Kyrgyzstan’s Law on Personal Information (No. 58 of 2008) requires personal-data holders to register with the State Agency for Personal Data Protection, and the Law on Cybersecurity (No. 121 of 2024) brings critical information infrastructure under state coordination. Neither names a standard. An ISO 27001 ISMS is the practical way to evidence security to regulators and enterprise customers.
Kyrgyzstan’s framework rests on two instruments. The Law of the Kyrgyz Republic “On Personal Information” No. 58 of 2008, amended in 2021 and 2022, is the data-protection statute. The Law “On Cybersecurity of the Kyrgyz Republic” No. 121 of 17 July 2024 adds critical information infrastructure categorisation, incident response, and state coordination of cybersecurity.
| Instrument | Regulator | What it requires |
|---|---|---|
| Law “On Personal Information” No. 58 of 2008 | State Agency for Personal Data Protection, under the Cabinet of Ministers (established 22 December 2021) | Protection of personal data; entry on the mandatory register of personal-data holders |
| Law “On Cybersecurity” No. 121 of 2024 | State coordination structure, with the Coordination Centre on Cybersecurity as national CERT under the State Committee for National Security | Critical information infrastructure categorisation and incident response |
The register is the visible obligation. The State Agency maintains a mandatory register of personal-data holders, which gives the regulator a record of who processes what. Registration is administrative and establishes nothing about how the systems would perform under attack. The security substance sits behind it, described in duties rather than standards, and no clause in either instrument names ISO 27001 or any certificate.
Two features of the framework are worth stating directly. There is no mandatory breach-notification regime or deadline in the legislation. And the 2024 law is recent, with its critical-infrastructure categorisation and coordination machinery still being established. Neither means the requirement is light: the requirement is unwritten, which makes it harder to evidence rather than easier.
Enterprise customers ask first. Security questionnaires from international customers and partners are unaffected by the quietness of Kyrgyz law, and a certificate answers in one line what otherwise takes a forty-page questionnaire per deal.
Groups spanning Central Asia run one system. Where the Kyrgyz operation belongs to a wider group, one ISMS can carry Kyrgyz sites inside a multi-country scope. A shared scope is cheaper to operate than a standalone certificate and keeps controls consistent across borders.
The 2024 law establishes incident response as a legal topic. Critical-infrastructure categorisation and a national CERT mean incident response is now a matter of law in Kyrgyzstan. Organisations that can already demonstrate monitoring and incident management have the evidence that conversation requires.
| Kyrgyz obligation | Where the ISMS answers it |
|---|---|
| Personal-data protection duties (Law No. 58) | Risk assessment across the 93 Annex A controls, applicability recorded in the Statement of Applicability, and evidence the applicable controls run |
| Mandatory register of personal-data holders | The ISMS is the operating substance behind the registration entry |
| CII categorisation and incident response (Law No. 121) | Monitoring and incident management with records ready for coordination through the national CERT |
Certification is typically delivered by internationally accredited certification bodies operating regionally. The audit follows the standard sequence — Stage 1 documentation review, Stage 2 interviews and evidence, then annual surveillance and recertification every three years — and audit fees are set by the certification body, varying with size and scope. It is not performed by Secure60.
Where data should reside is driven by your contracts, sector and group policy, and warrants legal advice for a specific case. The ISMS records where data resides and under whose control, so the answer exists before it is requested. Secure60 has delivery infrastructure in Kyrgyzstan via Rackcorp, with 2 datacentres, so collection and monitoring can run in-country where that is required.
The group certifies headquarters, scopes the ISMS to the main market, and treats the Kyrgyz entity as too small to include. The register entry, a customer questionnaire and the 2024 law’s categorisation questions then arrive at the one entity with no evidence behind it.
Bringing a Kyrgyz operation inside an existing multi-country ISMS scope costs a fraction of a standalone certificate, because the policies, risk method and management system already exist; what is added is local assets, local risks and local evidence. The next surveillance cycle is the natural point to scope it in.
We build and operate the ISMS — controls, logging, monitoring, incident response — on one security platform, with delivery infrastructure in Kyrgyzstan via Rackcorp so evidence and monitoring can stay in-country. For groups, we fold Kyrgyz operations into a multi-country scope rather than building a separate system. The certification audit belongs to an internationally accredited certification body operating in the region, and our work is making sure everything it samples is operating. Secure60 holds ISO 27001:2022 certification and applies the same test to its own system.
Is ISO 27001 legally mandatory in Kyrgyzstan?
No. Neither the Law on Personal Information (No. 58 of 2008) nor the 2024 Cybersecurity Law names a standard or a certificate. Certification is the practical way to evidence security duties to the regulator, and the form enterprise customers expect.
Do we have to register as a personal-data holder?
The State Agency for Personal Data Protection, established under the Cabinet of Ministers in December 2021, maintains a mandatory register of personal-data holders. Registration is administrative: it records the holder with the regulator and establishes nothing about system security.
Is there a breach-notification deadline in Kyrgyzstan?
No. The legislation sets no mandatory notification regime or deadline. Detection still matters, because the 2024 Cybersecurity Law builds a state incident-response and coordination structure, and customers and group policies impose their own reporting deadlines.
Who performs the ISO 27001 certification audit in Kyrgyzstan?
Certification is typically delivered by internationally accredited certification bodies operating regionally, and not by Secure60. Audit fees are set by the certification body and vary with the size and scope of what is being certified.
Can Secure60 deliver in Kyrgyzstan?
Yes. We have delivery infrastructure in Kyrgyzstan via Rackcorp, with 2 datacentres, so log collection and monitoring can run in-country. We have no local offices, and we do not perform the certification audit.