Skip to content
Octo Inc. — Access Control Unit
Octoberus ACCESS

COMPLIANCE — LAW 21,663 AND ANCI

Access control and compliance with Law 21,663 (ANCI)

ANCI designated 915 vital-importance operators in December 2025 (Res. Ex. N°87: 147 in electricity and 29 in telecommunications) and reached 1,154 with Res. Ex. N°187 of July 2026. Such an operator must run an ISMS, appoint a cybersecurity delegate and report incidents: early warning within 3 hours, an update within 72 hours and a final report within 15 days. Of all that, access control is the easiest evidence to ask for and the hardest to improvise.

Compliance map

From the legal duty to the file you hand over.

ObligationControl in OctoberusEvidence producedFrequency
Designation as a vital-importance operator — Res. Ex. N°87 (17 Dec 2025) designated 915 operators, 147 in electricity and 29 in telecommunications; Res. Ex. N°187 (24 Jul 2026) took the list to 1,1541 Inventory of critical facilities with their zones, doors and owners, from day one. List of facilities under access control, with the date each was added. On designation
Law 21,663 art. 8 — duties of a vital-importance operator: information security management system and operational continuity plans2 Physical and logical access events enter the same ISMS file, organised around the critical asset. Access report per critical asset, signable by the cybersecurity delegate. Per ISMS
Law 21,663 art. 9 and its regulation — incident reporting: early warning within 3 hours, update within 72 hours and final report within 15 days2 Access timeline for the affected asset, with immediate export of people, permits and openings. Evidence package for the early warning and for the final report. Per incident
ANCI General Instruction N°3 — appointment and duties of the cybersecurity delegate3 A “delegate” role with read access to all access evidence, across every facility, with no operating permissions. Report the delegate can sign, with declared scope and period. Permanent
ANCI General Instruction N°4 — containment measures during an incident: restrict access, block exposed remote access and change administrative passwords3 Bulk revocation per facility, role or person in one click, pushed to the door and to the system. Revocation log with time, owner and scope. Per incident
ISO/IEC 27001:2022 A.5.15, A.5.18 and A.7.2 — access control, access rights and physical entry controls (the law requires an ISMS; the reference standard is ISO 27001)4 Role matrix per facility and zone, grants and removals with an approver, and a dated access review. Role matrix and access review record, both exportable. Planned review
  1. 1 https://anci.gob.cl/noticias/anci-presenta-nomina-de-oiv-correspondiente-al-primer-procedimiento-de-calificacion/
  2. 2 https://www.bcn.cl/leychile/navegar?idNorma=1202434
  3. 3 https://anci.gob.cl/normativa/instrucciones/
  4. 4 https://www.iso.org/standard/27001.html
What we do not claim

Honesty about what the rules do not say yet.

01

The basic-standards rule does not exist yet

ANCI has not yet published the basic cybersecurity standards rule: the public consultation closed in June 2026. We will publish the definitive mapping once it exists. In the meantime we map to ISO/IEC 27001:2022 and to the Coordinator’s Cybersecurity Standard (source: anci.gob.cl).

02

Automatic incident reporting to ANCI: module in development

Today we produce the access evidence package for the affected asset in minutes and you attach it to the report. Automatic submission to the ANCI platform is a module in development: we do not sell it as available.

03

We do not issue certifications

We map our controls to Law 21,663, to the ANCI General Instructions, to ISO/IEC 27001:2022 and to the Coordinator’s standard, and hand you the evidence. Designation as a vital-importance operator is made by ANCI through an exempt resolution, and certification is issued by a third party. We do neither.

Frequently asked questions

How do I know whether we are a vital-importance operator? +

The designation is made by ANCI through an exempt resolution and published in the Diario Oficial. Check Res. Ex. N°87 of December 2025 —915 operators, 147 in electricity and 29 in telecommunications— and Res. Ex. N°187 of July 2026, which took the list to 1,154. Both are on anci.gob.cl.

Does ANCI request access evidence on a fixed schedule? +

The law gives it inspection and audit powers; the cadence will be set by its instructions. We design the evidence to be ready when it is requested, not for a calendar that does not exist yet.

What about incident reporting? +

During an incident the evidence package for the affected asset —who entered, when, under which permit, what was revoked and at what time— is assembled in minutes, in time for the early warning. Automatic submission to ANCI is a module in development; today you file the report yourself with our export.

Could you hand over your access evidence today?
Measure it in 10 minutes.

Free self-assessment →