Law / Mozambique

Cybersecurity Law, Incident Notification and Responsible Vulnerability Disclosure

Lei n.º 13/2026, arts. 57 a 66

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force in 11 days, effective 29 September 2026.

A vulnerability and incident reporting rule binding public and private bodies.

As of 18 September 2026.

What it requires

  • This duty does not yet bind: Mozambique's Cybersecurity Law (Lei n.º 13/2026) enters into force on 29 September 2026, ninety days after its 1 July 2026 publication.
  • It reaches you once it binds whether you are a Public Administration body, a private-sector business of any kind, or one of the named critical-infrastructure, essential-service, digital-service, data-centre, or cloud-platform categories.
  • Notify your sectoral CSIRT and the National CSIRT of a cybersecurity incident with a significant impact, judged by the number of users affected, duration, geographic spread, service disruption, and economic or social impact, within a deadline the National Cybersecurity Authority sets rather than the Law itself, and file a monthly report on your response and resolution.
  • If you operate a data centre or a cloud-computing platform, also notify your own subscribers promptly of an incident, including a data leak, that affects or may affect their content.
  • If you disclose a security vulnerability in good faith, including by giving at least 90 calendar days' notice before publishing it, the Law shields you from liability for having done so.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 76's own sanctions for this Law's contraventions are administrative fines rather than a criminal penalty, though its introductory clause leaves room for a more serious penalty under separate criminal legislation for the same conduct.

Who enforces it

Enforcement body

Autoridade Nacional de Segurança Cibernética (National Cybersecurity Authority), empowered by Article 11(b) to regulate, supervise, oversee, and impose sanctions in the field of cybersecurity.

Settledness

No court decision or regulator guidance construing these articles has been published yet; the Law's own implementing regulation is still pending.

As of
18 September 2026
Open questions
What notification deadline, in hours or days, will the National Cybersecurity Authority set for a significant incident, given that Articles 58 through 64 each defer the clock to a deadline the Authority determines rather than fixing one in the Law itself?

What it reaches

Obligation class

Reporting, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 57 defines a cybersecurity incident of significant impact by five alternative tests: its assessed severity, whether it stops an essential service beyond its maximum tolerable outage, whether it disrupts another essential-service provider, whether it requires an extraordinary remediation measure, or whether it harms a critical infrastructure's own users.

Articles 58 through 64 require the Public Administration and Private Sector at large, and separately the critical-infrastructure, essential-service, digital-service, digital-intermediary-service, data-centre, and cloud-computing-platform categories, to notify such an incident to their sectoral CSIRT and the National CSIRT within a deadline the National Cybersecurity Authority sets rather than the Law itself, and to file a monthly report on the incident's causes, resolution time, and measures taken; a data-centre or cloud-platform operator must also notify its own subscribers of an incident affecting their content.

Article 66 gives a good-faith safe harbour to a person who discloses a security vulnerability, provided among other conditions that they give at least 90 calendar days' notice before publishing it. Breach of the notification duty is punishable by a fine of 80 to 100 times the minimum public-service wage.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official gazette text, Boletím da República I Série No. 123 (1 July 2026), hosted by INTIC

Back to the example  ·  Lint your app