Perpres 95/2018 SPBE · evaluated under Pemdi | Electronic-based government for every institution. The evaluation itself changed in 2026: PermenPANRB 8/2026 replaced the old SPBE index with Evaluasi Kinerja Pemerintah Digital, running now across 645 institutions with external academic assessors and weighted toward service impact and citizen satisfaction rather than ICT maturity documentation. | Prepare against the instrument being applied this cycle rather than the one most institutions still hold evidence for — the emphasis moved, and documentation built for the old domains does not answer the new questions. | Evidence mapped to the current cycle |
Perpres 47/2023 Presiden RI | National Cyber Security Strategy across eight pillars, including protection of vital information infrastructure, preparedness and resilience, and national cryptographic independence. | Build against the pillars your institution owns, with the resilience pillar treated as an operational exercise rather than a policy document. | Tested playbooks, trained responders |
BSSN SPBE security BSSN | Security standards for SPBE, including audit of application and infrastructure security, and establishment of an institutional CSIRT. | Application and infrastructure assessment, and CSIRT stand-up that survives the person who set it up moving on. | Assessed estate, operating CSIRT |
PP 71/2019 Republik Indonesia | Electronic system obligations for public-scope operators, including where systems and data may be placed. | Architecture and deployment where residency is documented as a data path rather than asserted in a clause. | Documented data path, residency evidence |
UU PDP Republik Indonesia | Lawful processing, impact assessment and notification of a personal data breach within 72 hours. State bodies are within scope. | Governance and runbooks written for institutions where the notification decision crosses more than one authority and nobody wants to sign first. | DPIA records, notification runbook, RACI |
Perpres 16/2018 as amended by Perpres 46/2025 | Government procurement rules that determine what can be bought, on what schedule, and against which budget line. | Scope engagements to fit DIPA reality and procurement categories — a proposal that cannot be procured is not a proposal, however good the security in it. | Procurable scope, phased against budget |