Cyberመላ
Browse documentation
In this article
LAW EXPLAINER

Main provisions of Ethiopia's Critical Infrastructure Cybersecurity Proclamation No. 1426/2026

A plain-language guide to the proclamation's main operational provisions. It does not yet summarize every article; the coverage map below makes those limits visible.

Page published 8 August 2026 • Last reviewed 13 August 2026 • Primary source checked
READ THIS IN 60 SECONDSRead full guide
What it creates

A national system to identify, oversee and protect designated critical infrastructure.

Who decides coverage

The Information Network Security Administration (INSA) designates particular infrastructure. Being in a listed sector is not enough by itself.

Main obligation

Article 7 sets 18 duties covering governance, assets, risk, people, suppliers, monitoring, incidents and audit follow-up.

Important date

Published 21 July 2026; Article 28 points to entry into force on 21 July 2027.

Still evolving

Designation, licensing and operational details may be clarified by implementing directives.

Bottom line: use this guide to understand the framework, then confirm organization-specific questions with INSA or qualified Ethiopian counsel.

Four terms to understand first

Designation

The formal step where INSA identifies specific infrastructure as critical and notifies its owner. A sector label alone is not a designation.

Governance

Who makes cybersecurity decisions, who owns the work, how risk is accepted and how progress is checked.

Evidence

Records showing that a policy, decision, control or security activity actually happened—not evidence in the criminal-trial sense.

Administrative fine

A regulator-imposed monetary sanction under the proclamation. It is different from a criminal conviction or sentence.

These are navigation definitions. Check Article 2 and the official text for formal wording.

What this guide covers—and what it does not yet summarize

COVERED IN DEPTH

Articles 4–7, 16–20, 22–23 and 28

Sectors, designation, owner duties, provider licensing, administrative penalties, complaints and effective date.

NOT YET SUMMARIZED ARTICLE BY ARTICLE

Articles 1–3, 8–15, 21 and 24–27

Use the official PDF for these provisions. Their absence here does not mean they are unimportant or inapplicable.

How an organization moves into the regime

01Sector relevance

Infrastructure operates in or supports a sector listed in Article 4.

02INSA assessment

INSA applies the criteria and assessment process in Articles 5 and 6.

03Designation

The particular infrastructure is designated; sector membership alone is not a final decision.

04Owner duties

The designated owner implements the Article 7 duties and applicable directions.

Navigation summary based on Articles 4–7. It is not a designation test or legal determination.

When does it take effect?

The Federal Negarit Gazette is dated 21 July 2026. Article 28 says the proclamation enters into force one year after publication, which points to 21 July 2027.

Status note

As of 13 August 2026, the proclamation is published but its delayed effective date has not arrived. Existing laws and pre-existing regulatory powers may still apply independently.

Who can be covered?

Article 4 identifies sectors including information and communication technology, finance, security, transport, education, health, water and energy, government, disaster management, agriculture, trade and industry. Sector membership alone is not a final designation.

Under Articles 5 and 6, INSA designates and may later remove specific infrastructure after applying the proclamation's criteria and assessment process. Therefore, this platform uses phrases such as potentially relevant or possible designation exposure, never “you are definitely designated.”

Worked example: a fictional regional hospital

This is an illustration, not a designation prediction. The hospital is in a listed sector. Its clinical systems support emergency care, depend on power and telecoms, and could create serious public harm if unavailable. Those facts make the Article 4–5 indicators worth examining, but they do not designate the hospital.

1. Identify the infrastructure

Separate the hospital as an organization from the specific clinical, laboratory, network or data infrastructure being assessed.

2. Test impact and dependencies

Record affected services, population, safety consequences, geographic reach and dependencies on other essential systems.

3. Check for official notice

Ask legal and executive offices whether INSA has sent a notice. This status signal is separate from the impact analysis.

4. Prepare without self-designating

Improve asset ownership, incident roles, supplier records and recovery priorities while official status is confirmed.

What must a designated owner do?

Article 7 contains 18 duties. The six groups support scanning; the expandable index underneath preserves every numbered duty and its Article 7 reference.

