Computer crime, electronic transactions and IT-product security laws are marked in force by the Ministry of Justice.
Browse documentation
In this article
Which Ethiopian cybersecurity rules should you check now?
Proclamation 1426/2026 is important, but it is not the whole legal landscape—and it does not take effect until 21 July 2027.
The electronic-signature framework has a 2024 amendment and a 2025 implementing regulation.
Proclamation 1426/2026 is published, with an expected start date of 21 July 2027.
Banking, health, telecoms and other regulated sectors may have additional requirements not mapped here.
Bottom line: start with the activity you perform—not only the newest proclamation.
Five sources to check against your activities
This is a starting map, not an exhaustive legal inventory. Each card explains why a source may matter and the first question to ask.
Computer Crime Proclamation No. 958/2016
Start here if: Anyone responsible for systems, investigations, digital evidence or incident handling.
Creates computer-crime offences and procedures for investigation and electronic evidence. Security teams should preserve records and coordinate technical response with legal authority.
Could the incident involve an offence, and are we preserving evidence correctly?
Electronic Signature Proclamation No. 1072/2018, as amended
Start here if: Organizations using electronic signatures, certificates or trust services.
Gives legal recognition to electronic signatures and establishes a framework for reliable identity, authenticity and integrity in electronic records.
Which signature level and provider requirements apply to this transaction?
Electronic Transactions Proclamation No. 1205/2020
Start here if: Organizations contracting, communicating, selling or providing public services electronically.
Supports legal use of electronic messages, records and transactions instead of treating paper as the only valid form.
Are our electronic records, notices, consent and retention practices sufficient?
IT Products Security Clearance and Control Proclamation No. 1310/2023
Start here if: Importers, producers, sellers, deployers and users of covered IT products.
Creates security-clearance and control requirements for information-technology products. Product scope and practical steps should be checked before procurement or deployment.
Does this product need clearance before import, sale, integration or use?
National Cybersecurity Policy
Start here if: Leaders shaping cybersecurity governance and national-alignment decisions.
Sets national direction. A policy is not the same thing as a proclamation and should not be presented as creating the same kind of directly enforceable duty.
Which policy priorities should influence our governance and programme design?
What changes in July 2027?
Proclamation No. 1426/2026 creates a designation-led regime for specific critical infrastructure, sets 18 owner duties, and establishes a licensing framework for specified cybersecurity products and services. Until designation and implementing processes are clearer, listed-sector membership is a signal to prepare—not proof that an organization is designated.
Read the main-provisions guideA practical first review
List the activity
Transactions, electronic signatures, product import or integration, incident handling, and essential services.
Match the source
Use the cards above, then add laws and directives from your sector regulator.
Name the unanswered question
Separate factual gaps, regulator questions and legal-interpretation questions.
Assign an owner and record
Record the decision, source, reviewer, date and next review point.
What this page does and does not cover
The Ministry of Justice status labels support the “in force” statements above. The page does not map every sector law, directive, data-protection requirement, criminal provision or later amendment. Confirm organization-specific obligations with the relevant authority and qualified Ethiopian counsel.
Need an organization-specific map?
See the inputs, participants, duration and sample outputs before deciding whether a scoped engagement is useful.
Compare readiness packages