Israel Advances National Cybersecurity Law Aligning With Global Standards
On June 8, 2026, the Israeli Knesset approved in its first reading the National Cybersecurity Protection Law, aiming to establish a comprehensive legal framework for cybersecurity in Israel. This move aligns Israel with international regulations such as the European NIS and NIS2 directives, as well as standards adopted by the UK, Australia, and Canada. Israel, frequently targeted by cyberattacks, especially since the escalation of "Iron Swords," has lacked a unified national cybersecurity law until now.
The law's primary goal is to raise cybersecurity awareness across public and private sectors and to create a uniform operational continuity framework for organizations facing cyber incidents. It formally establishes the National Cyber Directorate as the central coordinating body for national cyber defense, alongside sector-specific units within various regulators, including the Ministry of Communications and local authorities.
A key concept in the law is the definition of "essential organizations," encompassing all government bodies and private entities meeting sector-specific criteria in communications, energy, health, water and sewage, transportation, chemicals, agriculture, and local authorities. Regulators have the authority to add or remove organizations from this list individually. The law also covers digital service providers and data storage services, including cloud providers, IT, and cybersecurity services, if they meet thresholds of 40 million shekels in annual revenue or 50 employees, or if they serve government or public bodies.
The legislation mandates all organizations to implement appropriate cybersecurity measures, with essential organizations required to follow recognized international standards such as ISO 27001 and NIST 800-53. It also imposes immediate reporting obligations for significant cyberattacks, with provisions for exemptions. Violations carry substantial financial penalties reaching hundreds of thousands of shekels and, in severe cases, criminal liability for responsible officers.
The National Cyber Directorate emphasized that the law aims to enhance national resilience and maintain the continuity of critical services, balancing operational needs with regulatory oversight. The law preserves a decentralized management model, empowering sector regulators familiar with their domains while providing national-level professional guidance. The legislation is expected to undergo further revisions and include a transition period for organizations to comply. This development marks a significant step in integrating cybersecurity and information security into Israel's business lifecycle, complementing recent privacy law amendments.