Argentina's state cybersecurity regulation: 180 days to comply
Contents
Argentina's National Cybersecurity Center has issued a technical regulation requiring public agencies to put in place contingency policies and plans, inventories of their systems classified by criticality, backup data processing sites located no less than 1,500 kilometers (about 930 miles) from the primary site, and Tier 3 certification within a maximum of 20 months.
To draft it, they drew on standards that are well known in the field: FIPS 199, NIST SP 800-34, ISO 22301 and the Uptime Institute guidelines.
It is the first time Argentina's public administration faces formal technical requirements on this subject, and with measurable parameters rather than good intentions.
A turning point that went almost unnoticed
For years, digital transformation in the Argentine state advanced on the political will of each administration, on budgets that appeared and disappeared, and on standards that each agency defined as best it could. The result was a deeply uneven infrastructure: ministries with modern systems and resilient processes operating alongside agencies that could take days to come back online after a service outage.
The new regulation changes that logic. It defines precise technical requirements, measurable deadlines and mandatory testing mechanisms for the state's own digital infrastructure. This is not a set of recommendations; it is a text with operating parameters and certification obligations.
What the regulation establishes
The document is organized into four chapters covering the full contingency planning cycle: policy, plan, infrastructure and the role of the enforcement authority.
Contingency plan policy
Every agency covered by the rule has to produce a formal policy defining purpose, scope, roles, responsibilities and update mechanisms. The policy also has to set out the procedures for implementing it and designate an official responsible for its development.
It must provide for updates on a regular schedule and also in reaction to relevant events. And it works as the framework for building the system inventory and the individual contingency plans for each system.
Mandatory inventory and criticality classification
The regulation requires each agency to list all of its systems along with their dependencies: applications, data, infrastructure and vendors. The inventory has to be updated at least once a year, or sooner if there are significant events such as acquisitions or changes in architecture.
Each system has to be classified into one of three criticality levels: High, Medium or Low. The classification is modeled on FIPS 199, the US federal standard, and weighs the potential impact of an interruption across five dimensions: safety and life, continuity of citizen services, economic or operational impact, legal or regulatory exposure, and reputation.
The regulation itself offers examples that help clarify what falls into each level:
- High: citizen authentication platforms, central data centers of major ministries, energy or telecommunications providers, national banking systems.
- Medium: decentralized agencies, provincial registries, referral hospitals, public transport logistics operators.
- Low: internal administrative systems, non-critical public reference databases, duplicated systems with no direct effect on citizens.
This classification is the foundation everything else is built on. Recovery objectives, backup strategy, testing frequency and infrastructure requirements all depend on the level assigned to each system.
Contingency plan and disaster recovery plan
Every plan must include, at a minimum: formal scope, business impact analysis (BIA), backup and recovery strategy, roles and responsibilities with 24/7 emergency contacts, step-by-step playbooks, coordination with other areas, security measures during recovery, documentary records, a testing program, a review and approval mechanism, and a continuous improvement process.
One detail worth noting: playbooks have to be specific to the type of incident. The regulation explicitly mentions distinguishing between ransomware and physical destruction, in line with NIST SP 800-184. It's regulatory recognition of something the technical community already took for granted: ransomware stopped being an emerging threat some time ago and now warrants a protocol of its own.
Download the Regulation for the Implementation of Contingency Plans
The three technical requirements that change the game
1. A minimum geographic distance of 1,500 km
The backup data center has to sit within Argentine territory, no less than 1,500 kilometers from the primary data center. The reasoning is to avoid simultaneous exposure to disruptive events such as earthquakes, floods, prolonged regional outages or coordinated physical attacks.
For a primary infrastructure in Buenos Aires, that means looking north or to Patagonia. It's a decision that blends resilience engineering with an idea of digital sovereignty: replication cannot leave national territory.
The regulation also requires at least two independent communication links between the primary and backup sites, preferably fiber optic running along physically separate routes and contracted from different providers. It further recommends a third satellite or radio link for extreme contingencies.
That said, we think this requirement will be revised in the coming months, because it is incompatible with existing infrastructure once you put it on the table alongside the Tier 3 requirement.
2. Tier 3 certification within 20 months
This is the most demanding obligation. The backup data center has to be certified Tier 3 under ANSI/TIA-942 and the Uptime Institute guidelines, within a maximum of 20 months from the date the regulation takes effect.