Governance

Create cybersecurity programs, implement mandatory or recognized frameworks, establish an internal framework and create the required organizational structure.

Art. 7(1)–(3), (9)

Assets and risk

Classify and protect critical assets; conduct regular cybersecurity risk assessments and impact analyses; participate in the annual national risk survey.

Art. 7(4)–(6)

Audit and correction

Maintain and renew the required audit or inspection certificate and correct findings within the required time.

Art. 7(7)–(8)

People

Use appropriately certified cybersecurity professionals; conduct training and exercises; meet personnel clearance and ethics requirements.

Art. 7(10), (16)–(18)

Technology and suppliers

Address technology supply-chain security and obtain required security clearance before integrating new or upgraded ICT systems.

Art. 7(11)–(12)

Monitoring and incidents

Establish a monitoring/reporting/response center, notify the national emergency response center within 48 hours, and exchange information through INSA's system.

Art. 7(13)–(15)
Show all 18 duties with article references
  1. 1

    Create cybersecurity programs based on the national cybersecurity frameworks.

    Article 7(1)
  2. 2

    Implement mandatory cybersecurity frameworks issued or recognized by INSA.

    Article 7(2)
  3. 3

    Develop and implement an internal cybersecurity framework based on applicable national laws, policies and regulatory technical policy.

    Article 7(3)
  4. 4

    Classify and protect critical assets under the standard issued by INSA.

    Article 7(4)
  5. 5

    Conduct periodic cybersecurity risk assessments and impact analyses through the official system.

    Article 7(5)
  6. 6

    Participate in the annual National Cybersecurity Risk Survey and provide relevant information.

    Article 7(6)
  7. 7

    Maintain and renew the required cyber-audit and cyber-inspection-and-evaluation certificate.

    Article 7(7)
  8. 8

    Take corrective action on cyber-audit or inspection-and-evaluation findings within the required period.

    Article 7(8)
  9. 9

    Create the required cybersecurity organizational structure under the national framework.

    Article 7(9)
  10. 10

    Use cybersecurity professionals certified by, or recognized by, INSA and ensure existing professionals obtain the required certification.

    Article 7(10)
  11. 11

    Protect the supply chain of the technology products used.

    Article 7(11)
  12. 12

    Before integration, obtain security clearance for new or upgraded ICT systems acquired by purchase, donation, development or another means.

    Article 7(12)
  13. 13

    Establish and manage a center for monitoring, reporting and responding to cyberattacks under the framework to be issued by INSA.

    Article 7(13)
  14. 14

    Notify the National Computer Emergency Response Center of cybersecurity incidents within 48 hours using the official system, and implement directions provided.

    Article 7(14)
  15. 15

    Periodically exchange important information through the official information-exchange system.

    Article 7(15)
  16. 16

    Develop and run cybersecurity exercises and training, and participate in officially facilitated exercises and training.

    Article 7(16)
  17. 17

    Ensure employees and officers with access to critical resources receive security clearance from the relevant government body.

    Article 7(17)
  18. 18

    Ensure compliance with the professional ethics required for cybersecurity work.

    Article 7(18)

Plain-language index only. Confirm the exact wording in the official proclamation.

Translate Article 7 duties into controls, evidence and verification questions.

The proclamation states duties; it does not prescribe every technical implementation detail in the published text. The examples below are practical evidence categories a security or IT team can use to organize readiness—not an official regulator checklist or a claim that each artifact is legally mandatory.

Article 7(4)–(6)

Asset and risk evidence

Example control and evidence areas

Critical-asset inventory and classification, dependency mapping, risk register, business-impact analysis and national-risk-survey response records.

Technical verification prompt

Can the team identify the service, owner, data, dependencies, recovery priority and latest risk decision for every critical asset?

Article 7(11)–(12)

Technology and supply chain

Example control and evidence areas

Supplier assurance records, software and hardware provenance, third-party access controls, security requirements in contracts, change records and pre-integration security-clearance evidence.

Technical verification prompt

Can procurement, architecture and security trace a new or upgraded ICT system from approval through secure integration?

