Mandatory Information Systems Security Audit and Certification
Décret n°2021-917 du 22 décembre 2021, Arts. 3-4, 19-21
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 22 December 2021.
A sector security regimes rule binding public and private bodies.
As of 18 September 2026.
What it requires
- Where your service's information system connects through Côte d'Ivoire's public telecommunications networks, or you automatically process your customers' personal data in providing your service, you fall inside Article 3's mandatory-audit population; a telecommunications or ICT company, a telecommunications or internet service provider, an electronic-transactions company, an ARTCI-approved service provider, and an electronic-archiving or record-keeping provider are each named as their own category, a set of roles no activity in this vocabulary independently expresses.
- Undergo a security audit for certification of your information system every three years, performed by ARTCI or by an ARTCI-accredited Prestataire d'Audit de Sécurité des Systèmes d'Information (PASSI).
- Undergo a further mandatory periodic security audit eighteen months after your certificate is issued.
- Correct a major nonconformity ARTCI identifies and have your information system re-audited within twelve months, or receive a formal notice ordering you to comply.
- Expect a financial penalty proportional to the breach's severity and the advantage you gained, capped at 300,000,000 CFA francs and doubled on a repeat breach, if you fail to complete the mandatory audit.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 20's sanction for failing to complete the mandatory audit is an administrative financial penalty ARTCI imposes and collects itself; no article reviewed here makes the failure a criminal offence.
Penalty structure
Article 20 caps the sanction at 300,000,000 CFA francs (XOF) for a structure named in Article 3 that fails to complete the mandatory periodic security audit, doubled to 600,000,000 CFA francs on a repeat breach. The décret states only this ceiling; it names no floor.
- Rule
- Fixed only
- As of
- 18 September 2026
- Currency
- XOF
- Fixed cap
- 300,000,000
Who enforces it
Enforcement body
Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI), directly or through an ARTCI-accredited PASSI.
Settledness
- As of
- 18 September 2026
- Guidance link
- https://artci.ci/en/security-audit/
- Guidance body
- Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI)
- Open questions
- Does the eighteen-month periodic audit Article 4 requires after certification run within the same three-year certification cycle, or start a new one, given the décret states both clocks without reconciling them?
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 3 subjects every public-sector information system and an enumerated set of private-sector categories, a telecommunications or ICT company, a telecommunications or internet service provider, a company whose information system connects through Côte d'Ivoire's public telecommunications networks, a company that automatically processes its customers' personal data in providing its service, an electronic-transactions company, an ARTCI-approved service provider, and an electronic-archiving or record-keeping provider, to a mandatory periodic security audit.
Article 4 sets a three-year certification audit cycle, performed by ARTCI itself or by an ARTCI-accredited Prestataire d'Audit de Sécurité des Systèmes d'Information (PASSI), with a further mandatory periodic audit eighteen months after a certificate issues. Article 20 caps the financial penalty for failing to complete the audit at 300,000,000 CFA francs, doubled on a repeat breach.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product