BillBuddy
Back to bill feed
Local GovernmentHealthAgriculture
BillSBN-208520th Congress

Cybersecurity Act

In committee Filed May 4, 2026
◷ Where it standsIn Committee
FiledCommittee2nd Reading3rd ReadingBicamEnacted

Filed on May 4, 2026, and referred to the Committees on Science and Technology, Civil Service, Government Reorganization and Professional Regulation, and Finance; it has been pending in committee since then with no recorded action.

Should you care?
Relevance to you
Broad

The bill addresses increasing cybersecurity threats as the country digitizes.

Cybersecurity stakeholdersBusiness establishmentsGovernment institutions
Timeliness
Timely

The bill responds to the urgent need for improved cybersecurity measures due to rising cyber incidents.

Affects you ifGovernment agenciesPrivate corporationsCybersecurity professionalsGeneral public
Impact assessment
AI read — verify with source
Overall impact
7.5/ 10
Long title

Cybersecurity Act

Plain-language summary
AI Summary

The Cybersecurity Act aims to strengthen the national cybersecurity system by institutionalizing the National Cybersecurity Council and enhancing protections against cyber threats.

What this bill actually requires
RequiresInstitutionalizes the National Cybersecurity Council under the Office of the President.
RequiresRequires government and private entities to report data breaches within 24 to 72 hours.
RequiresMandates the formulation of a National Cybersecurity Plan.
FundsInitial implementation costs to be charged against current appropriations of concerned departments/agencies.
FundsSubsequent funding to be included in the annual General Appropriations Act.
PenalizesImprisonment of 6 months to 2 years or a fine of up to ₱1,000,000 for failure to report data breaches.
Deadline90 days for implementing rules and regulations after approval of the Act.
Deadline15 days after publication for the Act to take effect.
ⓘ AI-generated — verify with the source.↗ Official Senate PDF
What changes from current law

Compared with current law:

Today

No formal cybersecurity governance structure exists.

This bill

Establishes the National Cybersecurity Council to oversee cybersecurity efforts.

Today

No standardized reporting for data breaches.

This bill

Mandates reporting of data breaches within 24 to 72 hours.

Today

No comprehensive cybersecurity plan in place.

This bill

Requires the formulation of a National Cybersecurity Plan.

ⓘ AI-generated comparison — verify against the bill and the cited law.
Ask this bill

The Cybersecurity Act aims to strengthen the national cybersecurity system by institutionalizing the National Cybersecurity Council and enhancing protections against cyber threats.

Source · full text
Issue areas
Local GovernmentHealthAgricultureCybersecurityNational Cybersecurity CouncilDigital transformationData Breach Reporting

✦ Dashed tags are AI-suggested nuance; solid tags follow the committee taxonomy.

Legislative history
May 4, 2026Senate
Introduced by Senator ERWIN T. TULFO;
May 6, 2026Senate
Read on First Reading and Referred to the Committees on SCIENCE AND TECHNOLOGY; CIVIL SERVICE, GOVERNMENT REORGANIZATION AND PROFESSIONAL REGULATION and FINANCE;
✦ AI insight

Stalled: the bill has sat in committee for over five months with no action since it was referred on May 6, 2026.

Tap a term to decode it
Floor activity

No floor deliberations yet — this measure has not reached plenary. Its committee-stage actions appear under Legislative history above.

Full text
SBN-2085 — verbatim textAs filed

Senate Office of the Secretarp TWENTIETH CONGRESS OF THE 26 MAY -4 P3:27 REPUBLIC OF THE PHILIPPINES First Regular Session ) RECEIVED BY: SENATE 2085 Senate Bill No. _ Introduced by Senator Erwin T. Tulfo AN ACT STRENGTHENING THE NATIONAL CYBERSECURITY SYSTEM BY INSTITUTIONALIZING EXECUTIVE ORDER NO. 95, AND ENHANCING PROTECTION AGAINST CYBER THREATS, AND FOR OTHER PURPOSES EXPLANATORY NOTE The Philippines is undergoing a rapid digital transformation, driven by the expansion of e-governance, digital banking, e-commerce, and the increasing use of online platforms by Filipinos in their daily lives. Government initiatives such as digital public services, online financial transactions, and interconnected critical systems have significantly improved efficiency and accessibility. However, this growing dependence on information and communications technology has likewise heightened our country's exposure to cybersecurity threats. In recent years, the Philippines has experienced a surge in cyber incidents, including data breaches affecting government databases, ransomware attacks, online fraud, disinformation campaigns, and intrusions targeting critical information infrastructure such as energy, telecommunications, transportation, and financial systems. These incidents not only disrupt essential services but also erode public trust, compromise sensitive personal data, and threaten national security.

