Angola - New Cybersecurity Law

Angola - New Cybersecurity Law

October 2026
Angola - New Cybersecurity Law

Law No. 9/26 of 28 September establishes the legal framework for cybersecurity. It repeals Law No. 7/17 of 16 February, the Law on the Protection of Computer Networks and Systems (Lei de Protecção das Redes e Sistemas Informáticos).

The new regime imposes registration, risk management, and incident reporting obligations, directly impacting the activities of various categories of companies operating in Angola or whose actions are intended for Angolan cyberspace, in particular:

  • operators of critical infrastructure and providers of essential services;
  • digital service providers;
  • data centres service providers;
  • cloud computing service providers;
  • cybersecurity service providers;
  • electronic communications service providers.

Entities subject to registration have 180 days, until March 27, 2027, to register with the National Cyber Security Center (Centro Nacional de Cibersegurança).

Purpose: The Law seeks to protect citizens and public and private institutions against cyber threats and cyber-attacks. It also seeks to ensure the integrity, availability, authenticity and confidentiality of the country’s networks, information systems, critical infrastructure and essential services.

Scope: The Law applies to all public and private natural and legal persons that use Angolan cyberspace. It also applies to acts carried out outside the national territory, provided that they are directed at Angolan cyberspace. Cyber-defence and internal order are governed by a separate legal instrument.

In partnership with

Contacts

October 2026
Angola - New Cybersecurity Law

Key concepts

  • “Cybersecurity”: the set of measures, technologies, policies and practices intended to protect networks, computer systems, digital infrastructure and data against cyber threats and attacks, unauthorised access and operational failures, ensuring the confidentiality, integrity, authenticity and availability of information in the digital environment.

  • “Cyberspace”: the digital environment resulting from the interconnection of communications networks, information systems and technological infrastructure, including the internet, private networks and critical infrastructure, in which data and information are created, stored, processed and transmitted.

  • “Cyber threat”: an action, circumstance, event or conduct, whether intentional or accidental, capable of compromising the confidentiality, integrity, authenticity and availability of information systems, networks, critical infrastructure and data in cyberspace.

  • “Cyber-attack”: conduct carried out through networks, information systems or digital devices to compromise data, services and infrastructure. It may include espionage, sabotage, information theft, extortion or service disruption.

  • “Critical Infrastructure”: a facility, network, system or asset, whether physical or digital, located in the national territory and essential to maintaining vital functions of society, national security, public health, the economy or the well-being of the population.

  • “Service Provider”: a public or private natural or legal person who, in the course of its activities, makes available, operates or ensures the provision of services covered by this Law, using communications networks and information systems, such as:

    1. “Essential Services”: a public or private natural or legal person that provides services indispensable to the functioning of society and the economy. The interruption of those services has a significant impact on the continuity of fundamental social or economic functions.
    2. “Data Centre Services”: the storage, processing and transmission of data, encompassing facilities or groups of facilities dedicated to the hosting, interconnection and centralised operation of data communications network equipment and information technology;
    3. “Cybersecurity Services”: services relating to incident handling, vulnerability management, penetration testing, digital forensic services, cybersecurity governance, risk management, compliance, training and other cybersecurity services;

  • “CERT.ao”: the National Computer Emergency Response Team (Equipa Nacional de Resposta a Emergências Informáticas), the operational structure of the National Cybersecurity Centre (Centro Nacional de Cibersegurança).

  • “CSIRT (Computer Security Incident Response Team)”: a team of specialists responsible for preventing, managing and responding to cyber threats and attacks.

 

Covered entities

The Law defines the services forming part of the National Cybersecurity System (Sistema Nacional de Cibersegurança) and the obligations of their respective providers:

  • Critical infrastructure and essential services.
  • Digital services.
  • Data centre services.
  • Cloud computing services.
  • Cybersecurity services.
  • Electronic communications services.

 

Main duties of covered entities

Registration and Organisational

  • All entities subject to registration must register with the National Cybersecurity Centre.
  • Operators of critical infrastructure must also appoint a cybersecurity focal point and join a sector-specific CSIRT in accordance with their size, risk and criticality.
  • For digital services and essential services, organisational obligations are tailored according to the size, risk and criticality of the activity or organisation. Accordingly, a digital service provider may establish an institutional CSIRT, appoint a cybersecurity focal point or join a sector-specific CSIRT depending on these factors.
  • As for providers of essential services, the establishment of an institutional CSIRT is required in accordance with criteria defined on the basis of their size, criticality and risk.

Risk Management

  • Organisations must implement technical and organisational measures that are appropriate and proportionate to the risks and maintain procedures for the rapid recovery from incidents.