What does Tier 3 involve?
- Annual availability of 99.982%, which works out to less than 1.6 hours of tolerated downtime per year.
- Concurrent maintainability: any critical component has to be isolable or removable for maintenance without interrupting operations.
- N+1 electrical redundancy with multiple distribution paths, UPS and generators.
- N+1 cooling redundancy with duplicated HVAC systems.
- Fire protection with early detection (VESDA, for instance) and automatic suppression using clean agents or water mist, per NFPA 75/76.
- Physical and logical security equivalent to the primary site: layered access control, CCTV, multi-factor authentication, network segmentation and continuous monitoring.
The number of Tier 3 certified data centers on Argentine soil today is fairly limited, and they are concentrated mostly in the private sector and in a handful of jurisdictions. Through technical means, the rule creates concentrated demand for a very specific kind of infrastructure.
3. Measurable recovery objectives
The regulation sets RTO (Recovery Time Objective) and RPO (Recovery Point Objective) targets differentiated by criticality:
Criticality | RTO | RPO |
|---|---|---|
High | Under 4 hours | Under 1 hour |
Medium | Under 24 hours | Under 4 hours |
Low | 1 to 5 days | Sampled backups |
These parameters stop being aspirational and become enforceable. For a High criticality system, it means that after an incident the agency has less than four hours to get back into operation and cannot lose more than an hour of data.
Mandatory recovery strategies by level
The regulation also defines the minimum architecture of the backup site according to criticality:
- High: hot site, with continuous replication and automatic or semi-automatic failover.
- Medium: hot or warm site, with incremental copies and snapshots.
- Low: cold site, operated through manual processes, or a backup scheme.
For critical data, synchronous replication is required where the RPO is close to zero. Where that isn't feasible, asynchronous replication is allowed with a documented RPO formally accepted by the agency.
Mandatory testing: from PDF to live drill
Here is where the cultural shift happens. Having the plan is no longer enough; you have to test it.
- High criticality: full annual DRP test, semiannual tabletop exercises, recovery tests from offline backups, and network failover tests.
- Medium criticality: full annual test, quarterly tabletops, and offline backup tests.
- Low criticality: consistency checks on backups through file sampling.
After each exercise, the agency has to produce a report with metrics and a remediation plan. That turns contingency planning, which for years was an annual paperwork exercise, into a continuous operational process with evidence and traceability.
Political and management implications
Beyond the technical reading, there are three political consequences worth watching.
First, the regulation sets a common floor. Until now, maturity in operational continuity depended heavily on the will of each administration. Under this rule, every agency covered shares a verifiable minimum, which narrows the gap between jurisdictions and between levels of government.
Second, it redefines the budget conversation. Tier 3 certification, electrical redundancy, diversified links and testing programs all carry real costs. Governments will have to decide whether to build their own infrastructure, contract colocation or adopt hybrid models. Budget discussions about cybersecurity move from optional to structural.
Third, it positions the National Cybersecurity Center as the technical authority. The regulation gives it concrete functions: issuing standardized BIA guidance and forms, passing complementary resolutions, publishing a training calendar and supporting agencies through implementation. That's an active role, not a purely normative one.
What a public decision-maker should be looking at today
If you run or advise an agency covered by the rule, there are five immediate actions the regulation makes hard to postpone:
- Identify the formal official (designated authority) responsible for the contingency plan policy.
- Start or audit the system inventory along with its dependencies.
- Classify each system as High, Medium or Low according to impact.
- Assess the current state of the backup site: location, distance, Tier level, connectivity and security.
- Design the annual testing program and the playbooks by incident type.
The 20-month clock for Tier 3 certification starts running from the effective date (June 11, 2026). The difference between the agencies that make it on time and those that don't will be decided in these first months, not in the home stretch.
The regulation raises the regulatory floor for Argentina's public digital infrastructure. For the first time there are measurable parameters, firm deadlines and certification obligations for something that until now was left to the judgment of each administration.
The interesting question is less whether the rule will be complied with than how each jurisdiction is going to finance, plan and execute the adaptation. Agencies that start now will arrive with room to spare. Those that wait for the final stretch will most likely arrive with higher costs and a real risk of non-compliance.
There's an additional reading here that shouldn't be missed: putting the state's critical infrastructure in order is a concrete opportunity to build a more reliable state, better prepared for what's coming.