Law /
Central African Republic
Cybersecurity Law: Network and Information System Security Duty
Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité Titre II, Chapitre III, Sections I et II (art. 16, 19, 20, 21, 23)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 21 February 2024.
A security baseline statutes rule binding public and private bodies.
As of 20 September 2026.
What it requires
- This binds an electronic-communications network operator or service provider (Article 16) and any information-system operator, whether public or private (Article 19), regardless of the sector in which the network or system is deployed.
- Take all technical and administrative measures necessary to guarantee the security of the services you offer, and adopt standardized systems to continually identify, assess, treat and manage the risks to your information systems' security.
- Put in place technical mechanisms addressing threats to your systems' permanent availability, integrity, authentication, non-repudiation and data confidentiality, and to their physical security, and submit those mechanisms to the Agence Nationale de la Cybersécurité for approval.
- Periodically evaluate and revise your security systems, and introduce necessary changes as technology evolves, under the Agence Nationale de la Cybersécurité's oversight.
- Inform your users of the dangers of using your network or information system, the particular security-violation risks involved, and the technical means available to secure their communications or restrict access to certain services.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
No provision reviewed here states a criminal or administrative penalty specific to a network operator's or information-system operator's failure to meet the Article 16, 19, 20, 21 or 23 security duties.
Who enforces it
Enforcement body
L'Agence Nationale de la Cybersécurité (ANCy), which must approve the security mechanisms Article 19 requires and oversees the periodic review Article 23 requires.
Settledness
- As of
- 20 September 2026
- Open questions
- Has the Agence Nationale de la Cybersécurité specified, by implementing regulation, the standardized risk-management systems and the technical security mechanisms Article 19 requires it to approve?
- Does a fixed administrative or criminal penalty exist elsewhere in Central African Republic law for a network operator's or information-system operator's failure to meet the Article 16 or Article 19 security duty, since the text reviewed here states none?
What it reaches
Obligation class
Security, Disclosure
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 16 requires an electronic-communications network operator or service provider to take all technical and administrative measures necessary to guarantee the security of the services it offers, and to inform users of the danger of using its networks, of the particular security-violation risks involved (distributed denial of service, abnormal rerouting, traffic spikes, unusual traffic and ports, passive and active eavesdropping, intrusions), and of the technical means available to secure their communications.
Article 19 imposes the same all-measures security duty on any information-system operator, and further requires that operator to adopt standardized systems to continually identify, assess, treat and manage the risks to its information systems' security, to put technical mechanisms in place against threats to the systems' permanent availability, integrity, authentication, non-repudiation, data confidentiality and physical security, to submit those mechanisms to ANCy for approval, and to protect its platforms against intrusion with, among other things, an intrusion-detection system.
Article 20 requires a legal person offering access to information systems to inform users of the danger of an unsecured information system, the need for parental-control devices, and the particular risks of the generic virus family, and to offer at least one technical means of restricting access, such as an up-to-date operating system, antivirus and anti-spyware tools, a personal firewall, an intrusion-detection system or automatic updates; where no such means exists, the provider must say so.
Article 21 requires an information-system operator to inform users that using the network to distribute illicit content, or designing deceptive software, spyware or a potentially unwanted program, is prohibited. Article 23 requires an information-system operator to periodically evaluate and revise its security systems and introduce necessary changes as technology evolves, under ANCy's oversight, and lets it cooperate with its own users on that work.
None of the articles reviewed here states a fixed administrative or criminal penalty specific to a network operator's or information-system operator's failure to meet these security duties.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Text of Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité
an Internet Archive capture of the publication by the Central African Republic's telecommunications regulator ARCEP (arcep.cf)
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 10, 2025. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_002_relative_a_la_cyber_securite.pdfEvery line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.