Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, articles 6, 7, 13-14, 24, 26-30, 32, 61(3) (mesures de sécurité et audit de sécurité obligatoire par l'ANTIC)
Loi n°2010/012 du 21 décembre 2010, art. 6-7, 13-14, 24, 26-30, 32, 61(3)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 21 December 2010.
A security baseline statutes rule binding public and private bodies.
As of 18 September 2026.
What it requires
- This applies to any operator of an electronic-communications network or an information system that offers a service in Cameroon, directly or indirectly; Cameroon's law does not gate this duty by sector, size, or a government designation, so it reaches a network operator, an electronic-communications service provider, and an information-system operator alike.
- Take all technical and administrative measures necessary to guarantee the security of the services you offer.
- Adopt standardized systems that let you continuously identify, assess, treat, and manage the risks to your information systems' security.
- Have Cameroon's National Information and Communication Technologies Agency (ANTIC) approve the security mechanisms you put in place for this purpose.
- Submit your networks and information systems to ANTIC's mandatory security audit, conducted at least once a year or whenever circumstances require it.
- Evaluate and revise your security systems as technology evolves, and make the changes your security practices, measures, and techniques need.
- Inform your users of the dangers of using your network or service, the specific security risks it faces, and the technical means available to secure their communications.
- Do not obstruct, resist, or prevent ANTIC's security audit, and do not refuse to provide the information or documents it requires; doing so is a criminal offense.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Article 61(3) punishes obstructing, inciting resistance to, or preventing the security audit this instrument requires, or refusing to provide the information or documents it calls for, with one to five years' imprisonment and a fine of 100,000 to 1,000,000 FCFA, or either penalty alone. No provision reviewed sets a distinct administrative or criminal penalty for an operator's substantive failure to implement the underlying security measures themselves, beyond the Agency's power under article 26(3) to withhold approval of a non-compliant security mechanism.
Penalty structure
Article 61(3) is the only sanction located for obstructing or resisting the security-audit regime: a fine of 100,000 to 1,000,000 FCFA (XAF), or one to five years' imprisonment, or either penalty alone. It does not multiply by a count of violations. No provision sets a separate penalty for an operator's substantive failure to implement the article 24, 26, 27, 28, and 30 security measures themselves.
- Rule
- Fixed only
- As of
- 18 September 2026
- Minimum
- 100,000
- Currency
- XAF
- Fixed cap
- 1,000,000
Who enforces it
Enforcement body
Agence Nationale des Technologies de l'Information et de la Communication (ANTIC), Cameroon's National Information and Communication Technologies Agency, which regulates, controls, and monitors network and information-system security activities and conducts the mandatory security audit, in collaboration with the Agence de Régulation des Télécommunications (ART), the Telecommunications Regulatory Agency.
Settledness
- As of
- 18 September 2026
- Open questions
- Have the implementing decrees that article 7(3), article 12, and article 30(4) direct the Prime Minister and the Minister in charge of Telecommunications to issue, for the security-audit's severity-impact criteria and the certification-authorization procedure, been published, and do they narrow which information-system operators the mandatory annual audit under article 32 actually reaches?
- Does 'exploitant des systèmes d'information' (information-system operator), defined by article 4(72) as an isolated device or group of interconnected devices carrying out automated data processing under a program, reach a service provider with no physical presence or registered business in Cameroon, or does the duty in practice bind only an operator registered or established in Cameroon?
What it reaches
Obligation class
Security, Governance, Disclosure
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 24 requires that the operators of electronic-communications networks and providers of electronic-communications services take all technical and administrative measures necessary to guarantee the security of the services offered, and separately requires them to inform their users of the dangers of using their networks, the specific security risks they face (distributed denial of service, abnormal rerouting, traffic spikes, unusual traffic and ports, passive and active eavesdropping, and intrusions), and the technical means available to secure their communications.
Article 26 separately binds any information-system operator, a term the law defines broadly as an isolated device or a group of interconnected devices carrying out automated data processing under a program, requiring it to adopt standardized systems that let it continuously identify, assess, treat, and manage the risks tied to its information systems' security within the services it offers directly or indirectly, and to put in place technical mechanisms against threats to its systems' permanent availability, integrity, authentication, non-repudiation, data confidentiality, and physical security.
The security mechanisms an information-system operator adopts for this purpose must be approved by Cameroon's National Information and Communication Technologies Agency (ANTIC), which the law calls the Agency, before they satisfy the duty. The same operators must evaluate and revise their security systems as technology evolves, introducing whatever changes their security practices, measures, and techniques need.
Beyond that self-implemented program, networks and information systems are subject to a mandatory, periodic security audit that the Agency itself conducts at least once a year or whenever circumstances require, with confidential audit reports going to the Minister in charge of Telecommunications.
Article 13 separately and expressly subjects the networks and information systems of operators, certification authorities, and providers of electronic-communications services to that same mandatory security audit.
Obstructing, resisting, or preventing that audit, or refusing to provide the information or documents it requires, is a criminal offense carrying one to five years' imprisonment and a fine of 100,000 to 1,000,000 FCFA, or either penalty alone, though no provision sets a distinct penalty for an operator's substantive failure to implement the underlying security measures themselves, beyond the Agency's power to withhold approval of a non-compliant mechanism.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product