RGSSI and PPIC Compliance Duty
Décret n°2021-916 du 22 décembre 2021, Arts. 1-2
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 22 December 2021.
A sector security regimes rule binding public and private bodies.
As of 18 September 2026.
What it requires
- Where your service's information system connects through Côte d'Ivoire's public telecommunications networks, or you automatically process your customers' personal data in providing your service, comply with the RGSSI (the ISO 27001/27002-based security standard Décret n°2021-917's audits check you against) and, if you also operate a designated critical-infrastructure asset, the PPIC.
- Do not expect this décret to state its own penalty for noncompliance: enforcement runs through Décret n°2021-917's audit, certification and sanction mechanism, filed as its own row in this jurisdiction.
- Where you are designated and notified as a critical-infrastructure operator or manager, renew a complete risk analysis of your critical infrastructure at least every six months and designate a cybersecurity focal point, a designation this vocabulary does not separately express.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
This décret states no penalty of its own for noncompliance with the RGSSI or the PPIC; the sanction attaches to the Article 3 audit obligation under Décret n°2021-917 Article 20, filed as its own row.
Who enforces it
Enforcement body
Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI), through the Décret n°2021-917 audit and certification mechanism.
Settledness
- As of
- 18 September 2026
- Guidance link
- https://artci.ci/en/security-audit/
- Guidance body
- Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI)
- Open questions
- Does the RGSSI apply its full ISO 27001/27002-based control set uniformly to every organization Décret n°2021-917 Article 3 names, or does the référentiel itself scale requirements by an entity's size or risk profile?
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 1 adopts the Référentiel Général de Sécurité des Systèmes d'Information (RGSSI) and the Plan de Protection des Infrastructures Critiques (PPIC) as annexes to this décret. The RGSSI states that it draws heavily on ISO 27001:2013 and ISO 27002:2013. Article 2 requires every public body and private enterprise to comply with the RGSSI and the PPIC. Décret n°2021-917 Article 14 anchors that compliance duty to the same population its own Article 3 lists.
The PPIC requires an organization the State has designated and notified as a critical-infrastructure operator or manager to renew a complete risk analysis of its critical infrastructure at least every six months. The same organization must also designate a cybersecurity focal point who liaises with ARTCI, a sector cybersecurity officer, and CI-CERT, a set of roles no activity in this vocabulary expresses, so this PPIC-specific duty is recorded here rather than flagged.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product