Law / Ethiopia

Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner Obligations

Critical Infrastructure Cybersecurity Proclamation No. 1426/2026 art. 3, art. 4, art. 5, art. 7, art. 8, art. 22(1)(a), art. 22(1)(d)-(f), art. 22(2)-(3), art. 22(5), art. 25(1)(a), art. 25(1)(c)-(d), art. 25(2)-(4), art. 28

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force in 304 days, effective 21 July 2027.

A sector security regimes rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This binds a critical infrastructure owner, or its delegated cybersecurity service provider, that the Information Network Security Administration has designated by Directive under Article 5 as critical infrastructure within one of twelve named sectors (information technology and communication, finance, security and safety, transport, education, health, water and energy, government services, disaster management, agriculture, trade, and industry). It reaches a designated critical infrastructure located outside Ethiopia's territory as well as inside it, and the primary text confirms no duty yet on an organization the Administration has not designated.
  • Formulate and implement your own cybersecurity program and cybersecurity framework consistent with the mandatory national cybersecurity frameworks the Administration issues, classify and protect your critical assets to the Administration's standard, create the cybersecurity organizational structure the national framework calls for, and establish and manage a center responsible for monitoring, reporting, and responding to cyberattacks.
  • Conduct regular cybersecurity risk assessments and impact analyses, participate in the Administration's annual National Cybersecurity Risk Survey and supply the information it requests, and obtain and renew a cyber audit certificate and a cybersecurity inspection-and-evaluation certificate from the Administration, taking appropriate corrective action within the time the Administration sets on any gap the audit or inspection finds.
  • Employ cybersecurity professionals who hold a certification the Administration issues or recognizes, ensure the security of the supply chain of the technology products you use, obtain the Administration's security clearance before integrating a new or upgraded information and communication technology system acquired by purchase, donation, development, or any other means, and ensure that any employee or officer with access to your critical assets holds a security clearance from the relevant government body.
  • You may perform these obligations yourself or delegate them to a person licensed to provide cybersecurity services under this Proclamation, unless the Administration has identified your infrastructure, on national-security grounds, as one whose cybersecurity duties may not be delegated.
  • Not implementing a mandatory cybersecurity framework in a timely manner is an administrative offense fined from 500,000 to 1,000,000 Birr; not cooperating with a periodic cybersecurity audit is fined from 1,500,000 to 2,000,000 Birr; not taking timely corrective action on an audit or inspection finding, and using an information and communication technology system that has not undergone the required cybersecurity inspection and evaluation, are each fined from 800,000 to 1,000,000 Birr. A negligent violation is fined at no more than half those amounts, a first violation causing no damage may be resolved with a written warning instead, and a repeat violation is fined at triple the stated maximum for that offense.
  • An officer, employee, member of the management body, or owner of the critical infrastructure who intentionally fails to implement a mandatory cybersecurity framework, fails to take timely corrective action on an audit finding, or uses an information and communication technology system that has not undergone the required inspection and evaluation, is separately subject to imprisonment of up to one year, rising to rigorous imprisonment of seven to ten years, or three to five years if committed negligently, where the failure interrupts, disrupts, or damages the critical infrastructure's service, compromises its integrity or confidentiality, or harms national security, national interest, public health, life, or the environment.
  • This Proclamation is enacted but not yet in force. Article 28 sets its effective date one year after its own publication in the Federal Negarit Gazette (Year 32, No. 41), dated 21 July 2026, which places the effective date at 21 July 2027.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Article 25(1)(a), (c), and (d): a cybersecurity officer, employee, member of the management body, or owner of a critical infrastructure who intentionally fails to implement or ensure the timely implementation of a mandatory cybersecurity framework, fails to take timely corrective action on a gap the Administration's cyber audit identifies, or uses or causes to be used an information and communication technology system that has not undergone cybersecurity testing and evaluation, is punishable with simple imprisonment of up to one year. Article 25(2) raises this to rigorous imprisonment of seven to ten years where the failure interrupts, disrupts, or damages the critical infrastructure's service, compromises its integrity or confidentiality, or causes harm to national security, national interest, public health or life, or the environment; Article 25(3) and (4) set six months' simple imprisonment and three to five years' rigorous imprisonment respectively where the same conduct is committed negligently.