The bill aims to institutionalize and enhance the National Cybersecurity Council by ensuring a unified leadership in cybersecurity governance, improving inter-agency coordination, and establishing clear standards for the protection of government systems and critical digital assets. A key feature of the measure is the formulation of a National Cybersecurity Plan, which will serve as the country's strategic blueprint for safeguarding cyberspace. Ultimately, this proposed legislation aims to strengthen the country's cybersecurity posture by establishing a resilient, coordinated, and forward-looking framework that is responsive to evolving digital threats. In view of the foregoing, the immediate passage of this bill is earnestly sought. ERW IN T. TULFO

Senate Difice of the Sorcretarp TWENTIETH CONGRESS OF THE MAY -4 P3:27 REPUBLIC OF THE PHILIPPINES First Regular Session RECEIVED BY: SENATE Senate Bill No. 2085 Introduced by Senator Erwin T. Tulfo AN ACT STRENGTHENING THE NATIONAL CYBERSECURITY SYSTEM BY INSTITUTIONALIZING EXECUTIVE ORDER NO. 95, AND ENHANCING PROTECTION AGAINST CYBER THREATS, AND FOR OTHER PURPOSES Be it enacted by the Senate and the House of Representatives of the Philippines in Congress assembled:

SECTION 1. Short Title. - This Act shall be known as the

2 "Cybersecurity Act."

SEC. 2. Declaration of Policy. - It is hereby declared the policy

5 of the State to ensure the security, resilience, and reliability of the 6 country's information and communications technology (ICT) 7 infrastructure. The State recognizes cybersecurity as a critical component of national security, public safety, economic stability, and the protection of individual rights. Towards this end, the State shall develop and maintain a secure and resilient cyberspace by protecting critical information infrastructure, ensuring rapid and coordinated responses to cyber threats, and strengthening the capabilities of law enforcement and defense institutions.

SEC. 3. National Cybersecurity Council. - The National

2 Cybersecurity Inter-Agency Committee created under Executive Order 3 No. 95 (s. 2019) is hereby institutionalized, reorganized, and renamed 4 as the National Cybersecurity Council (NCC) under the administrative supervision of the Office the President.

SEC. 4. Reorganization of the National Cybersecurity Council. -

8 The NCC shall be chaired by the Secretary of the Department of 9 Information and Communications Technology (DICT) and co-chaired 10 by the Executive Secretary and the National Security Adviser and 11 Director General of the National Security Council (NSC), and shall further be composed of the following officials as members: a) Secretary of the Department of Foreign Affairs (DFA); b) Secretary of the Department of Finance (DOF); c) Secretary of the Department of Science and Technology (DOST); d) Secretary of the Department of Interior and Local Government (DILG); e) Secretary of the Department of Justice (DOJ); f) Secretary of the Department of Energy (DOE); g) Secretary of the Department of National Defense (DND); h) Secretary of the Department of Transportation (DOTr); i) Secretary of the Presidential Communication Operations Office (PCOO); j) Commissioner of the National Telecommunications Commission (NTC);

k) Director-General of the National Intelligence Coordinating Agency (NICA); 1) Director of the National Bureau of Investigation (NBI); m) Chief of the Philippine National Police (PNP); n) Chief of Staff of the Armed Forces of the Philippines; o) Chairman of the National Privacy Commission (NPC); P) Executive Director of the Anti-Terrorism Council- Program Management Center (ATM-PMC); q) Executive Director of the Cybercrime Investigation and Coordinating Center (CICC); and r) Governor of the Bangko Sentral ng Pilipinas (BSP) as members. The NCC shall have a secretariat to be headed by an Executive Director. The organizational structure and staffing pattern of the secretariat shall be formulated by the Secretary of the DICT, subject to the approval of the Department of Budget and Management (DBM) in accordance with Executive Order No. 292, otherwise known as the "Administrative Code of 1987." The NCC may invite concerned public and private agencies or entities to participate, complement, and assist in the performance of its functions. The NCC shall collaborate with the Anti-Terrorism Council (ATC) on matters relating to cyber-terrorism.

