Angola has officially published Law 9/26, of September 28, 2026 (Cybersecurity Law) which establishes a comprehensive legal framework for cybersecurity. It introduces strict compliance mandates, incident reporting duties, and significant financial penalties for public and private organizations operating within the country’s digital ecosystem.
Scope and Applicability
The law applies broadly to all natural and legal persons, public and private, who utilize Angolan cyberspace. Extraterritoriality applies if actions carried out outside of Angola are targeted at or affect the national cyberspace.
Key Covered Sectors and Entities
Specific security and registration duties are imposed on various digital and critical operators, including:
Core Obligations for Businesses
Incident Notification Requirements
Organizations must immediately notify CERT.ao (the operational arm of the National Cybersecurity Center) and their respective sectorial CSIRTs of any cybersecurity incident carrying a significant impact. An incident is categorized as significant if it causes severe operational disruption, substantial financial loss, prolonged service unavailability, or triggers a personal data breach. Notifications must include the incident’s nature, estimated impact, and mitigation measures taken, followed by a detailed final resolution report.
Enforcement and Financial Sanctions
The National Cybersecurity Center holds the authority to supervise, audit, and penalize non-compliant entities. Violations are categorized under a three-tiered administrative offense system:
Effective Date and Grace Period
The law entered into force immediately upon its publication on September 28, 2026. However, the statute grants a 180-day transitional grace period for all applicable entities to successfully finalize their mandatory operational registration with the National Cybersecurity Center.
© 2024 All rights reserved
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |