🎉

Thank You for Subscribing!

You'll now receive our latest updates, legal insights, and exclusive offers directly in your inbox.

← Back to Legal Updates
event August 27, 2026 description Legal Update

Ethiopia Enacts Critical Infrastructure Cybersecurity Proclamation

The House of Peoples' Representatives has enacted the Critical Infrastructure Cybersecurity Proclamation No. 1426/2026, establishing a comprehensive legal framework for the protection of Ethiopia's strategic infrastructure from cyber threats. Published in the Federal Negarit Gazette on 21 July 2026, the Proclamation will enter into full force on 21 July 2027.

The legislation arrives amid Ethiopia's ongoing digital transformation, addressing the growing frequency and sophistication of cyberattacks targeting national infrastructure. During the first half of fiscal year 2025/2026 alone, the Information Network Security Administration recorded 27,773 cyberattacks. The Proclamation establishes obligations for infrastructure owners, creates a dedicated funding mechanism, introduces a licensing regime for cybersecurity service providers, and prescribes penalties for non-compliance.

The Proclamation applies throughout Ethiopian territory and extends to designated critical infrastructures located outside the country. It also applies to persons providing cybersecurity products or services.

Critical infrastructure is defined as any public or private infrastructure or institution whose disruption or compromise due to a cyberattack would have a significant negative impact on national security or national interests. The definition encompasses both public and private entities operating in designated sectors.

The Proclamation identifies twelve critical infrastructure sectors: Information Technology and Communication, Finance, Security and Public Safety, Transport, Education, Health, Water and Energy, Government Services, Emergency and Disaster Response Services, Agriculture, Trade and Commerce, and Industry. The Administration retains authority to designate additional sectors through directives, subject to minimum criteria established in the Proclamation.

For infrastructure to be designated as critical, a cyberattack must pose a threat to the economy, social interaction, and daily life of the community, or adversely affect national security, peace and stability, diplomacy, or sovereignty. There must also exist a high level of interconnectedness such that damage would spread to other critical infrastructure sectors. Infrastructure that ceases to meet these requirements may be removed from critical infrastructure status following appropriate assessment by the Administration. Please read the full detals from the attachement.