Cybersecurity Incident Reporting and Emergency Response
Décret-loi n° 2023-17 du 11 mars 2023, relatif à la cybersécurité, Arts. 17-20, 24-25
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 11 September 2023.
A vulnerability and incident reporting rule binding public and private bodies.
As of 18 September 2026.
What it requires
- This duty runs to the same Article 6 population: telecommunications and internet operators, interconnected enterprises, hosting and cloud providers, enterprises automatically processing their users' personal data over telecommunications networks, and state-designated vital digital infrastructure.
- Create your own cybersecurity emergency response center, or join a public, sectoral or private one, and have it coordinate with the national emergency-response contact point.
- Immediately inform the national contact point or your emergency response center of any cybersecurity incident or attack, and comply with the emergency measures either one orders.
- Where an incident or attack has disrupted your information system or communications network, or endangered the national cyberspace's security, remedy the failure within thirty days of the Agency's warning, or expect the minister of communication technologies to order the temporary isolation of your systems.
- If you are classified at the first or second digital-trust level, expect a classification downgrade, rather than a fine, for failing to comply with an emergency measure or to create or join a response center.
- If you are classified at the third, unclassified level, expect a fine of 50,000 to 100,000 dinars for the same failures.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
The décret-loi names only an administrative reclassification downgrade (art. 24) for a first- or second-level organization and a financial penalty (art. 25) for a third-level one as the sanctions for an emergency-response or reporting failure; article 23's referral of constated infractions to the Public Prosecutor is a general enforcement mechanism rather than a named criminal offence for this duty.
Penalty structure
Article 25: a fine of 50,000 to 100,000 dinars for an Article 6 organization classified at the third, unclassified level that fails to comply with an emergency measure, to remedy a failure within the article 17 deadline, or to create or join an emergency response center. A first- or second-level organization draws the article 24 classification downgrade instead of this fine for the same failures.
- Rule
- Fixed only
- As of
- 18 September 2026
- Minimum
- 50,000
- Currency
- TND
- Fixed cap
- 100,000
Who enforces it
Enforcement body
Agence Nationale de la Cybersécurité (National Cybersecurity Agency), through its designated national emergency-response contact point, and the ministre chargé des technologies de la communication (Minister of Communication Technologies) for the isolation, downgrade and financial-penalty decisions.
Settledness
- As of
- 18 September 2026
- Open questions
- Article 17 lets the Agency warn an organization to remedy a disruptive incident within thirty days, but does not state what happens if that thirty-day remedy period and the ministerial isolation order under the same article run concurrently: can the minister isolate a system before the thirty days the Agency's own warning grants have run?
What it reaches
Obligation class
Security, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 19 requires the same Article 6 population, telecommunications and internet operators, interconnected enterprises, hosting and cloud providers, enterprises that automatically process their users' personal data over telecommunications networks, and vital digital infrastructure, to create its own cybersecurity emergency response center or to join a public, sectoral or private one, and to coordinate that center with the national emergency-response contact point Article 18 has the Agency designate.
Article 20 requires those organizations to immediately inform the national contact point or their emergency response center of any cybersecurity incident or attack, and to comply with the emergency measures either one orders.
Article 17 lets the Agency warn an organization whose incident or attack has disrupted its information system or communications network, or endangered the national cyberspace's security, to remedy the failure within thirty days, and lets the minister of communication technologies order the temporary isolation of its systems on the Agency's own reasoned report.
Article 24 lets the minister downgrade an organization classified at the first or second level, rather than fine it, for failing to comply with an emergency measure, to remedy a failure within the Article 17 deadline, or to create or join an emergency response center. Article 25 fines an organization classified at the third level 50,000 to 100,000 dinars for the same failures.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Full French text of Décret-loi n° 2023-17
hosted by legislation-securite.tn, a Tunisian security-sector legal-texts database maintained by DCAF (the Geneva Centre for Security Sector Governance), carrying the Journal Officiel publication metadata (JORT n° 26 of 11 March 2023)