Law / Ivory Coast

Mandatory Information Systems Security Audit and Certification

Décret n°2021-917 du 22 décembre 2021, Arts. 3-4, 19-21

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 22 December 2021.

A sector security regimes rule binding public and private bodies.

As of 18 September 2026.

What it requires

  • Where your service's information system connects through Côte d'Ivoire's public telecommunications networks, or you automatically process your customers' personal data in providing your service, you fall inside Article 3's mandatory-audit population; a telecommunications or ICT company, a telecommunications or internet service provider, an electronic-transactions company, an ARTCI-approved service provider, and an electronic-archiving or record-keeping provider are each named as their own category, a set of roles no activity in this vocabulary independently expresses.
  • Undergo a security audit for certification of your information system every three years, performed by ARTCI or by an ARTCI-accredited Prestataire d'Audit de Sécurité des Systèmes d'Information (PASSI).
  • Undergo a further mandatory periodic security audit eighteen months after your certificate is issued.
  • Correct a major nonconformity ARTCI identifies and have your information system re-audited within twelve months, or receive a formal notice ordering you to comply.
  • Expect a financial penalty proportional to the breach's severity and the advantage you gained, capped at 300,000,000 CFA francs and doubled on a repeat breach, if you fail to complete the mandatory audit.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 20's sanction for failing to complete the mandatory audit is an administrative financial penalty ARTCI imposes and collects itself; no article reviewed here makes the failure a criminal offence.

Penalty structure

Article 20 caps the sanction at 300,000,000 CFA francs (XOF) for a structure named in Article 3 that fails to complete the mandatory periodic security audit, doubled to 600,000,000 CFA francs on a repeat breach. The décret states only this ceiling; it names no floor.

Rule
Fixed only
As of
18 September 2026
Currency
XOF
Fixed cap
300,000,000

Who enforces it

Enforcement body

Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI), directly or through an ARTCI-accredited PASSI.

Settledness

As of
18 September 2026
Guidance link
https://artci.ci/en/security-audit/
Guidance body
Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI)
Open questions
Does the eighteen-month periodic audit Article 4 requires after certification run within the same three-year certification cycle, or start a new one, given the décret states both clocks without reconciling them?

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 3 subjects every public-sector information system and an enumerated set of private-sector categories, a telecommunications or ICT company, a telecommunications or internet service provider, a company whose information system connects through Côte d'Ivoire's public telecommunications networks, a company that automatically processes its customers' personal data in providing its service, an electronic-transactions company, an ARTCI-approved service provider, and an electronic-archiving or record-keeping provider, to a mandatory periodic security audit.

Article 4 sets a three-year certification audit cycle, performed by ARTCI itself or by an ARTCI-accredited Prestataire d'Audit de Sécurité des Systèmes d'Information (PASSI), with a further mandatory periodic audit eighteen months after a certificate issues. Article 20 caps the financial penalty for failing to complete the audit at 300,000,000 CFA francs, doubled on a repeat breach.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official décret text, ARTCI document repository

Back to the example  ·  Lint your app