Start with what you need to do
Find the relevant official source, understand the published rule, or explore the indicators—without sending CyberMela company or incident information.
Could your infrastructure fall within the designation signals?
Six guided questions based on Articles 4–5. No account, uploads, saved answers, compliance score or legal determination.
Explore the designation indicators PRIMARY GUIDEWhat does Proclamation 1426/2026 require?
Scope, designation, the 18 owner duties, enforcement, timing and open questions.
Read the article-by-article guide INCIDENT GUIDANCEHow do I report a cyber incident in Ethiopia?
What to prepare, what not to send to us, and links to the official channels.
View reporting guide LIVE OFFICIAL DIRECTORYFind the right INSA or Ethio-CERT destination
Task-based official links, current Ethio-CERT GCI data and regularly refreshed government publications.
Open official source hubInformation and official navigation. Nothing hidden.
The platform explains public rules, offers an answer-based educational navigator and directs visitors to the responsible government source. It does not inspect systems, test vulnerabilities, determine designation or compliance, make legal decisions or submit reports for you.
The navigator uses selections in the current browser tab only. No readiness scores, organization profiles, evidence uploads or incident details are collected.
Article references, direct source links, review dates and visible uncertainty notes.
Incident reporting sends you to the government channel. We never act as the receiving intermediary.
The short answer first
Fast, article-referenced answers to the questions organizations ask first. Use the linked guide and official text before making an organization-specific decision.
Is every organization in a listed sector automatically critical infrastructure?
No. Article 4 identifies sectors, but Article 5 says INSA designates particular infrastructure through a directive and notifies its owner. Sector membership is a signal to investigate, not a final designation.
See how designation worksWhich sectors are named in the proclamation?
Twelve sectors are listed. They are ICT, finance, security and safety, transport, education, health, water and energy, government services, disaster management, agriculture, trade and industry. INSA may identify additional sectors.
Review sector scopeWhat factors can make infrastructure important enough for designation?
The possible impact of a cyberattack matters. The published criteria look at effects on the economy, society and daily life; national security and sovereignty; and whether disruption could spread across interconnected critical-infrastructure sectors. A future directive may add criteria.
Explore the published indicatorsHow should an organization know that its infrastructure was designated?
Look for an official INSA notification. Article 5 says designation is made through a directive and the owner is notified. CyberMela cannot authenticate a notice or decide what it covers; confirm its scope directly with INSA or qualified Ethiopian counsel.
See the designation pathCan critical-infrastructure designation later be removed?
Yes, after an INSA assessment. Article 6 says INSA may remove infrastructure that no longer meets the relevant criteria. The proclamation also says its protection for that infrastructure then ends.
Read the scope explanationIs Proclamation No. 1426/2026 already in force?
Not yet. It was published on 21 July 2026. Article 28 says it enters into force one year after publication, which points to 21 July 2027. Existing laws and INSA powers may still apply independently.
Check the legal-status noteWho has the 48-hour cyber-incident notification duty?
Article 7 places it on a critical-infrastructure owner. The owner must notify the National Computer Emergency Response Center within 48 hours using the system established by INSA. The published text leaves some operational details to the official system and future directions.
Find the official reporting routeDoes the proclamation create licensing for cybersecurity providers?
Yes, but important details still depend on an INSA directive. Article 16 creates an INSA licensing regime for cybersecurity products and services. The exact service types, application process, licence content, renewal, oversight and related procedures are to be detailed by directive.
Read the provider-licensing guide