Cybersecurity Law, General Security Requirements for the Public Administration and the Private Sector
Lei n.º 13/2026, arts. 47 a 50
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force in 11 days, effective 29 September 2026.
A security baseline statutes rule binding public and private bodies.
As of 18 September 2026.
What it requires
- This duty does not yet bind: Mozambique's Cybersecurity Law (Lei n.º 13/2026) enters into force on 29 September 2026, ninety days after its 1 July 2026 publication.
- It reaches you regardless of sector or size once it binds: Article 2 covers the whole private sector and the public administration alongside named categories of infrastructure, service, and platform operator, and Article 49 makes the minimum security requirements below compulsory for every entity the Law covers.
- Adopt a written information-security policy, a cyber-risk-management methodology, incident-notification procedures, mechanisms to prevent, correct, or mitigate cyber risk, a backup and recovery infrastructure, internal security-audit and oversight mechanisms, and a staff security-awareness and training programme.
- Name a person responsible for information security and stand up a team dedicated to detecting and responding to security incidents.
- If you are part of the Public Administration or the Private Sector at large, rather than one of the specifically named operator categories, also name an internal cybersecurity auditor, adopt an institutional information-security policy, and establish an institutional CSIRT.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 76's own sanctions for this Law's contraventions are administrative fines rather than a criminal penalty, though its introductory clause leaves room for a more serious penalty under separate criminal legislation for the same conduct.
Who enforces it
Enforcement body
Autoridade Nacional de Segurança Cibernética (National Cybersecurity Authority), empowered by Article 11(b) to regulate, supervise, oversee, and impose sanctions in the field of cybersecurity.
Settledness
No court decision or regulator guidance construing these articles has been published yet; the Law's own implementing regulation is still pending.
- As of
- 18 September 2026
- Open questions
- What specific technical and organisational measures will satisfy Article 48's minimum-security-requirements list, given that Article 79(2) leaves the Council of Ministers 180 days from publication to issue the implementing regulation?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Articles 47 through 50 of Mozambique's Cybersecurity Law (Lei n.º 13/2026) set minimum cybersecurity requirements binding every entity the Law covers, with no sector or size gate, and Article 50 restates the duty specifically for the Public Administration and the Private Sector at large.
A covered entity must maintain an information-security policy, a cyber-risk-management methodology, incident-notification procedures, risk-prevention and mitigation mechanisms, backup and recovery infrastructure, internal security-audit and oversight mechanisms, a staff security-awareness programme, a named person responsible for information security, and an incident detection-and-response team, and the Public Administration and the Private Sector must additionally name an internal cybersecurity auditor and establish an institutional CSIRT.
Breach of these requirements is punishable by a fine of 90 to 160 times the minimum public-service wage.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official gazette text, Boletím da República I Série No. 123 (1 July 2026), hosted by INTIC