Myanmar Cybersecurity Law (2023)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Content Controls
Comply with MoTC content removal requests, takedown orders, and lawful access requests within statutory timeframes (typically 24 to 72 hours per order class). Maintain content moderation operations capable of handling Burmese language and minority language content (Shan, Karen, Kachin, Mon, Rakhine, Chin). Preserve evidence of compliance with each order and retain user data subject to requests for the periods specified by the Cybersecurity Law and Electronic Transactions Law. Document any objections to overbroad requests through formal channels noting significant international criticism from Reporters Without Borders, Amnesty International, and the UN Special Rapporteur on Myanmar.
- Content removal request log
- Takedown response records
- Lawful access response records
- Multi-language moderation capability evidence
- Order objection log
- Statutory timeframe compliance metrics
- Missed statutory takedown deadlines
- No multi-language moderation
- Missing objection records
- Incomplete lawful access logs
Cybersecurity Governance and CII
Establish the Central Body for Cyber Security led by the State Administration Council (SAC) under the Ministry of Transport and Communications (MoTC) jurisdiction. Designate Critical Information Infrastructure (CII) covering banking, telecommunications, energy, transport, government, and digital service operators. Maintain CII registry, classification, and oversight reporting per the 2025 Cybersecurity Law (enacted 1 January 2025 following 2023 draft and 2024 revisions).
- Central Body for Cyber Security organisational chart
- MoTC CII designation letter
- CII registry entry confirmation
- Sectoral CII classification record
- Annual oversight report to SAC
- Designated officer appointment letter
- No formal CII designation letter
- Missing classification documentation
- Outdated CII inventory
- Unclear escalation to MoTC/SAC
Data Localisation
Store personal data, financial data, government data, and CII operational data on servers physically located in Myanmar per data localisation provisions in the 2025 Cybersecurity Law and supporting regulations. Limited cross-border transfers permitted only with MoTC authorisation and adequacy assessment. Maintain server inventory, location attestations, and transfer authorisation records. Apply heightened controls for transfers to jurisdictions deemed non-cooperative by the SAC.
- Server location attestation
- Data localisation policy
- MoTC cross-border transfer authorisation
- Adequacy assessment record
- Transfer impact assessment
- Encryption at rest configuration
- Data stored offshore without authorisation
- No server location attestation
- Missing transfer authorisation
- Incomplete adequacy assessment
Enforcement and Compliance
Acknowledge enforcement under the Cybersecurity Law (penalties up to 7 years imprisonment plus fines), Electronic Transactions Law 66(d) defamation provisions (up to 3 years imprisonment), Counter-Terrorism Law, and Penal Code Section 505A (false news against the SAC, up to 3 years). Document organisational compliance posture, executive accountability, board oversight, and external counsel engagement for managing enforcement risk. Maintain awareness of international criticism from RSF, Amnesty International, Human Rights Watch, ARTICLE 19, Access Now, and the UN Special Rapporteur, alongside the broader post-2021-coup human rights context affecting the operating environment.
- Board oversight minutes
- Executive accountability matrix
- External counsel engagement letter
- Enforcement risk register
- Human rights impact assessment
- Compliance attestation submission to MoTC
- No board oversight of cyber compliance
- Missing executive accountability
- No external counsel engagement
- No human rights impact assessment
Incident Response
Operate a Cybersecurity Incident Response Team (CSIRT) capability covering 24/7 monitoring, triage, containment, eradication, and recovery for CII and licensed operators. Notify the Central Body for Cyber Security and MoTC within statutory windows (typically 24 hours for material incidents, 72 hours for personal data breaches). Coordinate with mmCERT (Myanmar Computer Emergency Response Team) during cross-sector incidents. Conduct annual incident response tabletop exercises and maintain post-incident root cause analyses for at least 5 years.
- CSIRT operating procedures
- 24/7 SOC roster
- Incident notification to MoTC
- mmCERT coordination record
- Annual tabletop exercise report
- Root cause analysis archive
- No 24/7 monitoring capability
- Missed notification windows
- No mmCERT coordination
- Missing tabletop exercises
Internet Access Controls
Comply with the Cybersecurity Law prohibitions on unauthorised Virtual Private Network (VPN) use, anonymisation tools, and circumvention software. Penalties include fines and imprisonment of 1 to 6 months under VPN-specific provisions plus additional charges under broader Cybersecurity Law and Electronic Transactions Law (66(d)). Maintain organisational policies that prevent unauthorised VPN deployment while documenting legitimate enterprise VPN exemptions through pre-authorised licensed corporate VPN providers.
- Approved VPN provider list
- Corporate VPN deployment authorisation
- Employee acceptable-use policy with VPN clause
- VPN usage logs
- Awareness training records
- Exemption documentation from MoTC
- Unauthorised VPN deployment
- No corporate VPN authorisation record
- Employees not trained on VPN restrictions
- Missing MoTC exemption documentation
Licensing and Authorisation
Obtain MoTC licensing for digital platform operators, cybersecurity service providers, cloud service providers, and internet service providers operating in Myanmar. Comply with licence conditions including local representation, data localisation, content moderation cooperation, and incident reporting obligations. Renew licences annually with proof of continued cybersecurity capability and submission of annual compliance reports.
- MoTC operating licence
- Annual licence renewal certificate
- Local representative appointment record
- Cybersecurity capability attestation
- Annual compliance report
- Service-class registration
- Operating without valid licence
- No designated local representative
- Missed renewal deadlines
- Incomplete capability attestation
Technical Security Controls
Implement baseline cybersecurity controls including network segmentation, perimeter defence, multi-factor authentication for administrative access, privileged access management, vulnerability management, patch management, malware protection, and cryptographic protection of data at rest and in transit. Use only cryptographic algorithms permitted by the MoTC (with prohibition or restriction of certain end-to-end encryption implementations that block lawful access in scope of the Cybersecurity Law).
- Network segmentation diagram
- MFA configuration evidence
- PAM solution deployment
- Vulnerability scan reports
- Patch management metrics
- Cryptographic standards compliance attestation
- Flat networks without segmentation
- MFA gaps on admin accounts
- Unpatched critical vulnerabilities
- Non-compliant cryptographic algorithms
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Myanmar Cybersecurity Law (2023) framework page.