Mandatory Reporting of Attacks and Intrusions to ARTCI
Décret n°2021-917 du 22 décembre 2021, Arts. 16-17
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 22 December 2021.
A vulnerability and incident reporting rule binding public and private bodies.
As of 18 September 2026.
What it requires
- This duty runs to every public or private organization operating an information system in Côte d'Ivoire, with no activity or size gate.
- Inform ARTCI immediately of any attack, intrusion or other disruption likely to impede your information system's proper functioning.
- Expect ARTCI, not your own organization, to take the measures it judges necessary to stop a disruption once you have notified it.
- Where you are designated and notified as a critical-infrastructure operator or manager, expect your cybersecurity focal point to also serve as your liaison to CI-CERT and to a sector cybersecurity officer, roles this vocabulary does not separately express.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 16 states no penalty of its own for a failure to report; the Article 20 sanction reviewed on this jurisdiction's companion row is tied to the Article 3 audit obligation, not to this reporting duty.
Who enforces it
Enforcement body
Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI).
Settledness
- As of
- 18 September 2026
- Guidance link
- https://artci.ci/en/security-audit/
- Guidance body
- Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI)
- Open questions
- Does 'toutes attaques, intrusions et autres perturbations susceptibles d'entraver le bon fonctionnement' in Article 16 reach a merely attempted or blocked intrusion, or only one that actually disrupts the system's functioning?
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 16 requires every public or private organization to inform ARTCI immediately of any attack, intrusion or other disruption likely to impede its information system's proper functioning. Article 17 empowers ARTCI to take all measures it deems necessary to stop a disruption it identifies.
The Plan de Protection des Infrastructures Critiques names CI-CERT, alongside ARTCI and a sector cybersecurity officer, as one of the competent authorities a designated critical-infrastructure operator's cybersecurity focal point liaises with.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product