MONGOLIAN LAW
December 17, 2021
State Palace, Ulaanbaatar city
ON THE AMENDMENT TO THE CODE ON ADMINISTRATIVE OFFENSES
Article 1. Article 14.13 with the following content shall be added to the Code on Administrative Offenses:
"Article 14.13. Violation of the Law on Cybersecurity
1.If the legal entity fails to perform the relevant cyber security inspection for each newly introduced information
technology product or service or their change or update, the legal entity shall be fined in the amount of three hundred
units.
2. If the legal entity fails to immediately notify the affected users of cyber attacks or violations, the legal entity will be
fined one thousand units.
3. If an information security audit or cyber security risk assessment is not performed at the request of the competent
authority, or if the information security audit or cyber security risk assessment report is not submitted to the relevant
authority within the period specified by law, the legal entity shall be fined one thousand units.
4. If a legal entity does not have an information system to detect, register, or stop cyber attacks or violations, or does
not connect to a qualified cyber attack or breach response center, a legal entity shall be fined two thousand units.
5. If the information security audit or cyber security risk assessment report is disclosed, the legal entity shall be fined
ten thousand units.
6. In case of failure to comply with the requirements set by the competent authority regarding cyber security, the legal
entity with critical information infrastructure shall be fined in the amount of ten thousand units.
Article 2. This Law shall be enforced from the date of entry into force of the Law on Cybersecurity.
G. ZANDANSHATAR,
CHAIRMAN OF THE STATE GREAT KHURAL (PARLIAMENT) OF MONGOLIA