World Watch/Congo/Cybersecurity

Cybersecurity · Congo

Cybersecurity regulation in Congo (2026)

Comprehensive lawOrdinance-Law No. 23/010 of 13 March 2023 (Code du Numérique / Digital Code); National Cybersecurity Strategy 2022; ARPTIC (Autorité de Régulation des Postes, Télécommunications et Technologies de l'Information et de la Communication, est. Decree 23/13 of 3 March 2023)Country index 69 · B

Congo shaded by its cybersecurity status

The Democratic Republic of Congo enacted a comprehensive Digital Code (Ordinance-Law No. 23/010) on 13 March 2023, consolidating cybersecurity, cybercrime, cryptology, data protection, and electronic transactions into one omnibus law. A National Cybersecurity Strategy was adopted in 2022, and the DRC formally ratified the African Union Malabo Convention on Cyber Security and Personal Data Protection in March 2025. Operators of essential services and digital service providers bear statutory incident-reporting obligations to designated government authorities, while a mandated Data Protection Authority is to enforce data-breach notification rules.

Key points

Digital Code 2023 (comprehensive law)

Ordinance-Law No. 23/010 of 13 March 2023 (published in the Official Journal 11 April 2023) is the principal instrument, covering cybersecurity governance, cybercrime offences, cryptology, electronic transactions, and personal data protection in a single statute.

National Cybersecurity Strategy 2022

The DRC adopted a National Cybersecurity Strategy in 2022 under the broader Plan National du Numérique – Horizon 2025, establishing strategic objectives for protecting critical information infrastructure and building national cyber capacity.

Regulatory authority – ARPTIC

Decree No. 23/13 of 3 March 2023 created ARPTIC as the sector regulator for posts, telecommunications, and ICT, with oversight responsibilities that include cybersecurity compliance for licensed operators.

Incident-reporting obligations

The Digital Code imposes notification duties on digital service providers and operators of essential services: significant cybersecurity incidents must be reported to designated government authorities. A national CSIRT/CERT function for coordinating incident response is referenced in the framework.

Data Protection Authority & breach notification

The Digital Code mandates establishment of an independent Data Protection Authority empowered to investigate breaches, issue warnings, and impose fines of 8 million to 200 million Congolese francs; several implementing decrees remain pending as of 2024–2025.

AU Malabo Convention ratification

The DRC ratified the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) on 6 March 2025, binding it to AU-level standards on cybersecurity, cybercrime, and data protection.

Congo - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →