Search
Close this search box.

DICT Mandates Annual Cyber Testing for Government Agencies

Manila: The Department of Information and Communications Technology (DICT) has ordered all government agencies to undergo annual cybersecurity testing to strengthen defenses against cyberthreats and reduce the risk of disruptions to public services. Department Circular No. HRA-008, s. 2026, mandates the conduct of Vulnerability Assessment and Penetration Testing (VAPT) at least once every year, and whenever major system changes or cybersecurity incidents occur, according to a news release Thursday.

According to Philippines News Agency, the directive covers national government agencies, government-owned and controlled corporations and their subsidiaries, state universities and colleges, local government units of host cities, and other government instrumentalities. Operators of Critical Information Infrastructure, whose systems support essential government functions and services relied upon by the public, face additional cybersecurity obligations under the policy.

VAPT identifies weaknesses in systems, applications, and networks, and evaluates how these vulnerabilities could be exploited in real-world attack scenarios, the DICT said. The results help organizations address security gaps before they lead to data breaches, service interruptions, or other cyber incidents.

Government entities may conduct the assessments internally, subject to DICT requirements, or engage DICT Trusted Assessment Providers (D-TAPs). To ensure prompt action, the circular establishes remediation timelines based on risk severity. Critical vulnerabilities must be addressed within five business days, while medium- and low-risk findings must be resolved within 30 business days.

Government agencies may learn more about the D-TAP program and access the list of accredited providers through the official D-TAP Portal at https://dtap.dict.gov.ph/.