Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Incident and Vulnerability Notification Duties
Loi n° 05-20 relative à la cybersécurité Chapitre II, Section 3, Arts. 27, 30 et 33, promulguée par le Dahir n° 1-20-69 du 4 hija 1441 (25 juillet 2020), Bulletin Officiel n° 6906 du 16 hija 1441 (6 août 2020)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A vulnerability and incident reporting rule binding private bodies.
As of 17 September 2026.
What it requires
- This duty reaches you on the same terms as Loi n° 05-20's other opérateur security duties: you operate an online marketplace or service-contract platform, a search engine, a datacenter or cloud-computing hosting service, or you publish an Internet platform.
- Inform your clients of a vulnerability in your information systems, or of a breach that could affect them.
- When you detect an event that could affect the security of a client's information systems, inform the national cybersecurity authority of it without delay.
- If you are a digital service provider, as soon as you become aware of an incident affecting the networks or information systems your service needs, declare it to the national cybersecurity authority where the information available to you shows the incident has a significant impact on providing that service.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
Article 50 fixes a fine of 100,000 to 200,000 dirhams for a breach of the Article 30 or Article 33 incident-notification duties, the same tier Article 8's parallel duty on an entité draws; Article 52 doubles the sanction on recidivism within four years. Article 27's client-notification duty is not among the provisions Chapter V lists as carrying a fine.
- Rule
- Fixed only
- As of
- 17 September 2026
- Minimum
- 100,000
- Currency
- MAD
- Fixed cap
- 200,000
Who enforces it
Enforcement body
The national cybersecurity authority (autorité nationale) Loi n° 05-20 creates; DGSSI (Direction Générale de la Sécurité des Systèmes d'Information) operates in that role per its own published materials.
What it reaches
Obligation class
Reporting, Disclosure
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Chapter II, Section 3 of Loi n° 05-20 relative à la cybersécurité also binds the same opérateur class, a public telecommunications network operator, an Internet access provider, a cybersecurity service provider, a digital service provider, and an Internet platform publisher, to three notification duties with their own clocks. Article 27 requires an opérateur to inform its clients of a vulnerability in its information systems, or of a breach that could affect them.
Article 30 requires an opérateur, on detecting an event that could affect the security of a client's information systems, to inform the national cybersecurity authority of it without delay.
Article 33 requires a digital service provider specifically, as soon as it becomes aware of an incident affecting the networks or information systems its service needs, to declare the incident to the national authority where the information available to it shows the incident has a significant impact on providing that service.
A violation of Article 30 or 33 draws the same fine of 100,000 to 200,000 dirhams under Article 50 that Article 8's parallel duty on an entité draws, doubled on recidivism within four years under Article 52; Article 27's client-notification duty is not among the provisions Article 50 lists.
When LexLint raises it
operates_social_platform
Read the law
Text of Loi n° 05-20 relative à la cybersécurité
as published in Bulletin Officiel n° 6906 and mirrored by DGSSI (Direction Générale de la Sécurité des Systèmes d'Information)