World Watch/Comoros/Cybersecurity

Cybersecurity · Comoros

Cybersecurity regulation in Comoros (2026)

Comprehensive lawLaw No. 21-012/AU on Cybersecurity and the Fight Against Cybercrime (Union of Comoros), promulgated by Decree No. 22-003/PR (18 January 2022); supplemented by the Personal Data Protection Law (2021) and Penal Code Chapter IV (Articles 449–505 on cybercriminality); administered by ANADEN (National Agency for Digital Development)Country index 66 · B

Comoros shaded by its cybersecurity status

Comoros enacted a standalone, comprehensive cybersecurity and cybercrime law in 2021–2022 (Law 21-012/AU), covering critical infrastructure protection, cybercrime offences, and designating ANADEN as the national cybersecurity authority. A separate Personal Data Protection Law was enacted simultaneously, but the data protection supervisory body had not been formally constituted as of mid-2024. Implementation capacity remains limited: no operational national CIRT exists and the country scored 37.50/100 on the NCSI, ranking 92nd globally.

Key points

Primary Cybersecurity Law

Law No. 21-012/AU on Cybersecurity and the Fight Against Cybercrime was adopted in 2021 and formally promulgated by presidential Decree No. 22-003/PR on 18 January 2022, making it the binding legal foundation for cybersecurity in Comoros.

Regulatory Authority – ANADEN

Articles 6 and 7 of Law 21-012/AU designate ANADEN (Agence Nationale pour le Développement du Numérique) as the competent national authority for cybersecurity strategy, policy development, and oversight. ANRTIC (National Regulation Authority for ICT) retains general ICT sector regulatory functions.

Critical Infrastructure Protection

Chapter III of Law 21-012/AU (Articles 53–63) establishes obligations for operators of critical information infrastructure, including security requirements and incident-handling duties, though secondary regulations specifying sector-by-sector breach-notification timelines had not been publicly confirmed as adopted by early 2026.

Personal Data Protection & Breach Notification

A standalone Personal Data Protection Law enacted June 2021 establishes an independent supervisory authority with powers to investigate, warn, and sanction. It incorporates data-breach notification obligations; however, the supervisory authority had not been formally constituted or made operational as of mid-2024, leaving enforcement in abeyance.

National CIRT – Nascent

ITU undertook a National CIRT Assessment for Comoros to evaluate readiness for establishing an operational Computer Incident Response Team. As of the latest available data, Comoros does not have a fully operational national CIRT, though the ITU assessment process included stakeholder engagement and basic CIRT training.

Regional Commitments & NCSI Score

Comoros has signed the AU Malabo Convention on Cyber Security and Personal Data Protection but has not ratified it. The country scores 37.50/100 on the e-Governance Academy National Cyber Security Index (NCSI), ranked 92nd globally, reflecting the gap between enacted legislation and operational cybersecurity capacity.

Comoros - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →