Law / Central African Republic

Cybersecurity Law: Mandatory Security Audit Regime

Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité Titre II, Chapitre II (art. 14, 15 et 25) et Titre III, Chapitre I (art. 43)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 21 February 2024.

A sector security regimes rule binding public and private bodies.

As of 20 September 2026.

What it requires

  • This binds a network operator, a certification authority and an electronic-communications service provider by name under Article 14, and Article 25 extends the mandatory security-audit regime to every electronic-communications network and every information system.
  • Submit your networks or information systems to a mandatory security audit and severity-impact assessment by the Agence Nationale de la Cybersécurité at least once a year, or more often where circumstances require it.
  • Provide the information and documents a security audit requires, and do not obstruct or resist it: obstructing a security audit is a criminal offense under Article 43.
  • Expect the confidential audit report to reach the Agence Nationale de la Cybersécurité for approval and then the Ministères chargés de la Sécurité Publique and de l'Economie Numérique for decision.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Article 43 punishes obstructing a security audit, inciting resistance to it, or refusing to provide the information or documents it requires with one to five years' imprisonment and a fine of 100,000 to 1,000,000 CFA francs or either penalty alone. Article 41 separately punishes an unauthorized disclosure of confidential audit information by ANCy personnel or commissioned experts with one to five years' imprisonment and a fine of 1,000,000 to 10,000,000 CFA francs; that duty binds ANCy's own personnel and experts, not the audited operator.

Penalty structure

Article 43's fine of 100,000 to 1,000,000 CFA francs binds anyone who obstructs a security audit, incites resistance to it, or refuses to provide the information or documents it requires, stated in the alternative to, or alongside, one to five years' imprisonment. Article 41 separately fines ANCy personnel or commissioned experts 1,000,000 to 10,000,000 CFA francs, with the same imprisonment range, for an unauthorized disclosure of confidential audit information; that duty binds ANCy's own side of the audit, not the audited operator, and is not the figure recorded here.

Rule
Fixed only
As of
20 September 2026
Minimum
100,000
Currency
XAF
Fixed cap
1,000,000

Who enforces it

Enforcement body

L'Agence Nationale de la Cybersécurité (ANCy), which conducts the security audit and forwards its confidential report to the Ministères chargés de la Sécurité Publique and de l'Economie Numérique.

Settledness

As of
20 September 2026
Open questions
  • Has the implementing regulation Article 14 calls for, fixing the security audit's conditions and modalities and the follow-up of its recommendations, been issued?
  • Has the implementing regulation Article 25 calls for, fixing the conditions for assessing severity-impact levels, been issued, and has a security-audit cycle actually run under this regime since it took effect on 21 February 2024?

What it reaches

Obligation class

Security, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 14 places the electronic-communications networks and information systems of network operators, certification authorities and electronic-communications service providers under a mandatory security audit; the audit's conditions and modalities, and the follow-up of its recommendations, are set by implementing regulation.

Article 25 restates the mandatory security-audit regime over electronic-communications networks and information systems generally, requires the audit and a severity-impact assessment to run at least once a year or whenever circumstances require it, and requires the resulting confidential audit report to reach ANCy for approval before it is transmitted to the Ministères chargés de la Sécurité Publique and de l'Economie Numérique for decision; a further implementing regulation sets the conditions for assessing severity-impact levels.

Article 15 binds ANCy's own personnel and the experts it commissions for an audit to professional secrecy, and Article 41 makes an unauthorized disclosure by that personnel or those experts a criminal offense punishable by one to five years' imprisonment and a fine of 1,000,000 to 10,000,000 CFA francs.

Article 43 makes it a criminal offense, punishable by one to five years' imprisonment and a fine of 100,000 to 1,000,000 CFA francs or either penalty alone, to obstruct a security audit by any means, incite resistance to it, or refuse to provide the information or documents it requires.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product
  • handles_health_records
  • provides_financial_services
  • operates_essential_service
  • is_listed_company
  • provides_telecom_services

Read the law

Text of Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité
an Internet Archive capture of the publication by the Central African Republic's telecommunications regulator ARCEP (arcep.cf)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 10, 2025. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_002_relative_a_la_cyber_securite.pdf

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app