← Back to Regulation Watch

Regulation Watch · Business Licensing · Indonesia. The amendment applies to payment-system providers, money-market and foreign-exchange-market participants, and other parties regulated and supervised by Bank Indonesia under the information-security and cyber-resilience framework.

BI Tightens Cyber-Reporting Deadlines and Sanctions

PADG 29/2026 fixes annual and cyber-incident reporting cutoffs for BI-regulated payment, money-market and foreign-exchange operators and introduces escalating sanctions up to suspension and licence revocation.

Published
Bank Indonesia established PADG 29/2026 and published it through its official regulation portal on 25 September 2026. The official JDIH record does not identify a separate promulgation date or State Bulletin number.
Effective
25 September 2026, the date of establishment stated by Bank Indonesia.
Added to Watch
9 October 2026

Who is affected

PT PMA and PT PMDN companies licensed or approved by Bank Indonesia as payment-system providers, money-market or foreign-exchange-market participants, and other BI-regulated parties; their foreign and Indonesian shareholders and directors; and compliance, risk, technology, information-security, incident-response, internal-audit and reporting teams.

Practical impact

The annual cyber-resilience report is due by 31 January for the preceding reporting year. A report received after 31 January but by 15 February is late; a report not received by 15 February is treated as not submitted and must still be filed. A late annual report attracts a written warning, while non-submission attracts Rp5 million per report and can escalate to partial or complete suspension of activities and cooperation after more than three consecutive years, then licence or approval revocation after more than five consecutive years. An initial cyber-incident notification must reach BI within one hour after the operator becomes aware of the incident, and the incident report must follow within three calendar days after the incident; delay or non-submission attracts Rp5 million per report. The amendment also clarifies BI's designation of financial-sector vital information infrastructure.

Bank Indonesia established and made PADG 29/2026 effective on 25 September 2026. It amends PADG 24/2024 on information security and cyber resilience for payment-system providers, money-market and foreign-exchange-market participants and other parties regulated and supervised by BI. The official portal and JDIH record provide the operative text and implementation summary, but do not identify a separate promulgation date or State Bulletin number.

The amendment makes the annual-report timeline explicit. The report for the preceding reporting year must reach BI by 31 January. Receipt after 31 January through 15 February is classified as late, while a report that has not reached BI by 15 February is classified as not submitted. Classification as not submitted does not extinguish the duty: the operator must still provide the outstanding report.

Sanctions now escalate with the reporting failure. A late annual report attracts a written warning. Non-submission attracts a payment obligation of Rp5 million per report. An operator that fails to submit for more than three consecutive years can face temporary suspension of some or all activities, including cooperation arrangements; after more than five consecutive years, BI may revoke its licence or approval.

Cyber incidents have substantially shorter operational clocks. The operator must provide the initial notification no later than one hour after it becomes aware of the incident and submit the incident report no later than three calendar days after the incident occurs. Late or missing delivery of either report attracts Rp5 million per report, making precise awareness-time records, continuous escalation coverage and regulator-ready evidence essential.

PADG 29/2026 also clarifies BI's designation of financial-sector vital information infrastructure. BI may designate the regulated operator, its applications or technology infrastructure and the applicable protection roadmap, considering size, interconnectedness, substitutability, complexity, the operator's submitted identification and its cyber-security maturity level.

For foreign-owned and Indonesian regulated businesses, the immediate task is governance rather than a new OSS filing. The board and responsible officers should verify scope, own the January reporting calendar, test the one-hour and three-calendar-day incident workflow, preserve submission evidence and remediate any historical gap. Companies outside BI's regulated perimeter should not present the PADG as a general deadline applying to every Indonesian business.

Late discovery: PADG 29/2026 took effect in September but was not previously recorded in the Regulation Watch ledger. BI's official regulation page and JDIH metadata now provide the primary-source basis for publishing the reporting deadlines, monetary sanctions and escalation consequences without changing the instrument's true legal dates.

Required action

  • Confirm whether each Indonesian entity is a payment-system provider, money-market or foreign-exchange-market participant, or another party within BI's information-security and cyber-resilience reporting framework; do not assume that ordinary corporate or OSS status alone creates these duties.
  • Calendar 31 January as the annual-report deadline and 15 February as the non-submission cutoff, assign an accountable officer and reviewer, and preserve BI submission evidence for every reporting year.
  • Update the cyber-incident response plan so the responsible team can identify the awareness time, notify BI within one hour, submit the incident report within three calendar days after the incident, and retain the technical and governance evidence supporting both reports.
  • Test escalation, weekend and holiday coverage, management approval, regulator contact details, backup personnel and vendor notification clauses before an incident occurs; the three-day period is stated in calendar days.
  • Reconcile any previously late or missing annual or incident report and submit the outstanding report even where a warning or monetary sanction has already arisen, because the filing obligation continues after the cutoff.
  • Review BI correspondence and any vital-information-infrastructure designation covering the operator, its applications or technology infrastructure, then align the protection roadmap with the maturity level and remediation expectations stated by BI.

Start the Conversation

Need help applying this change?

Discuss how the regulation affects your company, investment, property, or compliance position.

Discuss Your Business