The gap a lawmaker pointed to
At a public hearing (RDPU) of the Commission I working committee (Panja) on Indonesia's Cybersecurity and Cyber Resilience Bill (RUU KKS) on 15 September 2026, DPR member Amelia Anggraini said the draft does not require foreign technology vendors to keep a legal representative in Indonesia. By her account, those vendors' digital products and services, including connected systems, are widely used and reach strategic systems. She also said it is unclear whether the requirement should cover every vendor or only high-risk ones, and that the representative's duties on incident reporting, audits and penalties are undefined. The bill would make BSSN, the national cyber agency, the central cyber authority.
A caveat on scope: the report of the hearing concerns vendor accountability in general and does not mention IoT devices. Applying it to connected devices is our inference. It is a reasonable one, since connected products are where a foreign manufacturer's software sits inside Indonesian homes, factories and utilities, and where an accountable local counterpart matters most.
The strongest case for a mandatory representative
The argument for a requirement is serious. When a camera, router or industrial gateway is compromised, regulators need someone they can reach, serve papers on and hold to a deadline. Without a local presence, a vendor headquartered abroad can ignore an incident notice at little cost. A named representative gives BSSN a counterpart for incident reporting, a custodian for technical documentation, and an entity against which penalties can be enforced. That is why the European Union built the idea into its Cyber Resilience Act (CRA, Regulation (EU) 2024/2847), which lets manufacturers outside the EU appoint an authorised representative by written mandate. Under Article 18, that mandate includes keeping documentation available to market surveillance authorities and cooperating on corrective action.
Why the open questions are the real risk
The lawmaker's three uncertainties are the right ones, and each is a place where a poorly drafted rule would do harm.
- Scope. A requirement that applies to every foreign vendor would reach the smallest module maker and the open-source-adjacent hardware startup as readily as a large network-equipment supplier. The fixed cost of a local entity falls hardest on small firms, and the likely response is that they withdraw from the Indonesian market, which reduces consumer choice without improving security.
- Duties. A representative whose obligations on incident reporting, audits and penalties are left to later regulation creates legal uncertainty for firms and wide discretion for the authority. Undefined audit powers over a foreign vendor's products invite requests that run well beyond security, including source code or data access.
- Penalties. If a local representative can be penalised for a parent company's decisions, the rational outcome is to appoint a thinly capitalised shell, or to avoid the role entirely.
The free-expression and open-internet stakes are indirect but real. Broad vendor-liability rules that give a single agency wide inspection discretion are easier to repurpose for non-security aims. Clear statutory limits are the safeguard.
What the evidence says good IoT rules look like
Indonesian scholars have argued for years that the country needs a coherent IoT framework. A 2017 analysis in a Komdigi-affiliated research journal identified security standards, covering data protection, network security and application security, and device standards including authentication and device security, as the regulatory parameters that needed to be set. A 2024 paper in an academic proceedings series likewise called for a comprehensive framework that includes security vulnerability response. Neither paper treats a local-representative rule as the centre of the solution.
The technical content is better supplied by standards than by representation requirements. ETSI EN 303 645, the consumer IoT baseline published in June 2020, sets out 13 cybersecurity provision areas, among them no universal default passwords, a means to manage vulnerability reports, and keeping software updated. Those are the behaviours that reduce real-world compromise. A local representative is a delivery mechanism for accountability; it does not make a device secure. The EFF made the same general point about a different domain in its September 2026 commentary on AI cybersecurity rules: legislation should be tied to well-established, evidence-backed security practices that can evolve, rather than prescriptive rules aimed at today's technology.
A proportionate design for RUU KKS
The committee can close the gap without a blanket rule. We would suggest four drafting choices.
- Tier by risk. Require a local representative only for vendors whose products are supplied to designated critical or strategic systems, or exceed a defined deployment threshold, with an exemption for low-volume and low-risk products.
- Define the duties in the statute. Specify the representative's role in incident notification, documentation retention and cooperation, with fixed response times, rather than leaving them to implementing regulation.
- Anchor requirements to a published baseline. Point to a named technical standard such as ETSI EN 303 645, or an Indonesian national equivalent, so firms know what compliance means before an audit.
- Bound the audit and penalty powers. Limit audits to security conformity, protect trade secrets and source code, and make penalties proportionate and appealable.
The EU's own sequencing is instructive. According to the European Commission, CRA vulnerability-reporting obligations begin on 11 September 2026, and the main obligations apply from 11 December 2027, giving manufacturers a long runway. Indonesia need not copy that regime. But a bill that creates a central authority and then leaves vendor accountability to be worked out later gets the order wrong.
Bottom line
Amelia Anggraini identified a real hole, and the committee should fill it. The risk is filling it bluntly. A tiered, clearly defined representative duty, paired with a published security baseline, would give BSSN a counterpart where it matters and keep smaller connected-device makers in the market.