Law / Ivory Coast

Mandatory Reporting of Attacks and Intrusions to ARTCI

Décret n°2021-917 du 22 décembre 2021, Arts. 16-17

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 22 December 2021.

A vulnerability and incident reporting rule binding public and private bodies.

As of 18 September 2026.

What it requires

  • This duty runs to every public or private organization operating an information system in Côte d'Ivoire, with no activity or size gate.
  • Inform ARTCI immediately of any attack, intrusion or other disruption likely to impede your information system's proper functioning.
  • Expect ARTCI, not your own organization, to take the measures it judges necessary to stop a disruption once you have notified it.
  • Where you are designated and notified as a critical-infrastructure operator or manager, expect your cybersecurity focal point to also serve as your liaison to CI-CERT and to a sector cybersecurity officer, roles this vocabulary does not separately express.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 16 states no penalty of its own for a failure to report; the Article 20 sanction reviewed on this jurisdiction's companion row is tied to the Article 3 audit obligation, not to this reporting duty.

Who enforces it

Enforcement body

Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI).

Settledness

As of
18 September 2026
Guidance link
https://artci.ci/en/security-audit/
Guidance body
Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI)
Open questions
Does 'toutes attaques, intrusions et autres perturbations susceptibles d'entraver le bon fonctionnement' in Article 16 reach a merely attempted or blocked intrusion, or only one that actually disrupts the system's functioning?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 16 requires every public or private organization to inform ARTCI immediately of any attack, intrusion or other disruption likely to impede its information system's proper functioning. Article 17 empowers ARTCI to take all measures it deems necessary to stop a disruption it identifies.

The Plan de Protection des Infrastructures Critiques names CI-CERT, alongside ARTCI and a sector cybersecurity officer, as one of the competent authorities a designated critical-infrastructure operator's cybersecurity focal point liaises with.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official décret text, ARTCI document repository

Back to the example  ·  Lint your app