Ethiopia'sCriticalInfrastructureCybersecurityProclamation1426/2026:whatitrequires,andwhoitappliesto
What Proclamation 1426/2026 requires: the twelve covered sectors, the eighteen obligations, incident reporting, cyber audits and what to do first.
Proclamation No. 1426/2026, Ethiopia's Critical Infrastructure Cybersecurity Proclamation, was ratified by the House of People's Representatives in August 2026. It covers twelve sectors including finance, health, education, transport and energy, and places eighteen core obligations on operators, among them regular risk assessments, cyber audits, and deploying certified cybersecurity professionals.
Last reviewed
What the proclamation is
Ethiopia has had cybersecurity institutions for years - the Information Network Security Agency has been the national authority since 2011, and its Ethiopian Computer Emergency Response Team coordinates incident response. What it has not had is a law that says, in binding terms, what an individual organisation must do.
Proclamation No. 1426/2026 is that law. It establishes a framework for protecting critical national infrastructure, designates the sectors it applies to, sets out obligations for the organisations operating in them, and creates a fund for research and workforce development. INSA is charged with developing sector-specific standards underneath it and providing technical support.
This is a new obligation for most of the organisations it touches, and it arrived quickly. If you operate in one of the sectors below, the first task is not procurement. It is finding out what actually applies to you.
The twelve covered sectors
The proclamation designates twelve critical infrastructure sectors. The list is broad, and deliberately so - it reaches well beyond the utilities and telecoms that the phrase "critical infrastructure" usually calls to mind.
Sectors named in the proclamation:
- Information technology and communications
- Financial services
- Security and public safety
- Transportation
- Education
- Health
- Water and energy
- Government and public services
- Emergency and disaster response
- Agriculture
- Trade and commerce
- Industry
Health and education are worth pausing on, because they take in a great many organisations that would never have described themselves as critical infrastructure: private hospitals and clinics, diagnostic laboratories, private colleges and training institutes. Trade and commerce is broader still.
Whether a specific organisation falls inside the designation is a question for INSA's implementing standards rather than for a reading of the sector list alone. If you are in one of these sectors and hold data or run systems that matter, the sensible assumption is that this concerns you until you establish otherwise.
The eighteen obligations, in practical terms
The proclamation places eighteen core cybersecurity requirements on covered operators. Reported summaries group them around risk assessment, cyber audit, institutional governance, certified personnel, security technology and vulnerability management. In practice they translate into a fairly conventional programme, and most organisations will already have fragments of it.
What each obligation tends to mean in practice:
| Obligation | What it means in practice |
|---|---|
| Internal cybersecurity framework | Written policies, defined ownership, and someone accountable by name rather than by department |
| Periodic risk assessment | A recurring, documented review of what systems you hold, what they are exposed to, and what would happen if each failed |
| Cyber audit | Independent examination against a standard, evidenced - not a self-assessment spreadsheet |
| Certified professionals | Named, qualified people responsible for security, whether employed or contracted |
| Vulnerability management | Finding weaknesses on a schedule and fixing them on a clock, with a record of both |
| Incident reporting | The ability to detect an incident and notify the national response centre within the required window |
Summarised from public reporting of the proclamation as passed in August 2026. INSA's sector-specific implementing standards are the operative detail; confirm the requirements applying to your sector against those and against the published proclamation before acting.
Incident reporting and penalties
The obligation most likely to catch an organisation out is reporting. It is not enough to recover from an incident quietly; covered operators are required to notify the national computer emergency response centre, and to do so quickly.
Ethiopian press reporting of the proclamation describes administrative fines in the range of 1.5 to 2 million birr for failing to report a cyber incident within 48 hours of detection, or for neglecting required corrective action.
We repeat those figures as reported, not as verified. The operative numbers, deadlines and definitions are those in the proclamation as published in the Federal Negarit Gazeta and in INSA's implementing standards. If a reporting deadline or a penalty matters to a decision you are about to make, read the primary text or take legal advice - do not rely on this page, or on any other summary.
The practical consequence of a 48-hour clock is easy to miss: it is not primarily a legal problem, it is an engineering one. An organisation with no logging, no alerting and no idea who to call cannot report inside two days, because it will not know anything has happened. Detection capability is what makes the reporting obligation achievable, and it is the part that takes longest to build.
What to do first
A transition period was provided for compliance preparation. Used well, that is enough time; used as a reason to wait, it is not. In rough order:
- Establish whether you are coveredCheck your sector against the designation and against INSA's implementing standards as they are published. This is cheap and it determines everything that follows - including, quite possibly, that a lighter programme is appropriate.
- Inventory what you actually runSystems, data, who has access, what is internet-facing, what is outsourced and to whom. Almost nobody has this written down accurately, and no risk assessment means anything without it.
- Run a real risk assessmentNot a questionnaire. What can be reached from outside, what an attacker could do with it, and which handful of issues carry genuine consequence.
- Fix the exposed thingsUnpatched systems, weak or shared credentials, absent multi-factor authentication, and backups nobody has ever restored from. This is where most of the real risk sits and it is unglamorous work.
- Build detection and a reporting pathLogging, alerting, and a written procedure naming who decides, who notifies, and by when. Rehearse it once. A plan nobody has run is a document, not a capability.
- Write the governance downPolicies, ownership, review cadence, and an evidence trail. This is what an audit examines, and it is the part that cannot be assembled the week before one.
Where we fit
We deliver the hands-on engineering underneath compliance: source code auditing, security remediation, automated threat detection, and vulnerability patching across ERP and web applications.
We prepare and harden your digital infrastructure so your systems maintain the rigorous operational security standards demanded by Proclamation 1426/2026.
We build ERP systems, web platforms and mobile applications for Ethiopian organisations, including in the health and education sectors this proclamation names. That is the perspective we bring: most of the exposure in a mid-sized Ethiopian organisation is in its own software and its own operational habits, not in the absence of an appliance.
Questions people ask
Not sure whether this applies to you?
Tell us what sector you operate in and what systems you run. We will tell you what we think applies and what the first step is - before you spend anything.