Skip to content

Curaçao puts cybersecurity at centre of next stage in gambling reform

Garance Limouzy
Written by Garance Limouzy

Curaçao’s gambling overhaul is moving from licensing mechanics to the security of the systems behind the island’s online gaming industry, with draft Curaçao Gaming Authority requirements proposing a mandatory cybersecurity baseline for B2C operators and B2B suppliers.

The draft information security controls come after months in which the regulator has tightened the framework around the Landsverordening op de Kansspelen, or LOK, Curaçao’s new gambling law. That process has included revised fee rules and extended reviews of provisional licences. The new document says the rules are intended “to ensure the operator provides a safe and secure gaming environment to its players” and confirms that “compliance with these requirements constitutes a mandatory condition of licensure under the LOK.”

Security as a licensing test

Curaçao’s reform programme is no longer only about who holds a licence, pays which fee, or sits on the public register. It is moving into how companies protect player data, payment flows, RNGs, sports data feeds, logs, backups, privileged accounts and third-party platforms.

Under the CGA’s proposed cybersecurity rules, every licensed gambling business in Curaçao, including B2C operators and B2B suppliers, would have to meet a mandatory basic security standard known as CIS Controls Implementation Group 1, or IG1.

The baseline covers asset inventories, secure configuration, access controls, vulnerability management, audit logging, anti-malware, backups, network security, staff training, vendor oversight, incident response, physical security, business continuity and cryptographic controls.

In practice, that means Curaçao-licensed companies would need to prove they know what technology they use, who has access to it, how it is protected, how quickly weaknesses are fixed, and what happens if something goes wrong.

For smaller operators, the rules turn cybersecurity from a general IT concern into a licensing obligation. For larger groups and suppliers, they create a clearer audit trail: security controls must be documented, tested and available for review by the regulator.

Suppliers pulled into the net

The new controls also sharpen the division of responsibility between operators and suppliers. B2B technology providers are treated as licensees in their own right, not merely as outsourced vendors sitting behind a B2C brand.

The CGA says the rules apply to “all holders of a CGA license, regardless of whether they operate in a B2C or B2B capacity.” It adds that B2B gaming technology providers are subject to the requirements “in their own right as CGA licensees.”

For B2C operators using third-party platforms, the regulator stops short of requiring direct control over a supplier’s internal systems. But it does require due diligence, contractual assurance and monitoring. The document states: “Contractual delegation of operational controls to a B2B provider does not relieve the B2C licensee of its regulatory accountability under the LOK.”

That approach mirrors the wider LOK transition. The cybersecurity rules follow the CGA’s release of Version 2.0 of its fee framework under the LOK regime, which confirmed that the licensing structure applies to both B2C operators and B2B service providers.

Incident reporting gets a hard deadline

The draft cyber rules would also introduce a strict incident notification standard. Licensees would have to notify the CGA “without undue delay, and in any event within 24 hours” of any security incident that compromises gaming integrity, affects player funds or personal data, or may affect reporting, system availability or game fairness.

For an industry built on outsourced platforms, live odds feeds, game aggregators and payment processors, this may prove one of the most demanding parts of the regime. Sports betting operators, in particular, are told to monitor the integrity of live event data feeds, with controls for authentication, encryption, anomaly detection and suspension of markets when integrity cannot be assured.

The measures are part of Curaçao’s effort to present the LOK regime as a more conventional regulatory framework, with licensing, fee compliance and cybersecurity treated as connected obligations. For operators, the practical effect is that approval under the new system may depend not only on corporate and financial checks, but also on whether their technology controls can stand up to regulatory scrutiny.

Don’t just read the news — stay ahead of it. Subscribe HERE to SiGMA’s Top 10 News countdown for stories shaping iGaming’s future, weekly insights from the world’s biggest iGaming community, and exclusive subscriber-only offers.