Two laws matter, both adopted 17 December 2021: the Law on Cyber Security, introducing the designation organisation with critical information infrastructure, and the Law on Personal Data Protection, in force since 1 May 2022, aligned with GDPR and OECD principles. Neither mandates ISO 27001. It’s the practical route to evidencing compliance — not a legal requirement.
On 17 December 2021 Mongolia’s parliament adopted two laws in one sitting, and between them they define the country’s information security baseline.
| Law | Adopted | What it does |
|---|---|---|
| Law on Cyber Security | 17 December 2021 | Introduces the designation “organisation with critical information infrastructure”, with security obligations attaching to designated organisations |
| Law on Personal Data Protection | 17 December 2021 (in force 1 May 2022) | Sets personal data handling obligations, aligned with GDPR and OECD principles |
The Law on Cyber Security matters most if you’re designated — or could be. An organisation with critical information infrastructure carries obligations it will be expected to demonstrate, and “demonstrate” is the operative word: a designation is an invitation for someone to check.
The Law on Personal Data Protection reaches wider. In force since 1 May 2022 and aligned with GDPR and OECD principles, it applies to how organisations handle personal data generally, not just to designated infrastructure. If your customers, staff or users are in Mongolia, it’s your baseline — and its GDPR alignment means foreign counterparties will read your compliance posture through a lens they already know.
Here’s the honest part, and it’s the part this page exists to say plainly: neither law mandates ISO 27001. No clause names the standard. If someone sells you certification as a legal requirement in Mongolia, they’re wrong.
Because the obligations still need evidencing, and the laws don’t come with a workbook.
Both laws tell you what — protect the infrastructure, protect the data. Neither tells you how, and neither gives you a format for proving it. When the question arrives — from a regulator after designation, from a bank’s third-party risk team, from a foreign customer’s security questionnaire — you need a structure that a stranger can inspect and trust. That structure, in practice, is an ISMS: a risk assessment, a Statement of Applicability across the 93 Annex A controls, evidence that the controls operate, and an independent certificate saying so.
The GDPR alignment makes the fit tighter than usual. An ISO 27001 ISMS already runs the machinery a GDPR-shaped law assumes exists — access control, supplier management, incident response, records of what data lives where. Building the ISMS once answers the Mongolian law and the foreign questionnaire with the same evidence.
And the certificate travels. Mongolian organisations selling into other markets carry it across borders without re-earning anything — the regional picture is covered in the Asia-Pacific and Central Asia hub above.
The mechanics are the same as anywhere. An accredited certification body — not Secure60, not any implementation partner — performs Stage 1 (documentation review) and Stage 2 (interviews and evidence), then annual surveillance audits, with full recertification every three years. Audit fees are set by the certification body and vary with the size and scope of what’s being certified.
Scope is your main lever. A tight scope around the systems that matter — the designated infrastructure, the platforms holding personal data — certifies faster and operates more cheaply than an everything-in scope, and you can extend later. If the Mongolian operation belongs to a wider group, one certificate can carry it inside a multi-country scope instead of standing alone.
An engagement, in practice, covers the whole path to that audit: a gap assessment against both laws and the standard, the risk assessment, policies and the Statement of Applicability across the 93 Annex A controls, implementation of the controls that are missing, the internal audit the standard requires, and preparation for Stage 1 and Stage 2. The certification body then examines what’s been built — that division of roles is fixed, and it protects you.
Delivery is the part people assume is hard from Mongolia, and it isn’t. Secure60 runs delivery infrastructure in-country via Rackcorp — 4 datacentres in Mongolia — so logging, monitoring and evidence collection run onshore rather than being backhauled somewhere your regulator or counterparties would question.
The mistake is reading “certified” as “compliant”. A certificate is not legal compliance with either law, and an auditor is not a regulator.
ISO 27001 certifies that your management system works — that you assess risk, run controls and can prove it. Whether the Law on Cyber Security’s obligations or the Law on Personal Data Protection’s duties are actually met depends on whether those laws were fed into the ISMS as legal requirements: named in the risk assessment, reflected in the controls, covered by the evidence. An ISMS built purely to pass Stage 2 can be certified and still silent on the two laws that matter here. Put the laws in first; let the certificate prove the result.
Tools hand you a to-do list. We do the list — and run the security behind it. For a Mongolian scope that means the ISMS build, the controls, the evidence, and the daily security operations — logging, monitoring, vulnerability management — on one security platform, running on in-country infrastructure via Rackcorp. The certification audit is performed by an accredited certification body; we get you to the point where their sampling finds a system that’s genuinely running. We hold ISO 27001:2022 certification ourselves, so we’re describing our own operating model, not a theory.
Is ISO 27001 mandatory in Mongolia?
No. Neither the Law on Cyber Security nor the Law on Personal Data Protection names ISO 27001 as a requirement. It’s the practical route to evidencing compliance with both, because the laws set obligations you’ll be asked to prove you meet.
What is an 'organisation with critical information infrastructure'?
It’s the designation introduced by Mongolia’s Law on Cyber Security, adopted 17 December 2021. Designated organisations carry security obligations under the law — which means being able to show, not just assert, that your systems are protected.
How close is Mongolia's data protection law to GDPR?
The Law on Personal Data Protection is aligned with GDPR and OECD principles, so if you’ve built for GDPR the concepts carry over. It’s still its own instrument in its own legal system — read it in its own right rather than assuming equivalence.
Who performs the certification audit in Mongolia?
An accredited certification body — not Secure60. Audit fees are set by the certification body and vary with the size and scope of what’s certified. Our role is building and running the ISMS the auditor examines.
Can Secure60 deliver in Mongolia?
Yes — we have delivery infrastructure in-country via Rackcorp, with 4 datacentres in Mongolia. Log collection, monitoring and evidence can run on Mongolian infrastructure. We don’t have local offices, and we never conduct the certification audit.