Law /
Democratic Republic of the Congo
Digital Code, Livre IV: ICT Product and Service Vendor Security Certification
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 13 March 2023.
A product security requirements rule binding private bodies.
As of 19 September 2026.
What it requires
- This binds a vendor of information and communication technology products, or a provider of information and communication technology services, regardless of the sector in which the product or service is deployed.
- Apply to the Minister responsible for digital affairs for a compliance certificate, which issues only after a vulnerability analysis and a security-guarantee evaluation performed by information security experts the Minister has accredited.
- Inform consumers of every vulnerability detected in your information and communication technology products and services, and of the solutions you have deployed to remedy them.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
No provision reviewed here states a criminal or administrative penalty specific to a vendor's failure to obtain the Article 294 certificate or make its consumer vulnerability disclosure.
Who enforces it
Enforcement body
The Minister responsible for digital affairs (Ministre ayant le numérique dans ses attributions), who issues the compliance certificate after an evaluation performed by accredited information security experts.
Settledness
- As of
- 19 September 2026
- Open questions
- Has the Minister responsible for digital affairs issued the implementing order naming the accredited information security experts and the certification procedure Article 294 contemplates?
What it reaches
Obligation class
Security, Disclosure
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 294 requires a vendor of information and communication technology products, or a provider of information and communication technology services, to apply to the Minister responsible for digital affairs for a compliance certificate. Article 294 conditions issuance of that certificate on a vulnerability analysis and an evaluation of the security guarantee performed by information security experts the Minister has accredited.
Article 294 separately requires the vendor or provider to inform consumers of every vulnerability detected in its information and communication technology products and services, and of the solutions deployed to remedy them. Neither Article 294 nor the other sections of the Digital Code reviewed here state a fixed administrative or criminal penalty specific to a vendor's failure to obtain the certificate or make the disclosure.
When LexLint raises it
distributes_software_productships_mobile_app
Read the law
Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique
reproduced by the Autorité de Régulation de l'Électricité (are.gouv.cd)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.