SEC. 5. Power and Functions. - The NCC shall be the main

authority to exercise powers and functions that would address all cybersecurity-related matters. It shall perform the following functions:

a) Formulate and implement a National Cybersecurity Plan pursuant to Section 7 of this Act; b) Assess the vulnerabilities of the country's cybersecurity; c) Implement capacity building measures for the purpose of responding to Cybersecurity threats and emergencies; d) Issue updated security protocols to all government employees involved in the storage, handling and distribution of all forms (digital, electronic, snail mail, etc.) of documents and communications, following best practices. These protocols shall be updated periodically and, as necessary, in light of the rapid developments in information and communications technology. e) Enhance the public-private partnership in the field of information sharing involving cyberattacks, threats and vulnerabilities to cyber threats; f) Conduct periodic strategic planning and workshop activities that will reduce the country's vulnerabilities to cyber threats; g) Direct its member agencies and appropriate agencies to implement cybersecurity measures as may be required by the situation; h) Serve as the country's coordinating arm on domestic, international, and transnational efforts pertaining to cybersecurity; i) Make such recommendations and/or such other reports as the president may from time to time direct; and j) Perform such other functions as may be necessary.

SEC. 6. Meetings of the Council. - The NCC shall hold regular

meeting every quarter and such special meetings as may be necessary upon the request of the chairman or at least two (2) of its members.

SEC.7. National Cyber Security Plan. - The NCC shall

6 formulate, adopt, and periodically update a National Cybersecurity 7 Plan (NCP), which shall serve as the comprehensive framework for safeguarding the country's cyberspace. The NCP shall include, but not 9 be limited to, the following components: a) Identification and protection of critical information infrastructure; b) National risk assessment and threat monitoring mechanisms; c) Cyber incident prevention, detection, response, and recovery protocols; d) Roles and responsibilities of government agencies and stakeholders; e) Capacity-building, workforce development, an d public awareness programs; f) Mechanisms for public-private sector collaboration; g) International cooperation and information sharing strategies; h) Standards, compliance, and regulatory frameworks for cybersecurity; and i) Periodic evaluation and performance metrics.

SEC. 8. Report of Data Breach. - Government institutions,

2 agencies, instrumentalities, including government-owned and 3 controlled corporations, all private corporations, companies, and business establishments, operating wholly or partly in the Philippines, 5 are required to report to the NCC, within 24 to 72 hours, all kinds of 6 data breaches occurring in their jurisdiction. Provided, That the NCC 7 shall conduct training on cybersecurity to all stakeholders for the 8 effective implementation of this Act. Failure to make the required report shall be penalized with 11 imprisonment of not less than six (6) months but not more than two (2) years or a fine of not more than P 1,000,000.00, or both at the discretion of the court. In case of penalty of imprisonment, the same shall be imposed on the officials or persons who are responsible for making the report, as determined in the implementing rules and regulations.

SEC. 9. Protection Against Insider Threats. - All government

agencies and Critical Information Infrastructure (CII) covered by this 19 Act shall implement measures to prevent, detect, and respond to insider 20 threats involving their employees, contractors, or other authorized users.

SEC. 10. Reportorial Requirement. - The NCC shall submit a

quarterly report, or as often as may be necessary, to the President of the Philippines and to Congress on the state of cybersecurity threats and other related information. The NCC may request an executive session from Congress if it may deem necessary.

SEC. 11. Implementing Rules and Regulations. - The DICT, the

DOJ, the DILG, and the NSC shall jointly formulate the necessary rules and regulations within ninety (90) days from approval of this Act, for its effective implementation.

SEC. 12. Appropriations. - The amount needed for the initial

implementation of this Act shall be charged against the current year's appropriations of the departments/agencies concerned. Thereafter, such

1 sums as may be necessary for the continued implementation of this Act 2 shall be included in the annual General Appropriations Act.

SEC. 13. Separability Clause. - Should any provision or part of

5 this Act be declared unconstitutional or invalid, the other provisions 6 and parts hereof, insofar as they are separable from the invalid ones, 7 shall remain in full force and effect.

SEC. 14. Repealing Clause. - All laws, decrees, executive orders,

10 issuances, rules, and regulations or parts thereof which are inconsistent 11 with this Act are hereby repealed or modified accordingly.

SEC. 15. Effectivity. - This Act shall take effect fifteen (15) days

after its publication in the Official Gazette or in at least two (2) newspapers of general circulation. Approved,

Reproduced from the Senate document. The official PDF is the authoritative version.