
Ethiopia’s New Critical Infrastructure Cybersecurity Law
Ethiopia's digital economy is expanding rapidly. Driven by the **Digital Ethiopia 2030** strategy, mission-critical operations—from national digital ID (Fayda) and interoperable mobile payment rails to e-procurement—are now digital-first. With this expansion, the attack surface has grown dramatically.
Ethiopia's digital economy is expanding rapidly. Driven by the **Digital Ethiopia 2030** strategy, mission-critical operations—from national digital ID (Fayda) and interoperable mobile payment rails to e-procurement—are now digital-first. With this expansion, the attack surface has grown dramatically.
To defend essential digital assets against increasingly sophisticated cyber threats, the House of Peoples' Representatives officially enacted the Critical Infrastructure Cybersecurity Proclamation (No. 1426/2026) .
Administered and enforced by the Information Network Security Administration (INSA) , this legislation introduces enforceable cybersecurity baselines, mandatory breach disclosure timelines, heavy administrative fines, and executive criminal liability for non-compliance.
Understanding Proclamation No. 1426/2026
Published in the Federal Negarit Gazette, the proclamation establishes a standardized legal and technical framework governing both state enterprises and private institutions.
The 1-Year Transition Window
Under Article 28, the Proclamation grants organizations a one-year grace period from its date of publication in the Federal Negarit Gazette before enforcement and penalties take full effect. During this transition window, INSA is rolling out sector-specific directives, technical baseline standards, and assessment criteria to give covered entities time to audit, re-architect, and harden their infrastructure.
The 12 Designated Critical Infrastructure Sectors
The statutory definition of "Critical Infrastructure" covers any public or private facility, network, or information system whose compromise would cause a substantial negative impact on national security, public health, or economic stability.
The law designates 12 critical sectors:
| Category | Designated Sectors |
|---|---|
| Core Utilities & Technology | 1. Information Technology & Communications (ICT) |
| Core Utilities & Technology | 2. Water & Energy |
| Core Utilities & Technology | 3. Transport & Logistics |
| Financial & Civil Services | 4. Finance & Banking |
| Financial & Civil Services | 5. Government Public Services |
| Financial & Civil Services | 6. Emergency & Disaster Response Services |
| Public Welfare | 7. Health (Hospitals, Clinics, Diagnostic Labs) |
| Public Welfare | 8. Education (Higher Education, Testing & Research Centers) |
| Public Welfare | 9. Security & Public Safety |
| Commerce & Production | 10. Agriculture & Food Supply Chains |
| Commerce & Production | 11. Trade & Commercial Systems |
| Commerce & Production | 12. Industry & Manufacturing |
Key Compliance Mandates & Penalties
The proclamation places 18 core cybersecurity obligations on critical infrastructure operators. The most critical operational requirements include:
Mandatory 48-Hour Incident Disclosure
Operators must report any confirmed cyberattack or data breach to the National Computer Emergency Response Center (National CERT) within 48 hours of detection.
Severe Administrative Fines
Failing to notify the National CERT within the 48-hour window or neglecting mandated corrective actions triggers administrative fines ranging from 1.5 million to 2.0 million ETB, with repeat violations subject to triple the maximum penalty.
Personal Liability for Leadership
Article 25 introduces criminal liability for corporate executives and IT leadership. Reckless negligence or intentional failure to implement mandatory protections resulting in critical service disruption carries statutory prison terms ranging from 3 to 10 years.
Pre-Deployment & Supply Chain Clearance
Uninspected or uncertified IT hardware, third-party software, and web applications cannot be integrated into production environments without prior technical clearance. Deploying uncertified systems risks fines up to 1.0 million ETB.
Mandatory Cyber Audits & Risk Assessments
Entities must conduct periodic threat impact assessments and undergo formal cybersecurity audits evaluated or certified by INSA.
Accredited Personnel & SOC Deployment
Security operations must be staffed by professionals holding certifications recognized or issued by INSA, backed by a dedicated Security Operations Center (SOC) for continuous monitoring.
National Critical Infrastructure Cyber Fund
Establishes a permanent, self-sustaining fund financed via mandatory operator contributions, service fees, and administrative penalties to support national incident response, research, and technical capacity building.
