Law / Democratic Republic of the Congo

Digital Code, Livre IV: General Cyberattack Cooperation and Incident-Reporting Duty

Code du numérique Livre IV, Titre II, Chapitre I, et Titre III, Chapitre I, Section 1, Ordonnance-loi n° 23/010 du 13 mars 2023 (art. 276 et 281)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 13 March 2023.

A vulnerability and incident reporting rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This binds the operator of an information system, public or private, and more broadly any natural or legal person operating in, or possessing expertise in, the digital sector, without any sector limitation.
  • Cooperate in detecting cyberattacks in accordance with the applicable legal and regulatory provisions.
  • Inform the Agence Nationale de Cybersécurité of every attack, intrusion or other penetration liable to impair the operation of another information system or network, so as to let the Agency take the measures necessary to address it, including isolating the affected system.
  • Comply with the measures the Agence Nationale de Cybersécurité prescribes to put an end to the disruption.
  • No fixed numerical notification deadline is stated; the duty runs from the operator's own awareness of the attack, intrusion or penetration.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

No provision reviewed here states a criminal or administrative penalty specific to an operator's failure to notify or cooperate with the Agence Nationale de Cybersécurité under Articles 276 or 281.

Who enforces it

Enforcement body

L'Agence Nationale de Cybersécurité, the national authority in charge of cybersecurity and information-system security the Digital Code establishes.

Settledness

As of
19 September 2026
Open questions
Does the organizing Ordonnance Article 275 calls for set a numerical notification deadline for the Article 276 duty that the statutory text itself leaves unstated?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 281 requires a natural or legal person operating in the digital sector, or possessing expertise in it, to cooperate in detecting cyberattacks in accordance with the applicable legal and regulatory provisions. Article 276 requires the operator of an information system, public or private, to inform the Agence Nationale de Cybersécurité of every attack, intrusion or other penetration liable to impair the operation of another information system or network.

Article 276 further requires that operator to comply with the measures the Agence Nationale de Cybersécurité prescribes to put an end to the disruption, including isolation of the affected information system. Neither Article 276 nor Article 281 states a fixed numerical deadline for the notification, or a fixed administrative or criminal penalty for a failure to notify or cooperate.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product
  • handles_health_records
  • provides_financial_services
  • operates_essential_service
  • is_listed_company
  • provides_telecom_services

Read the law

Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique
reproduced by the Autorité de Régulation de l'Électricité (are.gouv.cd)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app