Law / Central African Republic

Cybersecurity Law: Essential-Service Operator Cybersecurity Regime

Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité, Titre II, Chapitre I (art. 7 à 12)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 21 February 2024.

A sector security regimes rule binding public and private bodies.

As of 20 September 2026.

What it requires

  • This binds an operator, public or private, that the Agence Nationale de la Cybersécurité designates as an essential-service operator because its continuity could be gravely affected by an incident touching an electronic-communications network or an information system.
  • Comply with the protective measures the Agence Nationale de la Cybersécurité sets to secure your essential infrastructure, and hold the accreditation the Agency grants to a compliant operator.
  • Expect the Agence Nationale de la Cybersécurité to inspect and audit your essential infrastructure's information systems, and to impose administrative sanctions, including pecuniary ones, if you fail to meet your cybersecurity obligations; the law does not state a fixed amount.
  • Expect the Agence Nationale de la Cybersécurité, acting as the national Computer Emergency Response Team, to collect technical information about an incident affecting your essential infrastructure; no fixed deadline for reporting an incident to the Agency is stated.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 10 authorizes the Agence Nationale de la Cybersécurité to impose administrative sanctions, including pecuniary ones, on a noncompliant essential-service operator; no provision reviewed here states a criminal penalty specific to that noncompliance.

Who enforces it

Enforcement body

L'Agence Nationale de la Cybersécurité (ANCy), placed under the joint oversight of the Ministère chargé de la Sécurité Publique and the Ministère chargé de l'Economie Numérique.

Settledness

As of
20 September 2026
Open questions
  • Has the Décret pris en Conseil des Ministres that Article 12 requires to define the Agence Nationale de la Cybersécurité's organization and functioning been issued, and is the Agency now operational rather than performed provisionally by the two supervising Ministries under Article 141?
  • What amount does the Agence Nationale de la Cybersécurité's Article 10 power to impose pecuniary sanctions on a noncompliant essential-service operator actually set, since Article 10 authorizes the sanction without stating a figure?

What it reaches

Obligation class

Security, Licensing

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 8 creates the Agence Nationale de la Cybersécurité (ANCy), a public, non-commercial establishment with legal personality and financial autonomy, as the national authority over the security of essential infrastructure and of public authorities' information systems.

Article 10 gives ANCy the power to designate essential-service operators, whether public or private, whose continuity could be gravely affected by an incident touching an electronic-communications network or information system; to set the protective measures those operators must implement to secure their essential infrastructure and to control compliance with them; to grant accreditation to a compliant operator; and to impose administrative sanctions, including pecuniary ones, on an operator that fails to meet its cybersecurity obligations, with no fixed amount stated in the text reviewed here.

Article 11 gives ANCy the function of Computer Emergency Response Team (CERT) or Computer Security Incident Response Team (CSIRT) for the Central African Republic and a 24/7 point of contact, under which it coordinates incident prevention and response with national partners and foreign CERTs and collects technical information about an incident affecting an essential-service operator's essential infrastructure or a State information system; the reviewed text states no deadline by which an operator must report an incident to ANCy.

When LexLint raises it

  • operates_essential_service

Read the law

Text of Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité
an Internet Archive capture of the publication by the Central African Republic's telecommunications regulator ARCEP (arcep.cf)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 10, 2025. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_002_relative_a_la_cyber_securite.pdf

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app