Law / Tunisia

Mandatory Security Audit and Digital-Trust Classification

Décret-loi n° 2023-17 du 11 mars 2023, relatif à la cybersécurité, Arts. 6-9, 14-16, 24-25

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 11 September 2023.

A sector security regimes rule binding public and private bodies.

As of 18 September 2026.

What it requires

  • Where your service automatically processes your users' personal data while providing that service through Tunisia's telecommunications networks, you fall inside Article 6's mandatory-audit population; a telecommunications or internet operator, a hosting or cloud-computing provider, and a state-designated vital digital infrastructure are each named as their own separate category, roles no activity in this vocabulary independently expresses.
  • Undergo a mandatory information-systems security audit, performed by an expert the National Cybersecurity Agency lists as authorized, at least once every twelve months.
  • Submit a protected electronic copy of the audit report to the Agency within ten days of the audit's completion, and implement every security recommendation the report contains.
  • Where you host a governmental electronic system or service, do so only with a hosting or cloud provider holding the government-cloud or national-cloud label, or expect the same consequence your other Article 6 failures draw.
  • Expect the Agency to classify you into one of three digital-trust levels from your audit compliance, your equipment and your hosting choices, and expect a formal notice giving you up to one year to meet the standard if you are classified at the lowest, unclassified level.
  • If you are classified at the first or second level, expect the minister of communication technologies to downgrade your classification, rather than fine you, for failing to audit, report or implement recommendations on time.
  • If you are classified at the third, unclassified level, expect a fine of 50,000 to 100,000 dinars for the same failures.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

The décret-loi's own Chapter IX names only two sanctions for an Article 6 organization's audit or classification failure: an administrative reclassification downgrade (art. 24) for a first- or second-level organization, and a financial penalty (art. 25) for a third-level one. Article 23's referral of constated infractions to the Public Prosecutor is a general enforcement mechanism rather than a named criminal offence for this duty, and the only criminal exposure the text states, under article 254 of the Penal Code for a confidentiality breach (art. 9), binds Agency agents and auditors, not the audited operator.

Penalty structure

Article 25: a fine of 50,000 to 100,000 dinars for an Article 6 organization classified at the third, unclassified level that fails to complete the mandatory audit or to implement the audit report's recommendations. A first- or second-level organization draws the article 24 classification downgrade instead of this fine for the same failures; the décret-loi states no separate monetary figure for that path.

Rule
Fixed only
As of
18 September 2026
Minimum
50,000
Currency
TND
Fixed cap
100,000

Who enforces it

Enforcement body

Agence Nationale de la Cybersécurité (National Cybersecurity Agency), which reports to the ministre chargé des technologies de la communication (Minister of Communication Technologies), who issues the classification-downgrade and financial-penalty decisions and refers other infractions to the Public Prosecutor.

Settledness

As of
18 September 2026
Open questions
Articles 6 and 15 both leave their operative detail, the audit's technical criteria and the classification procedure, to an arrêté of the minister of communication technologies that this visit could not locate: have those implementing arrêtés been published, and do they narrow or widen the Article 6 population beyond the article's own five categories?

What it reaches

Obligation class

Security, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 6 subjects every public and private organization in five categories to a mandatory, periodic information-systems security audit: a public telecommunications network operator or telecommunications and internet service provider, an enterprise whose information networks are interconnected through telecommunications networks, a hosting or cloud-computing service provider, an enterprise that automatically processes its users' personal data while providing its service through telecommunications networks, and a vital digital infrastructure the state designates by decree.

Article 7 requires that audit to run at least once every twelve months, performed by an expert the Agency lists as authorized to practice cybersecurity auditing. Article 8 requires the audited organization to submit a protected electronic copy of the audit report to the Agency within ten days of the audit's completion, and to implement every recommendation the report contains.

Article 14 requires the same organizations to host any governmental electronic system or service only with a cloud-computing or hosting provider that holds the Article 12 government-cloud or national-cloud label. Article 15 subjects the same organizations to a mandatory, periodic classification into three digital-trust levels, set from their audit compliance, their use of approved equipment and solutions, and whether they host their systems with a labeled provider.

Article 16 gives an organization classified at the lowest, unclassified third level up to one year, after a formal notice, to meet the classification standard. Article 24 lets the minister of communication technologies downgrade an organization classified at the first or second level, rather than fine it, for failing to audit, to submit its audit report on time, to implement the report's recommendations, or to honor the Article 14 hosting duty.

Article 25 fines an organization classified at the third level 50,000 to 100,000 dinars for failing to audit or to implement the report's recommendations.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Full French text of Décret-loi n° 2023-17
hosted by legislation-securite.tn, a Tunisian security-sector legal-texts database maintained by DCAF (the Geneva Centre for Security Sector Governance), carrying the Journal Officiel publication metadata (JORT n° 26 of 11 March 2023) and the text's own repeal note for Loi n° 2004-5

Back to the example  ·  Lint your app