Article 7(13)–(15)

Monitoring and incident operations

Example control and evidence areas

Monitoring coverage, alert ownership, triage criteria, incident register, escalation matrix, 48-hour notification workflow, report receipts and information-exchange records.

Technical verification prompt

Can the operations team detect, classify, escalate and preserve the facts needed for an official report without improvising during an incident?

Article 7(7)–(10), (16)–(18)

Audit and corrective action

Example control and evidence areas

Audit or inspection certificates, findings register, remediation owners and due dates, staff qualification records, exercise reports, training attendance, clearance records and ethics acknowledgements.

Technical verification prompt

Can each finding and personnel requirement be linked to an accountable owner, evidence, due date and closure decision?

What is the 48-hour incident rule?

Article 7(14) requires a critical-infrastructure owner to notify the National Computer Emergency Response Center of cybersecurity incidents within 48 hours, using the system established by INSA. The official English text does not, by itself, answer every operational question about when the clock starts, required fields or follow-up format.

See the official reporting routes

What does the provider-licensing regime cover?

Articles 16–20 create a separate track for people and organizations that provide cybersecurity products or services. Article 16 says INSA issues the licence and prohibits providing covered products or services without it. A future directive is expected to identify the product and service types that require a licence and specify the application, licence content, renewal, oversight, security-clearance and complaint procedures.

Article 17 — entry requirements

The published criteria include legal-personality or establishment documents, security clearance, qualified personnel and technology, operational systems, capital and guarantee requirements, a permanent Ethiopian address and integrity-related requirements. Several details are left to directive.

Article 18 — licensed-person duties

Use the licence only within its purpose and scope; do not transfer or lend it without approval; report material requirement changes; protect confidential information; cooperate with regulatory oversight; and follow the proclamation and implementing rules.

Articles 19–20 — revocation and suspension

The proclamation lists grounds for revocation and permits suspension where those grounds may exist. The exact process and safeguards should be checked against the official text and later rules.

Do not infer coverage from a job title alone

Until the Article 16 directive identifies the covered product and service types, CyberMela cannot decide whether a particular consulting, managed-security, software or product activity requires a licence.

What penalties and complaint routes are published?

Article 22 lists administrative fines—regulator-imposed monetary sanctions, not criminal convictions—for specified intentional violations by critical-infrastructure owners. The amounts below are navigation aids, not predictions.

Published violationArticle 22 range
Mandatory framework not implemented on timeETB 500,000–1,000,000
48-hour incident notice or required corrective action not completedETB 1,500,000–2,000,000
Necessary information or cooperation not provided to the national incident-response centerETB 300,000–500,000
Required cooperation not provided for periodic cybersecurity auditsETB 1,500,000–2,000,000
Audit findings not corrected on time as directedETB 800,000–1,000,000
ICT systems used without the required cybersecurity inspection and evaluationETB 800,000–1,000,000
Negligence and first-time warning

Article 22 provides a reduced fine for negligent conduct. It also permits INSA to use a written corrective warning where an offence is a first occurrence and caused no damage.

Unlicensed providers and repeat offences

Providing covered cybersecurity services without a valid licence, or breaching Article 18 duties, carries a published ETB 1.2–2 million range. A repeat offence may be fined at three times the stated maximum.

Complaint and appeal route

Article 23 provides a written complaint to INSA within 30 consecutive days, its decision within 15 consecutive working days, a later grievance-board route and a court appeal within 60 consecutive days after the board decision.

Administrative amounts may later be revised by Council of Ministers regulation. Confirm the bilingual official text before acting.

What remains uncertain or evolving?

  • The exact designation process and notices used for specific organizations.
  • Detailed implementation rules for the 18 duties and certification renewal.
  • The catalogue and conditions for cybersecurity product and service provider licences under Article 16.
  • Operational details of the 48-hour incident reporting system.
  • How newer directives will interact with pre-existing official standards and sector rules.

Confirm these points with INSA or qualified Ethiopian counsel before making organization-specific legal or investment decisions.

Official sources

Official proclamation PDFOfficial documentation libraryOfficial publication announcementReview the article transcription pilot

How to use this guide: verify important decisions against the linked official text. This page provides general information, not legal advice, designation, audit, certification or a compliance finding.