Are listed-sector organizations automatically critical infrastructure?
No. INSA must designate specific infrastructure and notify its owner. Sector membership is a reason to investigate, not the final decision.
These are navigation answers, with the relevant article or official source attached.
No. INSA must designate specific infrastructure and notify its owner. Sector membership is a reason to investigate, not the final decision.
Not yet. It was published on 21 July 2026 and is expected to take effect on 21 July 2027. Other Ethiopian laws already apply.
A designated critical-infrastructure owner. Article 7 places the duty on the owner. The official reporting system and later rules control the operational details.
Yes, in principle. Articles 16–20 create the framework, but a directive must identify which products and services are covered.
A current-law map, the future proclamation and the questions that still need counsel or regulator confirmation.
Open the legal map IT, SECURITY & RISKMap controls to evidence: records that show a policy, decision or security activity really happened.
See the technical lens INCIDENT TEAMSPrepare the essential facts and submit directly to Ethio-CERT or INSA.
Open incident guidance BUYERS & PROJECT OWNERSTypical duration, participants, inputs and sample deliverables are stated before you contact us.
Compare packagesGCI commitment score
ARTICLE 718Published owner duties
ARTICLE 7(14)48 hoursFuture notice period for covered owners
ARTICLE 22ETB 2MTop stated range for specified violations
Use the guides, sources and navigator to understand the published framework. No account or organization data is needed.
If you need interviews, document review, gap analysis or a tailored roadmap, compare the consulting packages.
See packagesSee the package structure first, or send only your sector and the decision you are preparing for. Do not send sensitive incident or system data.