CyberCode.ph · Philippines

HB 9605 Cybersecurity Bill: What It Proposes for Critical Infrastructure and Ransomware

Last updated September 28, 2026 · Practical privacy, cybersecurity and technology-law guidance

Direct answer: House Bill No. 9605, the proposed National Cybersecurity and Critical Information Infrastructure Protection Act of 2026, would create a National Cybersecurity Agency (NCSA) and establish mandatory cybersecurity standards and certification for organizations that run critical systems. The House of Representatives passed it on third and final reading in August 2026, but it still needs Senate approval and enactment. Its proposed requirements are not yet binding law. The measure addresses risks such as ransomware by strengthening prevention, standards and coordinated response; it does not promise that attacks can be eliminated. Philippine Information Agency, August 14, 2026; House bill record.

Evidence and action

  • Verified fact: The House passed HB 9605 on third and final reading, and the measure proceeds to the Senate. It is not an enacted statute.
  • Uncertainty: The Senate may amend the measure; final covered entities, duties, timelines and agency powers depend on the enacted text and implementing rules.
  • Source: Philippine Information Agency report of the House passage and the House legislative record.
  • Timing: Status rechecked September 28, 2026; we found no enacted version, so no commencement date exists.
  • Next step: Operators of essential services should comply with the laws that already apply (see what to do next) while tracking the bill.

Where is HB 9605 in the legislative process?

According to the Philippine Information Agency, the House approved HB 9605 on third and final reading and the measure now proceeds to the Senate for consideration before it can be presented to the President. The PIA report also describes the bill as a Legislative-Executive Development Advisory Council (LEDAC) priority. Approval in one chamber is a legislative milestone, not enactment. Readers should check the 20th Congress bill record and the Senate Legislative Information System for the latest version before relying on any specific wording.

What would the measure change?

Area Proposed direction Why it matters
National coordination Create a National Cybersecurity Agency to lead cybersecurity policy, planning and implementation. Defines a central institutional lead for cross-sector security efforts.
Critical information infrastructure Identify vital systems and impose baseline security expectations and oversight on covered operators. Focuses resources on services whose interruption would have a wider public impact.
Security assurance Introduce mandatory standards and certification requirements for covered organizations and IT professionals. Moves from voluntary preparation toward verifiable security practices for designated systems.
Incident coordination Strengthen national response and information sharing for serious cyber incidents. Helps agencies and operators coordinate when an attack crosses organizational boundaries.

The PIA describes these broad elements. Specific frequencies, thresholds, sanctions and exclusions should be checked against the final legislative text before anyone treats them as a compliance rule.

How could HB 9605 help against ransomware?

Ransomware can interrupt essential services even when the initial compromise starts with a supplier, exposed account or ordinary office computer. A critical-infrastructure framework can require covered operators to understand which systems matter most, assess risk, establish minimum controls and coordinate a response. Standards and audits may improve preparedness; their effectiveness depends on implementation, resources, testing and the final scope of the law.

Practical example: A hospital could identify the systems needed to admit patients, maintain offline or otherwise isolated recovery copies, test how quickly clinical records can be restored and define who contacts its regulator after a serious incident. These are editorial preparedness examples, not a claim that HB 9605 currently requires each measure or sets a particular backup design.

Who might be covered?

The proposal focuses on government systems and designated critical information infrastructure, including essential public and private services. An operator should not assume it is covered merely because it has a website, or exempt merely because it is privately owned. Coverage will depend on the final law, designation criteria and any implementing rules. The government’s summary identifies energy grids, financial institutions and government networks as examples of systems the measure aims to protect.

What rules apply while HB 9605 is pending?

Existing law still matters. RA 10175 defines cybercrime offenses, including illegal access and data interference, and makes the NBI and PNP responsible for enforcement (§10). RA 10844 §15(b) transferred cybersecurity functions, including the National Cybersecurity Plan and the National Computer Emergency Response Team, to DICT. The Data Privacy Act and the NPC’s rules apply to personal-data processing; where a breach meets the NPC’s conditions, the controller must notify the NPC and affected data subjects within 72 hours of knowledge or reasonable belief of the breach (NPC breach-reporting guidance). Particular operators may also face sector-regulator rules and contractual duties. HB 9605 does not suspend any of them while it is a bill.

What can an operator do now?

  1. Map the services whose outage would harm customers or the public, and identify their supporting technology and suppliers.
  2. Review current sector-specific, privacy and contract obligations; assign owners to each.
  3. Test a ransomware response: isolate affected systems, preserve logs and evidence, restore essential service and communicate through verified channels.
  4. Document risk assessments, recovery exercises, access decisions and supplier assurance.
  5. Monitor the House bill and any Senate counterpart for changes before building a compliance checklist around draft wording.

These are prudent security steps, not new statutory obligations created by an unenacted bill.

What to do next if you are hit by ransomware today

Because HB 9605 is not law, a ransomware incident today is handled under existing rules. Your realistic options and forums are:

  • Contain and coordinate technically: isolate affected systems and contact DICT’s national CERT, whose functions RA 10844 §15(b) placed under DICT, for incident coordination.
  • Report the crime: file a complaint with the PNP Anti-Cybercrime Group or the NBI cybercrime unit, the enforcement bodies under RA 10175 §10. Our reporting directory lists the channels.
  • Assess privacy notification: if personal data may have been acquired by the attacker, run the NPC three-part test; if it is met, notify the NPC through its Data Breach Notification Management System and the affected people within 72 hours. See our data breach reporting guide.
  • Check your sector regulator and contracts: banks, telcos, utilities and other regulated operators may have separate reporting rules; this guide did not verify each sector’s deadline.

Documents to keep: the ransom note, affected system list, logs, timeline of when you first knew, backups used, communications with the attacker (do not delete them) and all notices sent. First action: isolate the affected systems and preserve evidence before wiping or restoring anything. Our ransomware first-response guide covers the first hours in detail.

Questions that lawmakers and operators should test

  • How will critical infrastructure be designated and reviewed?
  • Which small operators or suppliers will be covered, and how will they afford compliance?
  • How will incident reports to a cybersecurity agency interact with NPC and sector-regulator reporting?
  • What due-process, confidentiality and privacy safeguards will constrain any audit or directive power?
  • Will the final rules measure resilience and recovery, rather than paperwork alone?

Frequently asked questions

Is HB 9605 already law?

No. The House approved it on third reading in August 2026; Senate action and the remaining constitutional lawmaking steps are still required.

Does it ban paying a ransomware demand?

Do not infer a blanket payment ban from the broad public summaries. Any final rule on reporting or ransom decisions must be checked in the enacted text. A ransomware victim should preserve evidence and get incident, legal and sector-specific advice before deciding.

Will all Philippine businesses need certification?

That cannot be concluded from the public summaries alone. Final coverage, designation and certification rules remain dependent on legislation and implementation.

Does this replace DICT, CICC or the NPC?

The proposal contemplates a new national cybersecurity agency, but present statutory roles remain in place. Any transfer or overlap must be read from the final enacted text. See our guide to DICT and CICC legal limits.

Sources

This is a proposal; the final law could differ materially.

Sources rechecked as of: September 28, 2026

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.