-classified actions and resolutions are made available for public access, consistent with national security and data privacy laws.
SEC. 7. Reporting of Cybersecurity Breaches. - All government agencies,
government owned or controlled corporations, and private entities operating critical information infrastructure shall immediately report any cybersecurity breach, incident, or data compromise to the National Cybersecurity Council, through the Cybercrime Investigation and Coordinating Center and the National Computer Emergency Response Team. The initial report shall be made within twenty-four (24) hours from discovery of the breach and shall include basic details necessary to assess the nature, scope, and possible impact of the incident. A full report shall be submitted within seventy two (72) hours thereafter, unless otherwise extended by the Council for justifiable reasons. Entities handling personal or sensitive information shall also notify affected individuals and the National Privacy Commission (NPC) in accordance with the Data
1 Privacy Act of 2012. Failure to report a breach or the deliberate concealment of material information shall constitute gross neglect and may result in administrative, civil, or criminal liability under this Act and other applicable laws. The Council shall maintain a confidential National Cyber Incident Registry for classified data and a public advisory system that promptly informs citizens, without disclosing sensitive details, of major cyber threats or ongoing attacks that could endanger public welfare or essential services.
SEC. 8. Implementing Rules and Regulations. - The DICT, the DOJ, the DILG
9 and the NSC shall jointly formulate the necessary rules and regulations within ninety 10 (90) days from approval of this Act, for its effective implementation.
SEC. 9. Separability Clause. - If any provision of this Act is here invalid, the
other provisions not affected shall remain in full force and effect.
SEC. 10. Repealing Clause. - All laws, decrees, orders, rules and regulations
or other issuances or part thereof inconsistent with the provisions of this Act are hereby repealed accordingly.
SEC. 11. Effectivity. - This Act shall take effect fifteen (15) days after its
publications in the Official Gazette or in any two (2) newspapers of general circulation in the Philippines. Approved,
Reproduced from the Senate document. The official PDF is the authoritative version.