Law /
Central African Republic
Cybersecurity Law: Mandatory Security Audit Regime
Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité Titre II, Chapitre II (art. 14, 15 et 25) et Titre III, Chapitre I (art. 43)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 21 February 2024.
A sector security regimes rule binding public and private bodies.
As of 20 September 2026.
What it requires
- This binds a network operator, a certification authority and an electronic-communications service provider by name under Article 14, and Article 25 extends the mandatory security-audit regime to every electronic-communications network and every information system.
- Submit your networks or information systems to a mandatory security audit and severity-impact assessment by the Agence Nationale de la Cybersécurité at least once a year, or more often where circumstances require it.
- Provide the information and documents a security audit requires, and do not obstruct or resist it: obstructing a security audit is a criminal offense under Article 43.
- Expect the confidential audit report to reach the Agence Nationale de la Cybersécurité for approval and then the Ministères chargés de la Sécurité Publique and de l'Economie Numérique for decision.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Article 43 punishes obstructing a security audit, inciting resistance to it, or refusing to provide the information or documents it requires with one to five years' imprisonment and a fine of 100,000 to 1,000,000 CFA francs or either penalty alone. Article 41 separately punishes an unauthorized disclosure of confidential audit information by ANCy personnel or commissioned experts with one to five years' imprisonment and a fine of 1,000,000 to 10,000,000 CFA francs; that duty binds ANCy's own personnel and experts, not the audited operator.
Penalty structure
Article 43's fine of 100,000 to 1,000,000 CFA francs binds anyone who obstructs a security audit, incites resistance to it, or refuses to provide the information or documents it requires, stated in the alternative to, or alongside, one to five years' imprisonment. Article 41 separately fines ANCy personnel or commissioned experts 1,000,000 to 10,000,000 CFA francs, with the same imprisonment range, for an unauthorized disclosure of confidential audit information; that duty binds ANCy's own side of the audit, not the audited operator, and is not the figure recorded here.
- Rule
- Fixed only
- As of
- 20 September 2026
- Minimum
- 100,000
- Currency
- XAF
- Fixed cap
- 1,000,000
Who enforces it
Enforcement body
L'Agence Nationale de la Cybersécurité (ANCy), which conducts the security audit and forwards its confidential report to the Ministères chargés de la Sécurité Publique and de l'Economie Numérique.
Settledness
- As of
- 20 September 2026
- Open questions
- Has the implementing regulation Article 14 calls for, fixing the security audit's conditions and modalities and the follow-up of its recommendations, been issued?
- Has the implementing regulation Article 25 calls for, fixing the conditions for assessing severity-impact levels, been issued, and has a security-audit cycle actually run under this regime since it took effect on 21 February 2024?
What it reaches
Obligation class
Security, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 14 places the electronic-communications networks and information systems of network operators, certification authorities and electronic-communications service providers under a mandatory security audit; the audit's conditions and modalities, and the follow-up of its recommendations, are set by implementing regulation.
Article 25 restates the mandatory security-audit regime over electronic-communications networks and information systems generally, requires the audit and a severity-impact assessment to run at least once a year or whenever circumstances require it, and requires the resulting confidential audit report to reach ANCy for approval before it is transmitted to the Ministères chargés de la Sécurité Publique and de l'Economie Numérique for decision; a further implementing regulation sets the conditions for assessing severity-impact levels.
Article 15 binds ANCy's own personnel and the experts it commissions for an audit to professional secrecy, and Article 41 makes an unauthorized disclosure by that personnel or those experts a criminal offense punishable by one to five years' imprisonment and a fine of 1,000,000 to 10,000,000 CFA francs.
Article 43 makes it a criminal offense, punishable by one to five years' imprisonment and a fine of 100,000 to 1,000,000 CFA francs or either penalty alone, to obstruct a security audit by any means, incite resistance to it, or refuse to provide the information or documents it requires.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_producthandles_health_recordsprovides_financial_servicesoperates_essential_serviceis_listed_companyprovides_telecom_services
Read the law
Text of Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité
an Internet Archive capture of the publication by the Central African Republic's telecommunications regulator ARCEP (arcep.cf)
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 10, 2025. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_002_relative_a_la_cyber_securite.pdfEvery line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.