Sets Ethiopia’s national direction for a secure, resilient and trusted cyberspace.
Browse documentation
In this article
Ethiopia’s National Cybersecurity Policy (2024)
A plain-language guide to the policy’s national direction, seven focus areas and implementation framework—and how to use it without confusing policy direction with a proclamation.
It is a policy, not a proclamation. Do not treat policy alignment by itself as proof of legal compliance.
Its stated scope includes public bodies, private organizations, non-governmental organizations and citizens.
The policy places oversight and national coordination with the Information Network Security Administration (INSA), while implementation is shared.
Bottom line: use the policy to shape strategy and priorities, then check proclamations, regulations, directives and sector rules for specific legal duties.
What the policy is
The policy is a national strategy document. It describes the problems Ethiopia intends to address, the outcomes it wants, and the institutions and stakeholders expected to contribute. The source itself is dated June 2024; INSA’s current official document listing is dated 22 October 2025. Those are different dates and are shown separately here.
Policy direction
Explains national priorities, principles and strategies. It helps leaders decide what a cybersecurity programme should work toward.
Legal obligation
Comes from the applicable proclamation, regulation, directive, licence, contract or sector requirement. Check those sources separately.
Vision, mission and five objectives
Build a globally competitive and resilient national cybersecurity capability that supports Ethiopia’s development and positions the country as a model in Africa.
Develop self-reliant capability to protect national interests, information and critical information infrastructure in cyberspace.
Resilience and response
Improve prevention, detection, response and recovery across national systems.
Rights and trust
Protect privacy, human rights and democratic values while improving cybersecurity.
Partnership
Strengthen coordination among government, the private sector, academia, civil society and international partners.
Local capability
Develop indigenous research, technology, services and professional capacity.
Cybersecurity culture
Make safe digital behaviour and shared responsibility part of everyday national practice.
The seven focus areas
Part Two is the operational centre of the policy. These seven themes are the clearest way to map an organization’s strategy to the national direction.
Legal and regulatory framework
Develop coordinated laws, standards and regulatory mechanisms that can respond to changing cyber risks.
Cybersecurity awareness
Build sustained awareness across government, organizations and the public—not only one-off campaigns.
Capacity building
Develop the people, institutions, education and professional capability needed for national resilience.
Research and development
Strengthen local research, innovation and technology development to reduce dependence and meet local needs.
Digital identity and personal data
Protect digital identities and personal data as digital services and data use expand.
Critical information infrastructure
Identify and protect systems whose disruption could seriously affect public security or national interests.
National and international cooperation
Coordinate public and private stakeholders domestically and strengthen cooperation with international partners.
How implementation is organized
Part Three describes a shared national programme rather than a task owned by one institution alone.
INSA oversight
INSA is positioned to coordinate the policy, prepare implementation plans, and lead monitoring and evaluation.
National coordination
The policy envisages a National Cyber Security Council and coordinated participation by government, the private sector, academia, civil society and other stakeholders.
Plans, measures and budgets
Stakeholders are expected to translate policy direction into action plans, responsibilities, measures and budget commitments.
Monitoring and revision
The implementation framework calls for monitoring and evaluation and states that the policy should be revised every five years.
A practical organization checklist
This is a strategy-alignment checklist, not a compliance determination.
- Map your programmeShow which of the seven focus areas each major initiative supports.
- Name accountable ownersAssign leadership, delivery and evidence responsibilities instead of leaving “cybersecurity” with one technical team.
- Record dependenciesIdentify regulators, national services, suppliers, research partners and sector bodies you need to coordinate with.
- Choose measurable outcomesTrack capability, coverage, response, workforce and awareness results—not only activities completed.
- Separate policy from lawMaintain a second register for enforceable obligations and the sources that create them.
Official sources and language status
National Cybersecurity Policy
54-page PDF with an extractable text layer. This guide summarizes it; it does not reproduce an official-text block.
Download from INSAሀገራዊ የሳይበር ደህንነት ፖሊሲ
The provided source is a 56-page PDF. No Amharic Tier A official-text block is published because character-by-character human verification is not complete.
Open the official policy listingNo official-text block is published on this guide. Every explanatory sentence on this page is CyberMela-authored summary, not the policy text.
The English PDF’s Part Three headings are not fully consistent between the contents page and the body. This guide follows the substance without silently rewriting any official-text block.
Now check the rules that may apply today.
The policy sets direction. The current-law guide helps you identify proclamations and other sources to check against your activities.
Open the current-law guide