When cybersecurity becomes a matter of national security, compliance can no longer be another item on the to-do list. For Indonesian organizations, BSSN was a means of reassurance that policies, people, and technical controls were really doing the business.
That is important because the BSSN is not simply an advisory body. It is responsible for performing the executive body’s responsibilities in the field of cybersecurity and encryption, including technical policy, standards, procedures, criteria, guidance, and supervision, as provided for by Presidential Regulation 28/2021. It is the task of organizations to demonstrate security discipline, especially with systems handling sensitive information or providing critical services.
Table of Contents
ToggleWhy BSSN Compliance Is Important
Established and empowered by Presidential Regulation No. 28 of 2021 of the National Cyber and Crypto Agency, it provides security guidance and conducts technical conformity assessments of IT security products and systems.
Compliance is not just about avoiding future problems; it is about earning trust now. Companies with a degree of security governance maturity, security training, and technical control maturity will have an edge in working with regulated industries, partners, and customers that require evidence of security. In practice, this is often the difference between winning a contract and losing it.
BSSN compliance is not in a vacuum. It is connected with other regulations, such as Government Regulation No. 71 of 2019 and UU PDP. “Think of it as one compliance program rather than a separate task.
Book a Free
Demo Call
with Our Expert
Discover how Threatcop protects your workforce from modern cyber threats.
Key Requirements for BSSN Compliance
Cybersecurity Governance
Accountability is the starting point of a good compliance program. BSSN’s regulatory model embeds cybersecurity into the formal government structure, so it should not be assumed as just an IT responsibility.
It should comprise:
- An assigned cybersecurity owner or function
- All policies and standards are written very clearly, so they are easy to understand for different teams
- Management review on a regular basis
Ownership at the highest level is very important to ensure consistency.
Technical Standards and Control Baselines
BSSN’s role is to develop norms, procedures, and criteria in cybersecurity and encryption. That makes technical controls, in a standardized way, an integral part of compliance readiness.
Having secure defaults, proper authentication, and logs that you can actually read.
Security Assessment
The enactment of BSSN Regulation No. 7 of 2024 regarding the Indonesian Common Criteria for Information Technology Security Evaluation adds a new layer of security assurance. It describes the process of conformity assessment of IT security products. For many organizations, compliance is more than policy. It also includes product and system assurance.
Incident Response Preparedness
Under BSSN Regulation No. 1/2024, Electronic System Operators, especially those operating vital information infrastructure, must set up a CSIRT and report incidents to the national CSIRT within 24 hours. Check the current regulations to determine the exact reporting window that applies to your sector.
The following are examples of requirements for incident readiness under these regulations:
- An incident response plan is documented and is consistent with BSSN Regulation.
- In line with BSSN Regulation No. 2/2024, cyber crisis contingency planning is being conducted.
Think for yourself: can your team identify the incident owner and report it without any pressure or scrambling?
Human Awareness and Training
Security awareness and resilience are part of the compliance process, which means training cannot be treated as just another task employees need to do for the sake of it.
That’s why training in Indonesia is important. It includes:
- Phishing awareness.
- Account and password security.
- Handling and reporting of data discipline.
- Suspicious activity escalation.
- Role-specific security behavior.
General awareness is the starting point; role-based learning is the practical part of the training that is useful.
Evidence and Documentation
Compliance only matters if you can prove it. If an organization claims it has policies and everything in place, it should be able to provide documentation to back up those claims.
It includes:
- Training records
- Incident drill and contingency-plan simulation reports (per BSSN Regulation No. 2/2024)
- Security logs
- Monitoring outputs
Even good controls can look incomplete during review.
How Threatcop Actually Fits BSSN Compliance
Threatcop enables compliance with BSSN on two levels: the technical and the human layers.
On the technical side, TDMARC authenticates email and stops domain spoofing. TDMARC‘s DMARC Record Checker reveals if a domain has a DMARC record.
On the human side:
- TSAT conducts phishing, vishing, smishing, and ransomware simulations to prepare employees.
- TLMS provides target-specific, role-based security training.
- TPIR accelerates the processing and response to phishing reports.
It‘s not just about controls written into compliance. It‘s all about having employees who can identify threats, report quickly, and follow procedure. Threatcop encapsulates that element.
BSSN Compliance Training Indonesia Should Prioritize
- Get the fundamentals right – phishing, suspicious links, password security, reporting.
- The IT team, compliance team, and executive team will be required to have varying degrees of depth and responsibility.
- Phishing simulations to check training efficacy in stressful situations.
Why This is Important for Business Resilience
Resilience is key to BSSN compliance. Organizations that combine governance, employee awareness training, and evidence are better equipped to address incidents and meet partner expectations. The ideal compliance stance for Indonesian businesses is repeatable. This should not rely on a person’s memory or, importantly, on a one-off audit every year. It should be a routine part of everyday working practices, backed up by control, documentation, and training.
The Bottom Line
BSSN compliance is more than just following the regulations. It embodies a clear cybersecurity methodology across its business practices, governance, and technical processes.
Platforms like Threatcop can help organizations improve security awareness, deliver 24/7 training, and track evidence for audit readiness. The main requirement for all Indonesian businesses is resilience.
FAQs
What is BSSN compliance?
BSSN compliance is a process that requires an organization to comply with BSSN requirements for cybersecurity governance and technical security.
Why is compliance training important for BSSN in Indonesia?
It teaches employees about cyber threats and what to do if they see them. This reduces phishing risk and helps secure the operation of day-to-day business.
Who are the companies subject to BSSN compliance?
The requirements vary depending on the sector and whether an organization operates a critical information infrastructure. Check the applicable regulations to find out what applies to you.

Purva is a Technical Content Strategist at Threatcop with an MBA in Business Analytics, specializing in SEO-driven content and technical editing across IT and digital domains, and is the author of the book From a Daughter’s Eye.
