Law / Sierra Leone

Cyber Security and Crime Act, 2021, Critical National Information Infrastructure

Cyber Security and Crime Act, 2021 (Act No. 7 of 2021), ss. 7-8 (Critical National Information Infrastructure)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 15 November 2021.

A sector security regimes rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This only binds a computer system, computer data, or traffic data the President has designated, by an Order published in the Gazette on the Minister's recommendation and in consultation with the National Cybersecurity Advisory Council, as Critical National Information Infrastructure; declaring a flagged activity alone does not put an app in scope, and no public register of designated infrastructure was located.
  • If your system, data, or traffic data is designated, meet the minimum standards, guidelines, rules, or procedures the Presidential Order prescribes, which section 7(2) requires to cover at least securing systems by default and logging system and user activity for audit, and permit the National Computer Security Incidence Response Team to audit and inspect the designated infrastructure at any time.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Who enforces it

Enforcement body

The National Computer Security Incidence Response Team (established under section 2 as the National Computer Security Incidence Response Coordination Centre), which section 8 empowers to audit and inspect designated Critical National Information Infrastructure at any time where a Presidential Order under section 7(1) requires it; neither section 7 nor section 8 states a penalty for an operator's non-compliance.

Settledness

As of
19 September 2026
Open questions
  • Has the President published any Order under section 7(1) actually designating a computer system, computer data, or traffic data as Critical National Information Infrastructure, and if so, what does it cover?
  • What penalty or enforcement mechanism, if any, applies where a designated Critical National Information Infrastructure operator fails to meet a Presidential Order's minimum standards under section 7(2) or fails to cooperate with a section 8 audit or inspection, given neither section states one?
  • Does the Act intend the National Computer Security Incidence Response Team that sections 8 and 53 direct duties to, and the National Computer Security Incidence Response Coordination Centre that section 2 establishes, to be the same body, and if so what accounts for the two names?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 7(1) lets the Minister, in consultation with the National Cybersecurity Advisory Council, recommend that the President designate specific computer systems, computer data, or traffic data, or a combination of them, as Critical National Information Infrastructure by an Order published in the Gazette.

The Act's interpretation section defines Critical National Information Infrastructure as computer systems necessary for the continuous delivery of essential services Sierra Leone relies on, whose loss or compromise would have a debilitating impact including on services directly related to communications infrastructure, banking and financial services, public utilities, public transportation, or public-key infrastructure.

Under section 7(2), a Presidential Order made under section 7(1) must prescribe minimum standards, guidelines, rules, or procedures including requiring critical information systems to be secured by default and to log system and user activity for accurate and efficient audits.

Section 8 lets a Presidential Order made under section 7(1) require the National Computer Security Incidence Response Team to audit and inspect any Critical National Information Infrastructure at any time to ensure compliance with the Act. Section 2 establishes that body as the National Computer Security Incidence Response Coordination Centre, headed by the National Cyber Security Coordinator.

When LexLint raises it

  • provides_financial_services
  • operates_essential_service
  • provides_telecom_services

Read the law

official gazetted Act text, Supplement to the Sierra Leone Gazette No. 71 of 25 November 2021, reproduced by SierraLII (Laws.Africa)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app