Two laws apply, both adopted 17 December 2021: the Law on Cyber Security, introducing the designation organisation with critical information infrastructure, and the Law on Personal Data Protection, in force since 1 May 2022 and aligned with GDPR and OECD principles. Neither mandates ISO 27001. Certification is the practical route to evidencing compliance rather than a legal requirement.
On 17 December 2021 Mongolia’s parliament adopted two laws that together define the country’s information security baseline.
| Law | Adopted | What it does |
|---|---|---|
| Law on Cyber Security | 17 December 2021 | Introduces the designation “organisation with critical information infrastructure”, with security obligations attaching to designated organisations |
| Law on Personal Data Protection | 17 December 2021 (in force 1 May 2022) | Sets personal data handling obligations, aligned with GDPR and OECD principles |
The Law on Cyber Security applies to designated organisations. An organisation with critical information infrastructure carries obligations it will be required to demonstrate, and designation brings inspection with it.
The Law on Personal Data Protection has wider reach. In force since 1 May 2022 and aligned with GDPR and OECD principles, it applies to how organisations handle personal data generally rather than only to designated infrastructure. Where customers, staff or users are in Mongolia, it is the baseline, and its GDPR alignment means foreign counterparties assess your position through a framework they already use.
Neither law mandates ISO 27001. No clause names the standard, and certification presented as a legal requirement in Mongolia is a misstatement of the law.
Both laws set obligations without specifying how to meet them or how to evidence compliance. When the question arrives — from a regulator after designation, from a bank’s third-party risk team, or from a foreign customer’s security questionnaire — the answer has to be a structure an external party can inspect. In practice that structure is an ISMS: a risk assessment, a Statement of Applicability across the 93 Annex A controls, evidence that the controls operate, and an independent certificate confirming it.
The GDPR alignment tightens the fit. An ISO 27001 ISMS already runs the machinery a GDPR-shaped law assumes: access control, supplier management, incident response, and records of what data resides where. Building the ISMS once answers the Mongolian law and the foreign questionnaire from the same evidence.
The certificate is also portable. Mongolian organisations selling into other markets carry it across borders without re-certifying, and the regional picture is covered in the Asia-Pacific and Central Asia hub.
The mechanics match those elsewhere. An accredited certification body — not Secure60, and not any implementation partner — performs Stage 1 (documentation review) and Stage 2 (interviews and evidence), then annual surveillance audits, with full recertification every three years. Audit fees are set by the certification body and vary with the size and scope of what is being certified.
Scope is the main variable. A tight scope around the systems that matter — the designated infrastructure, the platforms holding personal data — certifies faster and operates more cheaply than an all-inclusive scope, and it can be extended later. Where the Mongolian operation belongs to a wider group, one certificate can carry it inside a multi-country scope.
An engagement covers the path to that audit: a gap assessment against both laws and the standard, the risk assessment, policies and the Statement of Applicability across the 93 Annex A controls, implementation of the missing controls, the internal audit the standard requires, and preparation for Stage 1 and Stage 2. The certification body then examines what has been built, and that separation of roles is fixed by the accreditation rules.
Secure60 runs delivery infrastructure in-country via Rackcorp, with 4 datacentres in Mongolia, so logging, monitoring and evidence collection run onshore rather than being backhauled to a jurisdiction a regulator or counterparty would question.
ISO 27001 certifies that the management system works: that risk is assessed, controls are run, and both can be evidenced. An auditor is not a regulator.
Whether the Law on Cyber Security’s obligations and the Law on Personal Data Protection’s duties are met depends on whether those laws were entered into the ISMS as legal requirements — named in the risk assessment, reflected in the controls, covered by the evidence. An ISMS built to pass Stage 2 alone can be certified while addressing neither law. The laws go in as inputs, and the certificate evidences the result.
Secure60 delivers the certification and operates the security behind it. For a Mongolian scope that means the ISMS build, the controls, the evidence, and the daily security operations — logging, monitoring, vulnerability management — on one security platform, running on in-country infrastructure via Rackcorp. The certification audit is performed by an accredited certification body, and our work is getting you to the point where their sampling finds a running system. Secure60 holds ISO 27001:2022 certification, so this is our own operating model.
Is ISO 27001 mandatory in Mongolia?
No. Neither the Law on Cyber Security nor the Law on Personal Data Protection names ISO 27001 as a requirement. It is the practical route to evidencing compliance with both, because the laws set obligations that have to be demonstrated.
What is an 'organisation with critical information infrastructure'?
The designation introduced by Mongolia’s Law on Cyber Security, adopted 17 December 2021. Designated organisations carry security obligations under the law, and those obligations have to be demonstrated rather than asserted.
How close is Mongolia's data protection law to GDPR?
The Law on Personal Data Protection is aligned with GDPR and OECD principles, so an organisation built for GDPR will find the concepts carry over. It remains its own instrument in its own legal system and needs reading in its own right.
Who performs the certification audit in Mongolia?
An accredited certification body, and not Secure60. Audit fees are set by the certification body and vary with the size and scope of what is certified. Our role is building and running the ISMS the auditor examines.
Can Secure60 deliver in Mongolia?
Yes. We have delivery infrastructure in-country via Rackcorp, with 4 datacentres in Mongolia, so log collection, monitoring and evidence can run on Mongolian infrastructure. We have no local offices, and we do not conduct the certification audit.