COMPLIANCE — LAW 21,663 AND ANCI
Access control and compliance with Law 21,663 (ANCI)
ANCI designated 915 vital-importance operators in December 2025 (Res. Ex. N°87: 147 in electricity and 29 in telecommunications) and reached 1,154 with Res. Ex. N°187 of July 2026. Such an operator must run an ISMS, appoint a cybersecurity delegate and report incidents: early warning within 3 hours, an update within 72 hours and a final report within 15 days. Of all that, access control is the easiest evidence to ask for and the hardest to improvise.
From the legal duty to the file you hand over.
| Obligation | Control in Octoberus | Evidence produced | Frequency |
|---|---|---|---|
| Designation as a vital-importance operator — Res. Ex. N°87 (17 Dec 2025) designated 915 operators, 147 in electricity and 29 in telecommunications; Res. Ex. N°187 (24 Jul 2026) took the list to 1,1541 | Inventory of critical facilities with their zones, doors and owners, from day one. | List of facilities under access control, with the date each was added. | On designation |
| Law 21,663 art. 8 — duties of a vital-importance operator: information security management system and operational continuity plans2 | Physical and logical access events enter the same ISMS file, organised around the critical asset. | Access report per critical asset, signable by the cybersecurity delegate. | Per ISMS |
| Law 21,663 art. 9 and its regulation — incident reporting: early warning within 3 hours, update within 72 hours and final report within 15 days2 | Access timeline for the affected asset, with immediate export of people, permits and openings. | Evidence package for the early warning and for the final report. | Per incident |
| ANCI General Instruction N°3 — appointment and duties of the cybersecurity delegate3 | A “delegate” role with read access to all access evidence, across every facility, with no operating permissions. | Report the delegate can sign, with declared scope and period. | Permanent |
| ANCI General Instruction N°4 — containment measures during an incident: restrict access, block exposed remote access and change administrative passwords3 | Bulk revocation per facility, role or person in one click, pushed to the door and to the system. | Revocation log with time, owner and scope. | Per incident |
| ISO/IEC 27001:2022 A.5.15, A.5.18 and A.7.2 — access control, access rights and physical entry controls (the law requires an ISMS; the reference standard is ISO 27001)4 | Role matrix per facility and zone, grants and removals with an approver, and a dated access review. | Role matrix and access review record, both exportable. | Planned review |
Honesty about what the rules do not say yet.
The basic-standards rule does not exist yet
ANCI has not yet published the basic cybersecurity standards rule: the public consultation closed in June 2026. We will publish the definitive mapping once it exists. In the meantime we map to ISO/IEC 27001:2022 and to the Coordinator’s Cybersecurity Standard (source: anci.gob.cl).
Automatic incident reporting to ANCI: module in development
Today we produce the access evidence package for the affected asset in minutes and you attach it to the report. Automatic submission to the ANCI platform is a module in development: we do not sell it as available.
We do not issue certifications
We map our controls to Law 21,663, to the ANCI General Instructions, to ISO/IEC 27001:2022 and to the Coordinator’s standard, and hand you the evidence. Designation as a vital-importance operator is made by ANCI through an exempt resolution, and certification is issued by a third party. We do neither.
Frequently asked questions
How do I know whether we are a vital-importance operator? +
The designation is made by ANCI through an exempt resolution and published in the Diario Oficial. Check Res. Ex. N°87 of December 2025 —915 operators, 147 in electricity and 29 in telecommunications— and Res. Ex. N°187 of July 2026, which took the list to 1,154. Both are on anci.gob.cl.
Does ANCI request access evidence on a fixed schedule? +
The law gives it inspection and audit powers; the cadence will be set by its instructions. We design the evidence to be ready when it is requested, not for a calendar that does not exist yet.
What about incident reporting? +
During an incident the evidence package for the affected asset —who entered, when, under which permit, what was revoked and at what time— is assembled in minutes, in time for the early warning. Automatic submission to ANCI is a module in development; today you file the report yourself with our export.