CONPES 3995 Explained: Colombia's National Digital Trust Policy

Cumplimiento y regulación
25 Sep 2026, 9:00 a.m. By Juan Carlos Hernandez 💬 0
CONPES 3995 Explained: Colombia's National Digital Trust Policy

Most of Colombia's cybersecurity laws — Law 1581, Law 1273, the sector circulars from the SFC and Supersalud — were born either before or after a document few businesses know about, but which largely explains why all those other rules ended up existing: CONPES 3995 of 2020, the National Digital Trust and Security Policy.

It's not a law that directly fines your business. It's something different, and in a sense more important: it's the document where the Colombian state defined its long-term strategy for cybersecurity across the entire country.

Anatomy of the attack described in the article.

Anatomy of the attack described in the article.

What a CONPES Document Is

Colombia's National Council for Economic and Social Policy (CONPES) is the highest coordinating body for economic and social policy in the country. When the government needs to align multiple entities — ministries, superintendencies, the police, the private sector — around a national objective, it does so through a CONPES document. It isn't a law in the traditional sense; it's an official roadmap with goals, responsible parties, and timelines.

CONPES 3995, approved in 2020, is the specific roadmap for the country's digital trust and security.

What It Set Out to Solve

Before this document, Colombia had scattered cybersecurity rules — the criminal Law 1273, the personal data Law 1581, a handful of sector circulars — but no unified strategy connecting them to a national vision. CONPES 3995 identified several structural problems: incident-response capabilities fragmented across agencies, weak coordination between the public and private sectors on threats, and a growing gap between the speed of the country's digitalization and its real capacity to manage the risks that digitalization brings with it.

The Policy's Main Pillars

While the document uses formal public-policy language, its lines of action boil down to a few concrete goals:

Strengthening national cybersecurity governance, with clearer roles for entities like the Ministry of Information and Communications Technology (MinTIC) and its operational arm, ColCERT, responsible for monitoring and responding to incidents at the national level.

Improving cyber risk management in strategic sectors — energy, healthcare, transportation, the financial system — recognizing that an attack on critical infrastructure has an impact that extends well beyond the directly affected company.

Fostering public-private collaboration, understanding that the state alone can't monitor or respond to the scale of threats facing Colombia's digital ecosystem; it needs the private sector as an active partner, not just a regulated subject.

Driving digital security culture among citizens and businesses, betting that a large part of the problem — phishing remains the most common entry point for successful attacks in the country — gets reduced through education, not just technology.

What This Actually Means for Your Business

CONPES 3995 won't fine you directly. But it does explain the reasoning behind trends that affect you concretely: why the SFC and Supersalud have tightened their sector-specific requirements in recent years, why the government keeps pushing public-private collaboration on incident reporting, and why it's increasingly common for business clients to ask for evidence of a cybersecurity posture before signing a contract — they're responding, even if they don't explicitly know it, to the same national policy pushing toward a more mature culture of digital trust.

In strategic sectors especially, understanding CONPES 3995 helps you anticipate where regulation is heading, instead of reacting once it's already in force.

Frequently asked questions

Is CONPES 3995 legally binding for businesses?

Not directly, the way Law 1581 or sector circulars are. It's a state policy that guides and gives rise to specific regulations, rather than a punitive rule in itself.

What is ColCERT and why does it matter?

It's the Colombian government's Computer Security Incident Response Team, operated under MinTIC. It's the national reference point for monitoring and coordinating the response to significant cyber incidents in the country.

How does CONPES 3995 relate to rules like the SFC's Circular 007?

The sector circular is a concrete manifestation, applied to a specific sector, of the broader objectives CONPES 3995 sets at the national level.

Should my business do anything specific because of CONPES 3995?

Not directly, but it's worth understanding its existence as context: it explains why regulatory requirements in Colombia have been getting stricter, and why that trend will likely continue.

Controls and monitoring that stop the attack.

Controls and monitoring that stop the attack.

Let's talk

Understanding the public policy framework behind Colombian cybersecurity helps you anticipate where regulation is heading, not just react to it. At T.I. RESCUE we track these developments closely, so our [cybersecurity audits](https://tirescue.com/en/auditoria-de-ciberseguridad/) and [consulting](https://tirescue.com/en/consultoria-de-ciberseguridad/) don't just solve today's problem — they leave your business better prepared for what's next. Want to understand how these policies affect your specific sector? [Let's talk](https://tirescue.com/en/contacto-ti-rescue/).

Contact us

You may also like

Comments (0)

Be the first to comment.