Critical Infrastructure Cybersecurity Proclamation, Cyber Incident Reporting to National CERT
Critical Infrastructure Cybersecurity Proclamation No. 1426/2026 art. 7(14), art. 9(2), art. 22(1)(b)-(c), art. 22(2)-(3), art. 22(5), art. 25(1)(b), art. 25(2)-(4), art. 28
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force in 304 days, effective 21 July 2027.
A vulnerability and incident reporting rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This binds a critical infrastructure owner, or its delegated cybersecurity service provider, that the Information Network Security Administration has designated by Directive under Article 5 as critical infrastructure within one of twelve named sectors (information technology and communication, finance, security and safety, transport, education, health, water and energy, government services, disaster management, agriculture, trade, and industry). It reaches a designated critical infrastructure located outside Ethiopia's territory as well as inside it, and the primary text confirms no duty yet on an organization the Administration has not designated.
- Notify the National Computer Emergency Response Center of a cyber incident within 48 hours of becoming aware of it, using the system the Administration establishes, and implement the mandatory recommendations or directions the Center provides within the time it sets.
- Provide the National Computer Emergency Response Center the information it requests and cooperate appropriately with its activities when it is responding to a cyberattack.
- Failing to notify an incident within 48 hours, or to take appropriate corrective action, is an administrative offense fined from 1,500,000 to 2,000,000 Birr; failing to provide the requested information or cooperation during a cyberattack response is fined from 300,000 to 500,000 Birr; a negligent violation of either is fined at no more than half the stated amount, a first violation causing no damage may be resolved with a written warning instead, and a repeat violation is fined at triple the stated maximum.
- An officer, employee, member of the management body, or owner of the critical infrastructure who intentionally fails to notify the Center within 48 hours, or to take appropriate corrective action, is separately subject to imprisonment of up to one year; where that failure interrupts, disrupts, or damages the critical infrastructure's service, compromises its integrity or confidentiality, or harms national security, national interest, public health, life, or the environment, the term rises to rigorous imprisonment of seven to ten years, or three to five years where the aggravated result is caused negligently.
- This Proclamation is enacted but not yet in force. Article 28 sets its effective date one year after its own publication in the Federal Negarit Gazette (Year 32, No. 41), dated 21 July 2026, which places the effective date at 21 July 2027.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Article 25(1)(b): a cybersecurity officer, employee, member of the management body, or owner of a critical infrastructure who intentionally fails to notify the National Computer Emergency Response Center of a cyberattack within 48 hours, or fails to implement appropriate corrective action, is punishable with simple imprisonment of up to one year. Article 25(2) raises this to rigorous imprisonment of seven to ten years where the failure interrupts, disrupts, or damages the critical infrastructure's service, compromises its integrity or confidentiality, or causes harm to national security, national interest, public health or life, or the environment; Article 25(3) and (4) set six months' simple imprisonment and three to five years' rigorous imprisonment respectively where the same conduct is committed negligently.
Penalty structure
Two distinct administrative-fine bands inside Article 22(1): failing to notify the National Computer Emergency Response Center of a cyber incident within 48 hours, or to take appropriate corrective action, is fined from 1,500,000 to 2,000,000 Birr (art. 22(1)(b)); failing to provide requested information or cooperate appropriately with the Center's activities in responding to a cyberattack is fined from 300,000 to 500,000 Birr (art. 22(1)(c)). Article 22(2) fines a negligent violation of either at no more than half the stated amount; Article 22(3) lets the Administration resolve a first violation that caused no damage with a written warning instead of a fine; Article 22(5) fines a repeat violation at triple the stated maximum for that offense. The minimum and fixed_cap shown here are the overall floor and ceiling across both bands, not one uniform range.
- Rule
- Fixed only
- As of
- 19 September 2026
- Minimum
- 300,000
- Currency
- ETB
- Fixed cap
- 2,000,000
Who enforces it
Enforcement body
The Information Network Security Administration, through the National Computer Emergency Response Center it administers.
Settledness
The Proclamation grants a one-year implementation period from its own publication before it enters into force, during which the Administration has publicly stated it will issue implementation directives and publish standards; no such directive is confirmed as a separately published text in the primary sources located here.
- As of
- 19 September 2026
- Open questions
- Which specific institutions within the twelve named sectors has the Administration designated as critical infrastructure under Article 5, and has that designation Directive been published?
- Has the Administration published the directive setting the system and procedure for the 48-hour notification duty under Article 7(14), and does it set a narrower clock or format for any sector?
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Information Network Security Administration may designate a critical infrastructure owner under Article 5. A designated owner sits in one of twelve named sectors, including information technology and communication, finance, security and safety, and health. A designated owner must notify the National Computer Emergency Response Center of a cyber incident within 48 hours of becoming aware of it, and must implement the mandatory recommendations or directions the Center provides.
A designated owner must also give the Center the information it requests and cooperate with its activities when it is responding to a cyberattack. Failing the 48-hour notification or corrective-action duty is fined from 1,500,000 to 2,000,000 Birr.
Failing to cooperate with the Center's response activities is fined from 300,000 to 500,000 Birr, with a negligent violation of either fined at no more than half the stated amount, a first violation causing no damage resolved with a written warning instead, and a repeat violation fined at triple the stated maximum.
A critical infrastructure officer, employee, manager, or owner who intentionally commits either failure is separately liable to imprisonment of up to one year, a term that rises to rigorous imprisonment of seven to ten years, or three to five years if committed negligently, where the failure interrupts or damages the infrastructure's service or harms national security, national interest, public health, life, or the environment.
The Proclamation was published in the Federal Negarit Gazette, Year 32, No. 41, on 21 July 2026. Under its own Article 28, it enters into force one year later, on 21 July 2027.
When LexLint raises it
operates_essential_serviceprovides_financial_serviceshandles_health_recordsprovides_telecom_services
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.