Law 21663 Compliance in Chile | OIV Gap Assessment Case Study
Law 21663 compliance case study in Chile: gap assessment for an OIV energy company, with an action plan aligned to the NIST Cybersecurity Framework.

Law 21663 compliance assessment for an OIV energy company in Chile
A Chilean energy company engaged Cyberhub to assess its level of compliance with Law 21663, the regulation governing Organizations of Vital Importance (OIV). The objective was to establish a clear baseline and define an action plan aligned with regulatory expectations.
Regulatory context and challenge
The organization needed to comply with new legal requirements related to cybersecurity and operational continuity in an increasingly regulated environment. However, it lacked a structured framework to measure readiness against guidance issued by the Government CSIRT and the competent authority.
Assessment methodology
- Information gathering through stakeholder interviews and document review.
- Maturity assessment based on the NIST Cybersecurity Framework (CSF).
- Identification of compliance gaps against Law 21663 requirements and technical guidelines.
- Design of a prioritized action plan with defined milestones, owners, and timelines.
- Delivery of executive and technical reports with a clear compliance roadmap.
Results achieved
The assessment enabled the organization to understand its actual maturity level in risk management, critical asset protection, and incident response. A three-phase improvement plan was defined and is currently under execution, with quarterly oversight by the Corporate Security Committee.
“Cyberhub helped us translate regulatory requirements into concrete actions, improving visibility and management of our operational cyber risks.”
Next steps
Following the assessment, the organization initiated formal adoption of the NIST CSF as the foundation of its corporate cybersecurity management system and strengthened its internal audit and compliance processes.
Need a Law 21663 compliance assessment in Chile? Contact us →