Law / Ivory Coast

RGSSI and PPIC Compliance Duty

Décret n°2021-916 du 22 décembre 2021, Arts. 1-2

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 22 December 2021.

A sector security regimes rule binding public and private bodies.

As of 18 September 2026.

What it requires

  • Where your service's information system connects through Côte d'Ivoire's public telecommunications networks, or you automatically process your customers' personal data in providing your service, comply with the RGSSI (the ISO 27001/27002-based security standard Décret n°2021-917's audits check you against) and, if you also operate a designated critical-infrastructure asset, the PPIC.
  • Do not expect this décret to state its own penalty for noncompliance: enforcement runs through Décret n°2021-917's audit, certification and sanction mechanism, filed as its own row in this jurisdiction.
  • Where you are designated and notified as a critical-infrastructure operator or manager, renew a complete risk analysis of your critical infrastructure at least every six months and designate a cybersecurity focal point, a designation this vocabulary does not separately express.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

This décret states no penalty of its own for noncompliance with the RGSSI or the PPIC; the sanction attaches to the Article 3 audit obligation under Décret n°2021-917 Article 20, filed as its own row.

Who enforces it

Enforcement body

Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI), through the Décret n°2021-917 audit and certification mechanism.

Settledness

As of
18 September 2026
Guidance link
https://artci.ci/en/security-audit/
Guidance body
Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI)
Open questions
Does the RGSSI apply its full ISO 27001/27002-based control set uniformly to every organization Décret n°2021-917 Article 3 names, or does the référentiel itself scale requirements by an entity's size or risk profile?

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 1 adopts the Référentiel Général de Sécurité des Systèmes d'Information (RGSSI) and the Plan de Protection des Infrastructures Critiques (PPIC) as annexes to this décret. The RGSSI states that it draws heavily on ISO 27001:2013 and ISO 27002:2013. Article 2 requires every public body and private enterprise to comply with the RGSSI and the PPIC. Décret n°2021-917 Article 14 anchors that compliance duty to the same population its own Article 3 lists.

The PPIC requires an organization the State has designated and notified as a critical-infrastructure operator or manager to renew a complete risk analysis of its critical infrastructure at least every six months. The same organization must also designate a cybersecurity focal point who liaises with ARTCI, a sector cybersecurity officer, and CI-CERT, a set of roles no activity in this vocabulary expresses, so this PPIC-specific duty is recorded here rather than flagged.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official décret text, ARTCI document repository

Back to the example  ·  Lint your app