Kyrgyzstan’s Law on Personal Information (No. 58 of 2008) requires personal-data holders to register with the State Agency for Personal Data Protection, and the Law on Cybersecurity (No. 121 of 2024) brings critical information infrastructure under state coordination. Neither names a standard. An ISO 27001 ISMS is the practical way to evidence security to regulators and enterprise customers alike.
Kyrgyzstan’s framework rests on two instruments a generation apart. The Law of the Kyrgyz Republic “On Personal Information” No. 58 of 2008, amended in 2021 and 2022, is the data-protection statute. The Law “On Cybersecurity of the Kyrgyz Republic” No. 121 of 17 July 2024 is the new layer: critical information infrastructure categorisation, incident response, and state coordination of cybersecurity.
| Instrument | Regulator | What it asks of you |
|---|---|---|
| Law “On Personal Information” No. 58 of 2008 | State Agency for Personal Data Protection, under the Cabinet of Ministers (established 22 December 2021) | Protect personal data; appear on the mandatory register of personal-data holders |
| Law “On Cybersecurity” No. 121 of 2024 | State coordination structure, with the Coordination Centre on Cybersecurity as national CERT under the State Committee for National Security | Critical information infrastructure categorisation and incident response |
The register is the visible obligation. The State Agency maintains a mandatory register of personal-data holders, so the regulator has a map of who processes what. Being on the register is administrative: it tells the state who you are, not whether your systems would hold up under attack. The security substance sits behind it, and the law describes it in duties, not standards — no clause in either instrument names ISO 27001 or any certificate.
Two honest gaps are worth stating plainly. There is no mandatory breach-notification regime or deadline in the legislation. And the 2024 law is young: its critical-infrastructure categorisation and coordination machinery are still bedding in. Neither gap means the bar is low — it means the bar is unwritten, which is harder to evidence, not easier.
Three practical reasons, none of them regulatory box-ticking.
Enterprise customers ask first. Security questionnaires from international customers and partners don’t soften because Kyrgyz law is quiet — a certificate answers in one line what would otherwise take a forty-page questionnaire per deal.
Groups spanning Central Asia want one system. If your Kyrgyz operation belongs to a wider group, one ISMS can carry Kyrgyz sites inside a multi-country scope. That’s cheaper to operate than a standalone certificate and keeps controls consistent across borders.
The 2024 law points one direction. Critical-infrastructure categorisation and a national CERT mean incident response is now a legal topic in Kyrgyzstan, not just operational hygiene. Organisations that can already show monitoring and incident management running will find that conversation short.
| Kyrgyz obligation | Where the ISMS answers it |
|---|---|
| Personal-data protection duties (Law No. 58) | Risk assessment across the 93 Annex A controls, applicability recorded in the Statement of Applicability, and evidence the applicable controls run |
| Mandatory register of personal-data holders | The ISMS is the substance behind the registration — when the regulator looks past the entry, there’s an operating system to find |
| CII categorisation and incident response (Law No. 121) | Monitoring and incident management with records ready for coordination through the national CERT |
Certification is typically delivered by internationally accredited certification bodies operating regionally. The audit follows the standard shape — Stage 1 documentation review, Stage 2 interviews and evidence, then annual surveillance and recertification every three years — and audit fees are set by the certification body, varying with size and scope. It is never performed by Secure60.
Where your data should live is driven by your contracts, sector and group policy; take legal advice for your specific case. What the ISMS does is record where data lives and under whose control, so the answer is written down before anyone asks. Secure60 has delivery infrastructure in Kyrgyzstan via Rackcorp, with 2 datacentres, so collection and monitoring can run in-country where that’s expected.
Regional groups leave Kyrgyzstan outside the certificate. The group certifies headquarters, scopes the ISMS to the main market, and treats the Kyrgyz entity as too small to bother with. Then the register entry, a customer questionnaire and the 2024 law’s categorisation questions all land on the one entity with no evidence behind it.
The fix costs little. Bringing a Kyrgyz operation inside an existing multi-country ISMS scope is a fraction of the work of a standalone certificate — the policies, risk method and management system already exist; what’s added is local assets, local risks and local evidence. Scope it in at the next surveillance cycle rather than waiting for the question you can’t answer.
We build and operate the ISMS — controls, logging, monitoring, incident response — on one security platform, with delivery infrastructure in Kyrgyzstan via Rackcorp so evidence and monitoring can stay in-country. For groups, we fold Kyrgyz operations into a multi-country scope rather than building an island. The certification audit belongs to an internationally accredited certification body operating in the region; our job is making sure everything it samples is real and running. We’re ISO 27001:2022 certified ourselves and hold our own system to the same test.
Is ISO 27001 legally mandatory in Kyrgyzstan?
No. Neither the Law on Personal Information (No. 58 of 2008) nor the 2024 Cybersecurity Law names a standard or a certificate. Certification is the practical way to evidence security duties to the regulator, and the way enterprise customers expect to see them evidenced.
Do we have to register as a personal-data holder?
The State Agency for Personal Data Protection, established under the Cabinet of Ministers in December 2021, maintains a mandatory register of personal-data holders. Registration is administrative — it puts you on the regulator’s map; it doesn’t evidence that your systems are secure.
Is there a breach-notification deadline in Kyrgyzstan?
No — the legislation sets no mandatory notification regime or deadline. Detection still matters: the 2024 Cybersecurity Law builds a state incident-response and coordination structure, and customers and group policies usually impose their own reporting clocks.
Who performs the ISO 27001 certification audit in Kyrgyzstan?
Certification is typically delivered by internationally accredited certification bodies operating regionally — never by Secure60. Audit fees are set by the certification body and vary with the size and scope of what’s being certified.
Can Secure60 deliver in Kyrgyzstan?
Yes — we have delivery infrastructure in Kyrgyzstan via Rackcorp, with 2 datacentres, so log collection and monitoring can run in-country. We don’t have local offices, and we never perform the certification audit.