Table of Contents

UN framework of responsible State behaviour in cyberspace

As of 30 September 2026. Information only, not legal advice – see the disclaimer.

Full title UN framework of responsible State behaviour in the use of ICTs
Type Consensus reports of UN Groups of Governmental Experts and Open-ended Working Groups, endorsed by UN General Assembly resolutions (soft law; voluntary, non-binding norms alongside applicable international law)
Adopted by UN Groups of Governmental Experts (GGE); Open-ended Working Groups (OEWG); UN General Assembly
Adopted Principal texts: GGE report A/70/174 (22 July 2015); OEWG report A/75/816 (March 2021); GGE report A/76/135 (14 July 2021); OEWG 2021–2025 final report (11 July 2025, A/80/257, Annex I), endorsed by GA resolution 80/16 (1 December 2025)
Legal status Norms are voluntary and non-binding; the reports state that existing international law, in particular the UN Charter, applies to the use of ICTs by States. Follow-up: permanent Global Mechanism on developments in the field of ICTs in the context of international security, operational since March 2026
Official text UN Doc. A/70/174 (GGE 2015) · UN Doc. A/80/257 (OEWG 2021–2025 final report)
Subject area UN processes and institutions; Cybersecurity, cybercrime and critical infrastructure

Overview

The “framework of responsible State behaviour in the use of ICTs” is the term used in UN documents for a set of consensus outcomes developed since 2010 in the UN First Committee track. It consists of four elements: the applicability of international law, voluntary non-binding norms of responsible State behaviour, confidence-building measures, and capacity-building. The eleven norms in paragraph 13 of the 2015 GGE report (A/70/174) are its core; the General Assembly called upon Member States to be guided by that report in resolution 70/237. The framework was reaffirmed and elaborated by the 2021 OEWG and GGE reports and by the final report of the OEWG 2021–2025. It is referred to in debates on the protection of critical infrastructure, attribution of cyber incidents and the limits of State cyber operations in peacetime.

Provisions relevant to the cyber and information sphere

Application to cyber and information operations

The norms are cited by States in public attributions of cyber operations, in particular norm 13(f) on critical infrastructure. States disagree on several points: some States, including the Russian Federation and others, have proposed a legally binding instrument on international information security; many other States hold that existing international law, complemented by voluntary norms, is sufficient. How international humanitarian law applies to ICT operations in armed conflict and how rules on State responsibility and attribution apply remain under discussion. National positions on international law are compiled in UN Doc. A/76/136. The Global Mechanism operates by consensus.

Recent developments

Sources

Change log