Indonesia connected devices IoT security regulation

Indonesia's Cyber Bill Needs a Risk-Tiered Local Representative Rule for Connected-Device Vendors, Not a Blanket One

A DPR member flagged that Indonesia's cyber bill sets no local-representative duty for foreign vendors; a proportionate, tiered fix would serve connected-device security.

Connected-Device Rules: Reference Points People of Internet Research · Indonesia 13 ETSI baseline provision areas Consumer IoT baseline sections 5.1… 11 Sep 2026 CRA reporting duties begin Manufacturers report actively expl… 11 Dec 2027 CRA full obligations apply All core cybersecurity requirement… peopleofinternet.com
Connected-Device Rules: Reference Poin… People of Internet Research · Indonesia 13 ETSI baseline provision areas 11 Sep 2026 CRA reporting duties begin 11 Dec 2027 CRA full obligations apply peopleofinternet.com

Key Takeaways

The gap a lawmaker pointed to

At a public hearing (RDPU) of the Commission I working committee (Panja) on Indonesia's Cybersecurity and Cyber Resilience Bill (RUU KKS) on 15 September 2026, DPR member Amelia Anggraini said the draft does not require foreign technology vendors to keep a legal representative in Indonesia. By her account, those vendors' digital products and services, including connected systems, are widely used and reach strategic systems. She also said it is unclear whether the requirement should cover every vendor or only high-risk ones, and that the representative's duties on incident reporting, audits and penalties are undefined. The bill would make BSSN, the national cyber agency, the central cyber authority.

A caveat on scope: the report of the hearing concerns vendor accountability in general and does not mention IoT devices. Applying it to connected devices is our inference. It is a reasonable one, since connected products are where a foreign manufacturer's software sits inside Indonesian homes, factories and utilities, and where an accountable local counterpart matters most.

The strongest case for a mandatory representative

The argument for a requirement is serious. When a camera, router or industrial gateway is compromised, regulators need someone they can reach, serve papers on and hold to a deadline. Without a local presence, a vendor headquartered abroad can ignore an incident notice at little cost. A named representative gives BSSN a counterpart for incident reporting, a custodian for technical documentation, and an entity against which penalties can be enforced. That is why the European Union built the idea into its Cyber Resilience Act (CRA, Regulation (EU) 2024/2847), which lets manufacturers outside the EU appoint an authorised representative by written mandate. Under Article 18, that mandate includes keeping documentation available to market surveillance authorities and cooperating on corrective action.

Why the open questions are the real risk

The lawmaker's three uncertainties are the right ones, and each is a place where a poorly drafted rule would do harm.

The free-expression and open-internet stakes are indirect but real. Broad vendor-liability rules that give a single agency wide inspection discretion are easier to repurpose for non-security aims. Clear statutory limits are the safeguard.

What the evidence says good IoT rules look like

Indonesian scholars have argued for years that the country needs a coherent IoT framework. A 2017 analysis in a Komdigi-affiliated research journal identified security standards, covering data protection, network security and application security, and device standards including authentication and device security, as the regulatory parameters that needed to be set. A 2024 paper in an academic proceedings series likewise called for a comprehensive framework that includes security vulnerability response. Neither paper treats a local-representative rule as the centre of the solution.

The technical content is better supplied by standards than by representation requirements. ETSI EN 303 645, the consumer IoT baseline published in June 2020, sets out 13 cybersecurity provision areas, among them no universal default passwords, a means to manage vulnerability reports, and keeping software updated. Those are the behaviours that reduce real-world compromise. A local representative is a delivery mechanism for accountability; it does not make a device secure. The EFF made the same general point about a different domain in its September 2026 commentary on AI cybersecurity rules: legislation should be tied to well-established, evidence-backed security practices that can evolve, rather than prescriptive rules aimed at today's technology.

A proportionate design for RUU KKS

The committee can close the gap without a blanket rule. We would suggest four drafting choices.

  1. Tier by risk. Require a local representative only for vendors whose products are supplied to designated critical or strategic systems, or exceed a defined deployment threshold, with an exemption for low-volume and low-risk products.
  2. Define the duties in the statute. Specify the representative's role in incident notification, documentation retention and cooperation, with fixed response times, rather than leaving them to implementing regulation.
  3. Anchor requirements to a published baseline. Point to a named technical standard such as ETSI EN 303 645, or an Indonesian national equivalent, so firms know what compliance means before an audit.
  4. Bound the audit and penalty powers. Limit audits to security conformity, protect trade secrets and source code, and make penalties proportionate and appealable.

The EU's own sequencing is instructive. According to the European Commission, CRA vulnerability-reporting obligations begin on 11 September 2026, and the main obligations apply from 11 December 2027, giving manufacturers a long runway. Indonesia need not copy that regime. But a bill that creates a central authority and then leaves vendor accountability to be worked out later gets the order wrong.

Bottom line

Amelia Anggraini identified a real hole, and the committee should fill it. The risk is filling it bluntly. A tiered, clearly defined representative duty, paired with a published security baseline, would give BSSN a counterpart where it matters and keep smaller connected-device makers in the market.

Sources & Citations

  1. European Commission: Cyber Resilience Act
  2. ETSI EN 303 645 V2.1.1 (2020-06)
  3. Komdigi Bpostel: Analisis Kebutuhan Regulasi terkait IoT (2017)
  4. EFF: Ground AI Cybersecurity Rules in Best Practices
  5. Isman & Novita (2024): Regulation of IoT Devices in Indonesia