CyberMela
አማ
Research prototypeLegal explanations are source-led but not yet reviewed by an appointed Ethiopian legal reviewer.About this status
Source-led • Reviewed 10 August 2026

CyberMela helps visitors understand Ethiopia’s cybersecurity rules, explore critical-infrastructure designation indicators, find the right INSA or Ethio-CERT service, and reach official cyber-incident reporting channels.

Understand the source. Find the official service. Take the right next step.

Source-led explanations and direct official links—without giving us technical access or incident data.

No system scanning No incident details collected Official sources linked
Independent guidanceNot INSA, Ethio-CERT or a legal authority
Official source trailClaims trace to INSA or Ethio-CERT
English and AmharicEquivalent routes in both languages
Privacy-minimizingNo organization or incident details collected
Current legal status

Proclamation No. 1426/2026 was published on 21 July 2026. Article 28 states that it enters into force one year after publication—21 July 2027. Implementing directives may change the practical requirements.

Read the official PDF
12named sectorsArticle 4
18owner dutiesArticle 7
48hincident noticeArticle 7(14)
1 yeardelayed effectArticle 28
CHOOSE YOUR NEXT STEP

Start with what you need to do

Find the relevant official source, understand the published rule, or explore the indicators—without sending CyberMela company or incident information.

OUR PRODUCT BOUNDARY

Information and official navigation. Nothing hidden.

The platform explains public rules, offers an answer-based educational navigator and directs visitors to the responsible government source. It does not inspect systems, test vulnerabilities, determine designation or compliance, make legal decisions or submit reports for you.

No technical assessment or saved answers

The navigator uses selections in the current browser tab only. No readiness scores, organization profiles, evidence uploads or incident details are collected.

Traceable guidance

Article references, direct source links, review dates and visible uncertainty notes.

Official handoff

Incident reporting sends you to the government channel. We never act as the receiving intermediary.

POPULAR QUESTIONS

The short answer first

Fast, article-referenced answers to the questions organizations ask first. Use the linked guide and official text before making an organization-specific decision.

Primary source: INSA PDF

Which sectors are named in the proclamation?

Twelve sectors are listed. They are ICT, finance, security and safety, transport, education, health, water and energy, government services, disaster management, agriculture, trade and industry. INSA may identify additional sectors.

Review sector scope
SHORT ANSWERArticle 4(3)

What factors can make infrastructure important enough for designation?

The possible impact of a cyberattack matters. The published criteria look at effects on the economy, society and daily life; national security and sovereignty; and whether disruption could spread across interconnected critical-infrastructure sectors. A future directive may add criteria.

Explore the published indicators
SHORT ANSWERArticle 5(1)

How should an organization know that its infrastructure was designated?

Look for an official INSA notification. Article 5 says designation is made through a directive and the owner is notified. CyberMela cannot authenticate a notice or decide what it covers; confirm its scope directly with INSA or qualified Ethiopian counsel.

See the designation path
SHORT ANSWERArticle 6

Can critical-infrastructure designation later be removed?

Yes, after an INSA assessment. Article 6 says INSA may remove infrastructure that no longer meets the relevant criteria. The proclamation also says its protection for that infrastructure then ends.

Read the scope explanation
SHORT ANSWERArticle 28

Is Proclamation No. 1426/2026 already in force?

Not yet. It was published on 21 July 2026. Article 28 says it enters into force one year after publication, which points to 21 July 2027. Existing laws and INSA powers may still apply independently.

Check the legal-status note
SHORT ANSWERArticle 7(14)

Who has the 48-hour cyber-incident notification duty?

Article 7 places it on a critical-infrastructure owner. The owner must notify the National Computer Emergency Response Center within 48 hours using the system established by INSA. The published text leaves some operational details to the official system and future directions.

Find the official reporting route
SHORT ANSWERArticle 16

Does the proclamation create licensing for cybersecurity providers?

Yes, but important details still depend on an INSA directive. Article 16 creates an INSA licensing regime for cybersecurity products and services. The exact service types, application process, licence content, renewal, oversight and related procedures are to be detailed by directive.

Read the provider-licensing guide