Skip to content
Regulatory Guide

Ethiopia'sCriticalInfrastructureCybersecurityProclamation1426/2026:whatitrequires,andwhoitappliesto

What Proclamation 1426/2026 requires: the twelve covered sectors, the eighteen obligations, incident reporting, cyber audits and what to do first.

Proclamation No. 1426/2026, Ethiopia's Critical Infrastructure Cybersecurity Proclamation, was ratified by the House of People's Representatives in August 2026. It covers twelve sectors including finance, health, education, transport and energy, and places eighteen core obligations on operators, among them regular risk assessments, cyber audits, and deploying certified cybersecurity professionals.

Last reviewed

What the proclamation is

Ethiopia has had cybersecurity institutions for years - the Information Network Security Agency has been the national authority since 2011, and its Ethiopian Computer Emergency Response Team coordinates incident response. What it has not had is a law that says, in binding terms, what an individual organisation must do.

Proclamation No. 1426/2026 is that law. It establishes a framework for protecting critical national infrastructure, designates the sectors it applies to, sets out obligations for the organisations operating in them, and creates a fund for research and workforce development. INSA is charged with developing sector-specific standards underneath it and providing technical support.

This is a new obligation for most of the organisations it touches, and it arrived quickly. If you operate in one of the sectors below, the first task is not procurement. It is finding out what actually applies to you.

The twelve covered sectors

The proclamation designates twelve critical infrastructure sectors. The list is broad, and deliberately so - it reaches well beyond the utilities and telecoms that the phrase "critical infrastructure" usually calls to mind.

Sectors named in the proclamation:

  • Information technology and communications
  • Financial services
  • Security and public safety
  • Transportation
  • Education
  • Health
  • Water and energy
  • Government and public services
  • Emergency and disaster response
  • Agriculture
  • Trade and commerce
  • Industry

Health and education are worth pausing on, because they take in a great many organisations that would never have described themselves as critical infrastructure: private hospitals and clinics, diagnostic laboratories, private colleges and training institutes. Trade and commerce is broader still.

Whether a specific organisation falls inside the designation is a question for INSA's implementing standards rather than for a reading of the sector list alone. If you are in one of these sectors and hold data or run systems that matter, the sensible assumption is that this concerns you until you establish otherwise.

The eighteen obligations, in practical terms

The proclamation places eighteen core cybersecurity requirements on covered operators. Reported summaries group them around risk assessment, cyber audit, institutional governance, certified personnel, security technology and vulnerability management. In practice they translate into a fairly conventional programme, and most organisations will already have fragments of it.

What each obligation tends to mean in practice:

ObligationWhat it means in practice
Internal cybersecurity frameworkWritten policies, defined ownership, and someone accountable by name rather than by department
Periodic risk assessmentA recurring, documented review of what systems you hold, what they are exposed to, and what would happen if each failed
Cyber auditIndependent examination against a standard, evidenced - not a self-assessment spreadsheet
Certified professionalsNamed, qualified people responsible for security, whether employed or contracted
Vulnerability managementFinding weaknesses on a schedule and fixing them on a clock, with a record of both
Incident reportingThe ability to detect an incident and notify the national response centre within the required window

Summarised from public reporting of the proclamation as passed in August 2026. INSA's sector-specific implementing standards are the operative detail; confirm the requirements applying to your sector against those and against the published proclamation before acting.

Incident reporting and penalties

The obligation most likely to catch an organisation out is reporting. It is not enough to recover from an incident quietly; covered operators are required to notify the national computer emergency response centre, and to do so quickly.

Check the figures against the published proclamation

Ethiopian press reporting of the proclamation describes administrative fines in the range of 1.5 to 2 million birr for failing to report a cyber incident within 48 hours of detection, or for neglecting required corrective action.

We repeat those figures as reported, not as verified. The operative numbers, deadlines and definitions are those in the proclamation as published in the Federal Negarit Gazeta and in INSA's implementing standards. If a reporting deadline or a penalty matters to a decision you are about to make, read the primary text or take legal advice - do not rely on this page, or on any other summary.

The practical consequence of a 48-hour clock is easy to miss: it is not primarily a legal problem, it is an engineering one. An organisation with no logging, no alerting and no idea who to call cannot report inside two days, because it will not know anything has happened. Detection capability is what makes the reporting obligation achievable, and it is the part that takes longest to build.

What to do first

A transition period was provided for compliance preparation. Used well, that is enough time; used as a reason to wait, it is not. In rough order:

  1. Establish whether you are coveredCheck your sector against the designation and against INSA's implementing standards as they are published. This is cheap and it determines everything that follows - including, quite possibly, that a lighter programme is appropriate.
  2. Inventory what you actually runSystems, data, who has access, what is internet-facing, what is outsourced and to whom. Almost nobody has this written down accurately, and no risk assessment means anything without it.
  3. Run a real risk assessmentNot a questionnaire. What can be reached from outside, what an attacker could do with it, and which handful of issues carry genuine consequence.
  4. Fix the exposed thingsUnpatched systems, weak or shared credentials, absent multi-factor authentication, and backups nobody has ever restored from. This is where most of the real risk sits and it is unglamorous work.
  5. Build detection and a reporting pathLogging, alerting, and a written procedure naming who decides, who notifies, and by when. Rehearse it once. A plan nobody has run is a document, not a capability.
  6. Write the governance downPolicies, ownership, review cadence, and an evidence trail. This is what an audit examines, and it is the part that cannot be assembled the week before one.

Where we fit

Cybersecurity Remediation & Security Engineering

We deliver the hands-on engineering underneath compliance: source code auditing, security remediation, automated threat detection, and vulnerability patching across ERP and web applications.

We prepare and harden your digital infrastructure so your systems maintain the rigorous operational security standards demanded by Proclamation 1426/2026.

We build ERP systems, web platforms and mobile applications for Ethiopian organisations, including in the health and education sectors this proclamation names. That is the perspective we bring: most of the exposure in a mid-sized Ethiopian organisation is in its own software and its own operational habits, not in the absence of an appliance.

Questions people ask

It was ratified by the House of People's Representatives and announced in August 2026. A transition period was provided for compliance preparation, and INSA is developing sector-specific standards underneath it. Confirm the dates applying to your sector against the published proclamation.

It applies to operators of designated critical infrastructure, and the twelve named sectors include financial services, health, education, agriculture, trade and commerce and industry - which are largely private. Being a private company is not, by itself, an exemption.

Proclamation 1426/2026 concerns the security of critical infrastructure and applies by sector. Proclamation 1321/2024, the Personal Data Protection Proclamation, concerns personal data and applies to any controller or processor regardless of size or sector. Many organisations are covered by both.

Health is one of the twelve designated sectors. Whether a particular clinic falls inside the designation depends on INSA's implementing standards rather than on the sector list alone. Given that clinics also hold personal health data and so fall under the data protection proclamation regardless, the practical answer for most is that some obligation applies.

It depends almost entirely on what you already have. An organisation with current systems, working backups and some logging is doing a gap assessment and tidying up. An organisation running unsupported software with shared administrator passwords is doing remediation first. Establish which you are before budgeting - the assessment is the cheap part.

Not sure whether this applies to you?

Tell us what sector you operate in and what systems you run. We will tell you what we think applies and what the first step is - before you spend anything.