The INSA Secure Website Management Standard
Because web portals and APIs are the most exposed vector for initial access, critical digital assets must comply with the lifecycle-based INSA Secure Website Management Standard:
1. Secure SDLC
Applications must be architected following secure coding and defensive design principles from day one.
2. Pre-Hosting Accreditation
Public-facing portals and institutional websites must pass comprehensive security testing and receive accreditation prior to production hosting.
3. Data Sovereignty & Local Hosting
Critical infrastructure systems and government websites must be hosted on-premises or within verified, secure data center infrastructure inside Ethiopia.
4. Routine Vulnerability Testing
Mandates quarterly vulnerability assessments and continuous configuration monitoring to eliminate zero-day and unpatched risks.
How AXUM SEC Prepares Your Organization for Full Compliance
Compliance is not a last-minute paperwork exercise; it requires continuous operational security.
As Africa's dedicated offensive cybersecurity and crowd-sourced security platform, AXUM SEC provides the offensive tooling, continuous monitoring, and local expertise required to satisfy the rigorous mandates of Proclamation 1426/2026.
1. Pre-Audit Security Assessments for INSA Certification
While official compliance certification is issued under INSA's regulatory authority, organizations must first uncover, validate, and remediate vulnerabilities to pass that audit.
Our Penetration Testing as a Service (PTaaS) delivers:
- Attack Surface Discovery: Automated identification of unpatched assets, open ports, exposed development environments, and leaked keys.
- Human-Validated Penetration Testing: Thorough testing conducted by vetted offensive security researchers and certified penetration testers, eliminating noisy false positives.
- Audit-Ready Evidence: Comprehensive remediation and risk mitigation reports formatted to align with INSA's technical assessment baselines.
2. Continuous Vulnerability Management via Managed Bug Bounty
Point-in-time penetration tests leave systems vulnerable between audits. Through AXUM SEC's managed bug bounty programs, your web platforms, mobile apps, and core APIs are continuously evaluated against real-world evasion tactics 24/7/365, satisfying statutory vulnerability management obligations.
3. Rapid Incident Triage for 48-Hour National CERT Compliance
Meeting the statutory 48-hour incident reporting window requires immediate clarity on whether an anomaly represents an active breach or benign telemetry. AXUM SEC's vulnerability monitoring and rapid incident triage workflows help internal engineering teams detect, isolate, and document security flaws before they escalate into reportable regulatory disasters.
4. Tailored to the Ethiopian Operating Environment
- Local Currency Billing: Avoid foreign currency bottlenecks. Enterprise subscriptions and bounty pools are payable directly in Ethiopian Birr (ETB) .
- Headquartered in Addis Ababa: Incubated at the Ethiopian Artificial Intelligence Institute, our team works directly within Ethiopia's tech ecosystem, with deep familiarity with local payment switches, telecom infrastructure, and regulatory directives.
- Pre-Deployment Code Hardening: Fast-turnaround Static and Dynamic Application Security Testing (SAST/DAST) ensures your software passes pre-deployment criteria before you submit it for state licensing and INSA accreditation.
Immediate Next Steps for the 1-Year Transition Period
With the grace period running, organizations must take proactive steps across technical and legal workflows:
1. Conduct a Sector Applicability Review
Determine which digital assets, data stores, and subsidiaries fall within the 12 critical infrastructure definitions.
2. Execute an External Surface Scan
Map and patch publicly accessible vulnerabilities, unauthenticated endpoints, and remote management interfaces.
3. Formalize the 48-Hour Incident Workflow
Establish a clear chain of custody, incident classification matrix, and notification procedure to ensure reporting to the National CERT occurs within statutory timelines.
4. Audit Third-Party Software & Supply Chains
Catalog external vendors and software dependencies to ensure they meet INSA pre-deployment clearance requirements.
Statutory & Regulatory References
- Federal Negarit Gazette: Critical Infrastructure Cybersecurity Proclamation No. 1426/2026
- Information Network Security Administration (INSA): Secure Website Management Standard & Critical Mass Cyber Security Requirement Standards (CMCSRS)
- National Strategy: Digital Ethiopia 2030
Disclaimer: This publication is prepared for informational and operational guidance purposes only and does not constitute formal legal counsel. Organizations should review the published text of Proclamation No. 1426/2026 in the Federal Negarit Gazette and consult qualified legal advisors and INSA directives for sector-specific regulatory thresholds.