Digital platforms developed or managed by Panamanian government institutions that provide citizens with access or interaction must, before being deployed to production, undergo an evaluation and receive authorization from the National Authority for Government Innovation (AIG).
The measure was established through Resolution No. 18 of June 15, 2026, which defines the process and requirements that the entities responsible for these technological solutions must comply with.
Subsequently, through Resolution No. 36 of August 13, 2026, AIG approved an Application Guide that sets out technical criteria, risk classification, requirements, and the workflow for the pre-production evaluation. The goal is for solutions to reach production with verifiable levels of security, functional quality, and performance, applying controls proportionate to each platform's level of risk.
Which platforms must be evaluated by AIG?
Resolution No. 18 establishes that platforms, systems, applications, or technological solutions with citizen access or interaction, developed or managed by government institutions, must undergo AIG's evaluation and authorization process before being deployed to production.
The Application Guide complements this provision by establishing technical criteria and a risk classification to determine the depth of the controls and evidence required according to the characteristics of each solution.
How will the application process with AIG work?
The responsible entity must submit an Evaluation Request to AIG together with the required documentation and evidence.
Once the request has been submitted, AIG will have up to 15 days to evaluate it and issue a response. As a result, it may authorize deployment to production or request corrections and adjustments supported on technical grounds.
What tests and documents must institutions submit?
The requirements include validation of cybersecurity testing and evidence that any identified critical and high-severity vulnerabilities have been corrected or mitigated and subsequently validated.
In addition, depending on the risk level and characteristics of the solution, evidence of functional testing and the results of load and stress testing must be submitted to validate the platform's expected performance.
The Application Guide details the scope of these tests under a principle of proportionality: not all platforms require exactly the same level of evaluation.
Who can conduct the independent cybersecurity assessment?
The Application Guide clarifies that the independence of the assessment is a key element of the process. The provider that developed, implemented, or maintains the solution may not act as the independent cybersecurity assessor of its own work.
Depending on the case, validation may rely on independent capabilities within the institution, another public entity with specialized capabilities, or an external provider.
This does not mean that all tests must be performed by a third party: functional tests and load and stress tests may be carried out by the development team or by the institution itself, provided that the corresponding evidence is generated.
What happens to digital platforms that are already in production?
The Application Guide clarifies that platforms that were already in production when Resolution No. 18 entered into force may continue operating and do not require a new evaluation solely because they are already active.
However, a new evaluation may be required when there is a major change to the solution, for example, the addition of transactional features or relevant changes to its architecture, technology, or data handling.
For this reason, institutions must assess the regulatory impact not only when launching a new platform, but also when planning significant updates to existing systems.
What happens if the platform is not included in the Digital Agenda or is not integrated with Panamá Conecta?
When a platform is not contemplated within the institution's Digital Agenda or is not integrated with Panamá Conecta, the entity must submit the corresponding justification to AIG as part of the evaluation process.
The Application Guide expands the criteria related to Panamá Conecta and allows the applicable form of integration to be analyzed according to the characteristics of each solution.
Can a platform be deployed to production without AIG authorization?
No, when the solution falls within the scope of Resolution No. 18. The regulation prohibits the deployment to production of systems, platforms, applications, or technological solutions with citizen access or interaction that have not completed the established review, validation, and approval processes or do not have the corresponding authorization.
In the event of non-compliance, the resolution provides for the temporary or permanent suspension of the platform's operation.
This means that the AIG evaluation must be incorporated into the project timeline rather than treated as a procedure to be considered only after development has been completed.
How does this regulation relate to the cybersecurity controls established by AIG?
Resolution No. 18 forms part of a broader framework aimed at strengthening cybersecurity in Panama's public sector.
On May 14, 2026, Resolution No. 7 established minimum cybersecurity controls for the information systems of public entities, including measures related to Internet-exposed assets, updates and patching, multi-factor authentication, malware protection, segmentation and protection of exposed systems, restrictions on administrative access, and periodic penetration testing, among others.
The pre-production evaluation therefore adds to the security obligations that institutions must consider throughout the life cycle of their digital systems and services.
What should entities and technology providers working with the Panamanian government consider?
The main practical change is that security, testing, and documentation requirements must be considered from the project planning and procurement stages.
This means defining from the outset the responsibilities of each participant, the required tests, the generation of evidence, vulnerability management, the time needed for the AIG evaluation, and, where applicable, the participation of an independent cybersecurity assessor.
Incorporating these requirements from the earliest stages helps reduce rework, unforeseen costs, and delays before deployment to production.
How can OYDIA support compliance with cybersecurity requirements?
The new regulation reinforces the importance of having technically sound and independent security assessments when applicable.
OYDIA has experience in offensive cybersecurity, security auditing, vulnerability assessment, and penetration testing for organizations in regulated sectors and government entities. These capabilities can support organizations in identifying, prioritizing, and validating security risks within their technology projects.
Each project must be analyzed according to its scope and the applicable AIG requirements.
Does your institution need to assess the security of a digital platform?
If your organization is preparing a new platform, a significant update, or needs to strengthen the security of an existing solution, talk to the OYDIA team to assess the project's cybersecurity needs.
Contact us!Official sources
