Puerto Rico — Ley 40-2024 (ciberseguridad del gobierno)
Puerto Rico's government cybersecurity act (3 L.P.R.A. § 10121 et seq.), as amended through Ley 140-2026. It binds the executive branch — including the Departamento de Educación and municipalities — and its contractors. Curated here is the personal scope and the duty catalogue that reaches vendors.
Statute text is Spanish (the authentic language); this README is curation.
Applicability to EdTech
- Scope reaches us directly: the act applies to "cualquier persona natural o jurídica que haga negocios o tenga contratos con el Gobierno", limited to the public functions/services performed (Art. 2). A platform serving PR public schools is a "Proveedor de servicios contratados" (Art. 4(x)).
- Art. 7 minimum standards bind "toda Agencia y todo Proveedor de servicios contratados" and flow down to their own subcontractors. The vendor-critical items:
- contracts must include safeguards for sensitive assets; providers must comply with the federal FISMA regime and retain no less than 3 years of information, producible electronically within 2 days of a law-enforcement demand (Art. 7(9));
- ICT providers must notify PRITS and the contracting agency within 48 hours of discovering an actual or potential cybersecurity incident (Art. 7(10));
- providers holding citizens' sensitive data must carry the security certifications PRITS requires at signing (Art. 7(12));
- encryption in transit and at rest for confidential information (Art. 7(16)), NIST-based encryption controls (Art. 7(4)).
- Procurement gate: agencies must consult PRITS before any contract with a Proveedor de servicios contratados, and un-consulted contracts can be cancelled if non-compliant (Art. 7 closing paragraphs) — expect these requirements in DE-PR tenders.
Contents
| Document | Covers |
|---|---|
| CIBERSEGURIDAD-PROVEEDORES.md | Art. 2 (aplicabilidad), Art. 4(x) (Proveedor de servicios contratados), Art. 7 in full (estándares mínimos) |
Scope note: the CISO/PRITS institutional articles (Arts. 5–6, 8–9) and sanctions (Art. 10) are not extracted; add them if an enforcement question arises.
Enforcement
Puerto Rico Innovation and Technology Service (PRITS) and its Principal Oficial de Seguridad Cibernética; contract cancellation is the operative sanction for providers.
Related
- PR Ley 111-2005 — general breach notification (10-day DACO report) alongside the 48-hour PRITS duty
- US NIST CSF — the referenced standards family
- EU NIS2 — the EU sibling supply-chain regime
Sources
Meta
Statute text in CIBERSEGURIDAD-PROVEEDORES.md is reproduced verbatim in Spanish from the OGP Biblioteca Virtual consolidated PDF (Rev. 03 de agosto de 2026, incorporating Ley 140-2026) by tools/pr-ogp/build_pr.py; verify re-fetches and fails on a newer Rev. stamp. In force immediately on approval (Art. 17), 18 January 2024.