Milestones

Milestones: 25 years of international co-operation powered by the Convention on Cybercrime (Budapest Convention)
In 1997, the Council of Europe decided that it was time to negotiate the first international treaty on cybercrime. On 23 November 2001, the Convention on Cybercrime was opened for signature in Budapest and since then 82 countries have become Parties.
The Budapest Convention has been a cornerstone for countries worldwide, offering a model framework that has guided the development of national legislation and institutional capacities aimed at effectively preventing and combating cybercrime.
We invite you to explore below the key milestones!
START HERE
23 November 2001
Convention opens for signature
28 January 2003
1st Additional Protocol on the criminalisation of acts of a racist and xenophobic nature
2001 – 2005
Albania, Croatia, Estonia, Hungary, Lithuania, North Macedonia, Romania, Slovenia, Bulgaria, Cyprus, Denmark join the Convention
1 July 2004
Convention enters into force
2006– 2010
Armenia, Bosnia and Herzegovina, France, Netherlands, Norway, Ukraine, Finland, Iceland, Latvia, Italy, Slovakia, Germany, Moldova, Serbia, Azerbaijan, Montenegro, Portugal, Spain and the United States of America (in 2006), as the first non-member of the Council of Europe, join the Convention
2012
The T-CY begins to carry out assessments of implementation and to adopt Guidance
Read more about assessments and Check the Guidance Notes
2013
Guidance Notes on DDOS attacks, the provisions of the Budapest Convention covering botnets, identity theft and phishing in relation to fraud, new forms of malware and critical information infrastructure attacks.
2014
Cybercrime Programme Office of the Council of Europe (C-PROC) in Bucharest becomes operational
2014
T-CY "Transborder Group" (2012-2014)
Guidance Notes on transborder access to data and spam
Read the Guidance Notes
2011 – 2015
Switzerland, United Kingdom, Australia, Austria, Belgium, Georgia, Japan, Malta, Czech Republic, Dominican Republic, Luxembourg, Mauritius, Panama, Turkey, Canada, Poland, Sri Lanka join the Convention
2016
Guidance Note on terrorism
Read the Guidance Notes
2017
T-CY "Cloud Evidence Group" (2015-2017)
Guidance Note on production orders for subscriber information
Read the Guidance Notes
2019
Guidance Note on election interference
Read the Guidance Notes
2016 - 2021
Andorra, Israel, Liechtenstein, Chile, Costa Rica, Greece, Monaco, Senegal, Tonga, Argentina, Cabo Verde, Morocco, Paraguay, Philippines, Ghana, Peru, San Marino, Colombia, Sweden join the Convention
May 2021
Second Additional Protocol on enhanced cooperation and disclosure of electronic evidence – approved by the Cybercrime Convention Committee
November 2021
Adoption of the 2nd Additional Protocol by the Council of Europe
12 May 2022
Opening for signature of the Second Additional Protocol by the Council of Europe. 22 Parties sign the Second Additional Protocol at the opening for signature conference [Austria, Belgium, Bulgaria, Chile, Colombia, Estonia, Finland, Iceland, Italy, Japan, Lithuania, Luxembourg, Montenegro, Morocco, Netherlands, North Macedonia, Portugal, Romania, Serbia, Spain, Sweden and the United States of America]
2022 – 2026
Another 30 countries sign the Second Additional Protocol [Andorra, Costa Rica, Croatia, Moldova, Slovenia, Sri Lanka, Ukraine, the United Kingdom, Greece, France, Germany, the Dominican Republic, Argentina, Albania, Mauritius, Canada, Malta, Hungary, Cabo Verde, Ghana, Armenia, Georgia, Czechia, Sierra Leone, Paraguay, Peru, Latvia, Fiji, Norway, Bosnia and Herzegovina]
May 2022 – April 2026
Further countries join the Convention, bringing the number of Parties up to 81 [Brazil, Cameroon, Tunisia, Sierra Leone, Grenada, Benin, Fiji, Kiribati, Ecuador, Rwanda, Sao Tome and Principe, Vanuatu, New Zealand] and the number of countries have signed or been invited to accede to 16
November 2022
New Guidance Note adopted by the T-CY - on Ransomware
January 2023
20th anniversary of the First Additional Protocol to the Convention on Cybercrime and Iceland joining the First Protocol
9 February 2023
Serbia becomes the first state to ratify the Second Additional Protocol to the Convention on Cybercrime
August 2023
Japan becomes the second state to ratify the Second Additional Protocol
August 2024
Application of the Budapest Convention was extended to Curaçao, This marks the first time that the Cybercrime Convention is extended by a Party to any other territory.
January 2025
Application of the First Additional Protocol to the Convention on Cybercrime extended to Curaçao. This follows the application of the Budapest Convention having been extended to Curaçao in June 2024, marking the first time the Convention was extended by a Party to any other territory.
June 2025
The T-CY adopts a new Guidance Note, on Spontaneous Information.
5 February 2026
Hungary became the third state to ratify the Second Additional Protocol, after Serbia and Japan in 2023
15 April 2026
Costa Rica becomes the fourth state to ratify the Second Additional Protocol, after Serbia, Japan and Hungary