Law / Ethiopia

Critical Infrastructure Cybersecurity Proclamation, Cyber Incident Reporting to National CERT

Critical Infrastructure Cybersecurity Proclamation No. 1426/2026 art. 7(14), art. 9(2), art. 22(1)(b)-(c), art. 22(2)-(3), art. 22(5), art. 25(1)(b), art. 25(2)-(4), art. 28

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force in 304 days, effective 21 July 2027.

A vulnerability and incident reporting rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This binds a critical infrastructure owner, or its delegated cybersecurity service provider, that the Information Network Security Administration has designated by Directive under Article 5 as critical infrastructure within one of twelve named sectors (information technology and communication, finance, security and safety, transport, education, health, water and energy, government services, disaster management, agriculture, trade, and industry). It reaches a designated critical infrastructure located outside Ethiopia's territory as well as inside it, and the primary text confirms no duty yet on an organization the Administration has not designated.
  • Notify the National Computer Emergency Response Center of a cyber incident within 48 hours of becoming aware of it, using the system the Administration establishes, and implement the mandatory recommendations or directions the Center provides within the time it sets.
  • Provide the National Computer Emergency Response Center the information it requests and cooperate appropriately with its activities when it is responding to a cyberattack.
  • Failing to notify an incident within 48 hours, or to take appropriate corrective action, is an administrative offense fined from 1,500,000 to 2,000,000 Birr; failing to provide the requested information or cooperation during a cyberattack response is fined from 300,000 to 500,000 Birr; a negligent violation of either is fined at no more than half the stated amount, a first violation causing no damage may be resolved with a written warning instead, and a repeat violation is fined at triple the stated maximum.
  • An officer, employee, member of the management body, or owner of the critical infrastructure who intentionally fails to notify the Center within 48 hours, or to take appropriate corrective action, is separately subject to imprisonment of up to one year; where that failure interrupts, disrupts, or damages the critical infrastructure's service, compromises its integrity or confidentiality, or harms national security, national interest, public health, life, or the environment, the term rises to rigorous imprisonment of seven to ten years, or three to five years where the aggravated result is caused negligently.
  • This Proclamation is enacted but not yet in force. Article 28 sets its effective date one year after its own publication in the Federal Negarit Gazette (Year 32, No. 41), dated 21 July 2026, which places the effective date at 21 July 2027.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Article 25(1)(b): a cybersecurity officer, employee, member of the management body, or owner of a critical infrastructure who intentionally fails to notify the National Computer Emergency Response Center of a cyberattack within 48 hours, or fails to implement appropriate corrective action, is punishable with simple imprisonment of up to one year. Article 25(2) raises this to rigorous imprisonment of seven to ten years where the failure interrupts, disrupts, or damages the critical infrastructure's service, compromises its integrity or confidentiality, or causes harm to national security, national interest, public health or life, or the environment; Article 25(3) and (4) set six months' simple imprisonment and three to five years' rigorous imprisonment respectively where the same conduct is committed negligently.

Penalty structure

Two distinct administrative-fine bands inside Article 22(1): failing to notify the National Computer Emergency Response Center of a cyber incident within 48 hours, or to take appropriate corrective action, is fined from 1,500,000 to 2,000,000 Birr (art. 22(1)(b)); failing to provide requested information or cooperate appropriately with the Center's activities in responding to a cyberattack is fined from 300,000 to 500,000 Birr (art. 22(1)(c)). Article 22(2) fines a negligent violation of either at no more than half the stated amount; Article 22(3) lets the Administration resolve a first violation that caused no damage with a written warning instead of a fine; Article 22(5) fines a repeat violation at triple the stated maximum for that offense. The minimum and fixed_cap shown here are the overall floor and ceiling across both bands, not one uniform range.

Rule
Fixed only
As of
19 September 2026
Minimum
300,000
Currency
ETB
Fixed cap
2,000,000

Who enforces it

Enforcement body

The Information Network Security Administration, through the National Computer Emergency Response Center it administers.

Settledness

The Proclamation grants a one-year implementation period from its own publication before it enters into force, during which the Administration has publicly stated it will issue implementation directives and publish standards; no such directive is confirmed as a separately published text in the primary sources located here.

As of
19 September 2026
Open questions
  • Which specific institutions within the twelve named sectors has the Administration designated as critical infrastructure under Article 5, and has that designation Directive been published?
  • Has the Administration published the directive setting the system and procedure for the 48-hour notification duty under Article 7(14), and does it set a narrower clock or format for any sector?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Information Network Security Administration may designate a critical infrastructure owner under Article 5. A designated owner sits in one of twelve named sectors, including information technology and communication, finance, security and safety, and health. A designated owner must notify the National Computer Emergency Response Center of a cyber incident within 48 hours of becoming aware of it, and must implement the mandatory recommendations or directions the Center provides.

A designated owner must also give the Center the information it requests and cooperate with its activities when it is responding to a cyberattack. Failing the 48-hour notification or corrective-action duty is fined from 1,500,000 to 2,000,000 Birr.

Failing to cooperate with the Center's response activities is fined from 300,000 to 500,000 Birr, with a negligent violation of either fined at no more than half the stated amount, a first violation causing no damage resolved with a written warning instead, and a repeat violation fined at triple the stated maximum.

A critical infrastructure officer, employee, manager, or owner who intentionally commits either failure is separately liable to imprisonment of up to one year, a term that rises to rigorous imprisonment of seven to ten years, or three to five years if committed negligently, where the failure interrupts or damages the infrastructure's service or harms national security, national interest, public health, life, or the environment.

The Proclamation was published in the Federal Negarit Gazette, Year 32, No. 41, on 21 July 2026. Under its own Article 28, it enters into force one year later, on 21 July 2027.

When LexLint raises it

  • operates_essential_service
  • provides_financial_services
  • handles_health_records
  • provides_telecom_services

Read the law

Official Federal Negarit Gazette text, hosted on the Information Network Security Administration's own document portal

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app