The government has declared Chattogram Port Authority (CPA) as a “Critical Information Infrastructure” (CII) to bring digital systems of the country’s premier gateway for foreign trade under state-level cyber security.
The Information and Communication Technology (ICT) Division, under Posts, Telecommunications and Information Technology Ministry, issued a gazette notification in this regard on Monday under the Cyber Security (Amendment) Act, 2026.
Issued by order of the president, the notification takes effect immediately.
Since the lion’s share of the country’s import and export trade passes through Chattogram Port, its digital infrastructure is considered highly critical for national economy and security.
Any major cyber-attack or technological disruption in the port’s digital systems – including container management, vessel movement, billing, revenue processing, and supply chain management – could directly impact national trade, industrial production, and public life.
Against this backdrop, the government decided to place the port’s critical digital systems under a more robust cyber security framework.
The CPA uses a vast number of digital systems to manage its daily operations. To strengthen the security of these systems and enhance cyber security capabilities at the national level, the authority successfully passed a specific evaluation process to achieve the CII designation.
Prior to this, 36 organisations in Bangladesh had been declared CIIs; Chattogram Port is the latest addition, opening up opportunities to further strengthen the security of its critical digital systems.
Under this new security framework, emphasis will be placed not only on conventional cyber security but also on data transmission, communication systems, databases, application-level communication, and the API hub, among other IT infrastructures.
Mandatory security standards
Following the CII declaration, adherence to higher cyber security standards has become mandatory for the prioritised systems of Chattogram Port.
Under these new obligations, the port authority must operate its own Security Operations Centre (SOC) and Cyber Incident Response Team (CIRT) to maintain 24-hour cyber surveillance.
It is also required to conduct regular and annual security audits of both internal and external information infrastructures and submit reports to the relevant authorities.
Moreover, the port authority must report regularly and share cyber incident information with the National Cyber Security Agency (NCSA) and the National Cyber Security Operations Centre. It must also conduct risk assessments, vulnerability assessments (VA), and penetration testing (PT) at designated intervals.
Other mandatory requirements include maintaining encrypted and offline backups of critical data, regularly testing Business Continuity (BC) and Disaster Recovery (DR) systems, and extending all necessary cooperation during inspections and audits conducted by relevant government authorities.
The gazette notification also stipulates that any breach of security measures or unauthorised access to the critical information infrastructure will be treated as a punishable offence under the law.
Strategic recognition and readiness
The CPA had already initiated various preparatory activities ahead of the formal declaration, guided by directives from the ICT Division and the NCSA.
These preparations include forming a dedicated cyber security team, preparing a comprehensive inventory of information infrastructure, updating security policies, and conducting regular cyber security awareness training programmes for officers and staff.
Welcoming the government’s decision, CPA Chairman Rear Admiral S. M. Moniruzzaman said the step is a specific recognition of the strategic and national importance of Chattogram Port.
He noted that as the premier gateway for Bangladesh’s foreign trade and economic activities, ensuring the safe, uninterrupted, and stable operation of the port is a national duty.
Since cyber risks are increasing alongside the port’s growing digital transformation, the authority does not view cyber security merely as an IT issue, but as an inseparable part of operational continuity, national security, and economic stability.
He added that the port authority would work in coordination with the ICT Division, the NCSA, and relevant stakeholders to follow international standards, conduct regular risk assessments, and strengthen capabilities to tackle cyber threats.
The CII declaration is expected to offer safer and more reliable digital services to port users, importers, exporters, shipping agents, and clearing and forwarding (C&F) agents.
However, the notification clarified that the CII declaration does not mean the government is taking over the management of the CPA’s IT systems.
The CPA will continue to own and operate its critical information infrastructure, though these systems will now be subject to higher-level national cyber security oversight, auditing, and compliance frameworks.