    In the case of essential services, this includes policies on backups, business continuity, supply chain security, multi-factor authentication and encryption. It also includes the approval and monitoring of these measures by the management body.
 

Information

  • Organisations must report to CERT.ao on any cyber threats and cyber attacks recorded in the course of their activities.

Confidentiality

  • Organisations must keep communications and information transmitted by users confidential.

Specific Duties

  • Data centre service providers must take out adequate insurance and inform subscribers of the existence, scope and conditions of the relevant cover.
  • Cloud computing service providers must also inform subscribers of any insurance cover provided by the service.
    Data centre and cloud computing service providers must adopt business continuity and disaster recovery policies and provide subscribers with a summary of these policies.
  • Cloud computing and electronic communications service providers must register their users, without this implying a general obligation to carry out civil identification of all users or the mass collection of personal data or communications content.

 

Incident notification

Organisations are required to report incidents with a significant impact.

Who?

  • Public Administration.
  • Sectoral and institutional CSIRTs.
  • Operators of critical infrastructure and providers of the services set out in the Act.
  • Other organisations that use networks and information systems, depending on their size, risk, criticality or economic and social impact.

What constitutes
a significant impact?

An incident has a significant impact, for example, when it causes serious operational disruption, affects a significant number of users, has a cross-border or systemic impact, or involves a personal data breach.

When?

  • The deadline will be set out in a separate piece of legislation.
  • High-impact incidents must be reported immediately.
  • In the cases provided for by the Act and applicable regulations, a final response and resolution report must also be submitted, without prejudice to interim reports where requested or where the incident remains ongoing.

What should be included?

The notification must include, at a minimum:
  • a description of the incident and its nature;
  • the estimated impact on the affected services;
  • the containment measures taken;
  • a preliminary assessment of the cause of the incident; and
  • other information relevant to managing the response.

 

Notification to CERT.ao or the sectoral CSIRT does not replace notifications legally required to the personal data protection authority, sectoral regulators, judicial authorities or service recipients, where applicable.

Providers of data centre and cloud computing services must also notify their customers of incidents that affect or may affect data, content or services, including personal data breaches where applicable.

Essential service providers that rely on a digital service provider to deliver an essential service must also notify them of significant impacts on the continuity of their services resulting from incidents affecting that provider.

 

Voluntary notification

Any entity may, on a voluntary basis, notify the sectoral CSIRT, the institutional CSIRT, or CERT.ao of incidents with a significant impact on the prevention, detection, response, recovery, and mitigation of cybersecurity incidents. Voluntary notification does not, in itself, create additional obligations for the notifying entity.

In any case, notification, in itself, does not constitute an admission of civil, administrative, or criminal liability.

 

Powers of CERT.ao and sectoral CSIRTs

They may, by means of a reasoned and proportionate decision, require operators of critical infrastructure or information systems to adopt preventive or corrective measures and to provide the technical and operational information necessary for the prevention, detection, analysis and response to incidents, including logs and indicators of compromise, without prejudice to the protection of personal data and without this constituting a breach of the duty of confidentiality. Where a system is compromised or at imminent risk, they may, by means of a reasoned and proportionate decision, order the temporary restriction of the use of systems or components that are strictly necessary.

 

Good-faith reporting of vulnerabilities

Any person may, in good faith, report vulnerabilities to the authorities legally competent in matters of cybersecurity without being deemed to have breached rules on confidentiality, data or system security, laws, contracts or codes of professional conduct by the mere fact of such reporting, subject to the terms, safeguards and exclusions set out in Article 48.

New cybersecurity rules, including registration, risk management, and incident reporting requirements, are already in force in Angola.

Administrative offence regime

Ancillary sanctions

  • Temporary suspension of activities until the requirements are met, in the event of a repeated offence or serious administrative offence.
  • Prohibition on participating in public procurement procedures for a period not exceeding three years, in the event of a very serious and repeated administrative offence.

A final decision imposing a fine and ancillary sanction for a serious or very serious administrative offence may be made public where this proves necessary to protect the public interest, prevent further offences or safeguard trust and security in the digital environment.

 

Civil and criminal liability

Civil liability arising from a breach of the Law is governed by the general principles of law. Criminal liability is governed by the Penal Code


Supervision and enforcement

Supervision and inspection are carried out by the cybersecurity regulatory body, in coordination with the competent sectoral regulators, while the National Cybersecurity Centre is responsible for the inspection and application of the administrative sanctions provided for in the Law.

 

Transitional regime and regulations

The Law came into force on 28 September 2026. Entities subject to registration must register within 180 days, that is, by 27 March 2027.

Various technical, procedural and compliance aspects – including security requirements, notification channels, notification deadlines and the organisation and functioning of the bodies – are subject to regulations yet to be adopted.

Interested in this article?