Penalty structure

Four distinct administrative-fine bands inside Article 22(1): not implementing a mandatory cybersecurity framework in a timely manner is fined from 500,000 to 1,000,000 Birr (art. 22(1)(a)); not cooperating with a periodic cybersecurity audit is fined from 1,500,000 to 2,000,000 Birr (art. 22(1)(d)); not taking timely corrective action on an audit or inspection finding is fined from 800,000 to 1,000,000 Birr (art. 22(1)(e)); and using an information and communication technology system that has not undergone the required cybersecurity inspection and evaluation is fined from 800,000 to 1,000,000 Birr (art. 22(1)(f)). Article 22(2) fines a negligent violation of any of these at no more than half the stated amount; Article 22(3) lets the Administration resolve a first violation that caused no damage with a written warning instead of a fine; Article 22(5) fines a repeat violation at triple the stated maximum for that offense. The minimum and fixed_cap shown here are the overall floor and ceiling across all four bands, not one uniform range.

Rule
Fixed only
As of
19 September 2026
Minimum
500,000
Currency
ETB
Fixed cap
2,000,000

Who enforces it

Enforcement body

The Information Network Security Administration.

Settledness

The Proclamation grants a one-year implementation period from its own publication before it enters into force, during which the Administration has publicly stated it will issue implementation directives and publish standards; no such directive is confirmed as a separately published text in the primary sources located here.

As of
19 September 2026
Open questions
  • Which specific institutions within the twelve named sectors has the Administration designated as critical infrastructure under Article 5, and has that designation Directive been published?
  • Have the mandatory national cybersecurity frameworks and standards Article 7 and Article 9(1) peg an owner's obligations to been published, given the Proclamation's own one-year implementation period?
  • Which critical infrastructure has the Administration identified, under Article 8(2), as infrastructure whose cybersecurity duties may not be delegated to a licensed cybersecurity service provider?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Information Network Security Administration may designate a critical infrastructure owner under Article 5. A designated owner sits in one of twelve named sectors, including information technology and communication, finance, transport, education, health, water and energy, government services, disaster management, agriculture, trade, and industry.

A designated owner must formulate and implement its own cybersecurity program based on the Administration's mandatory national cybersecurity frameworks. A designated owner must hold a current cyber-audit certificate and a cybersecurity inspection-and-evaluation certificate that the Administration issues. A designated owner must ensure the security of the supply chain of the technology products it uses.

A designated owner must obtain the Administration's security clearance before integrating a new or upgraded information and communication technology system. A designated owner must establish and manage a center responsible for monitoring, reporting, and responding to cyberattacks. An owner may perform these obligations itself or delegate them to a person providing cybersecurity services licensed under this Proclamation.

The Administration may identify infrastructure whose cybersecurity service may not be delegated on national-security grounds.

Not implementing a mandatory framework in time is fined from 500,000 to 1,000,000 Birr, not cooperating with a periodic audit is fined from 1,500,000 to 2,000,000 Birr, and not correcting an audit or inspection finding in time, or using an information and communication technology system that has not undergone the required inspection and evaluation, is each fined from 800,000 to 1,000,000 Birr, with a negligent violation of any of these fined at no more than half the stated amount, a first violation causing no damage resolved with a written warning instead, and a repeat violation fined at triple the stated maximum.

A critical infrastructure officer, employee, manager, or owner who intentionally commits the underlying failure is separately liable to imprisonment of up to one year, a term that rises to rigorous imprisonment of seven to ten years, or three to five years if committed negligently, where the failure damages the infrastructure's service or harms national security, national interest, public health, life, or the environment.

The Proclamation was published in the Federal Negarit Gazette, Year 32, No. 41, on 21 July 2026. Under its own Article 28, it enters into force one year later, on 21 July 2027.

When LexLint raises it

  • operates_essential_service
  • provides_financial_services
  • handles_health_records
  • provides_telecom_services

Read the law

Official Federal Negarit Gazette text, hosted on the Information Network Security Administration's own document portal

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app