01/10/2026

Angola: New Cybersecurity Law

Angola has officially published Law 9/26, of September 28, 2026 (Cybersecurity Law) which establishes a comprehensive legal framework for cybersecurity. It introduces strict compliance mandates, incident reporting duties, and significant financial penalties for public and private organizations operating within the country’s digital ecosystem.

Scope and Applicability

The law applies broadly to all natural and legal persons, public and private, who utilize Angolan cyberspace. Extraterritoriality applies if actions carried out outside of Angola are targeted at or affect the national cyberspace.

Key Covered Sectors and Entities

Specific security and registration duties are imposed on various digital and critical operators, including:

  • Critical Infrastructure and Essential Services Operators (e.g., energy, transport, water, health, banking)
  • Digital Service Providers (e.g., online marketplaces, search engines)
  • Data Center and Cloud Computing Providers
  • Electronic Communications and Cybersecurity Service Providers

Core Obligations for Businesses

  • Mandatory Registration: All covered service providers must register with the National Cybersecurity Center (Centro Nacional de Cibersegurança).
  • Technical and Organizational Security: Entities must adopt proactive risk management policies, robust access controls, encryption, business continuity/disaster recovery plans, and permanent systems monitoring.
  • Internal Governance: High-risk operators are required to appoint a Cybersecurity Focal Point and establish an institutional Computer Security Incident Response Team (CSIRT).
  • Mandatory Civil Liability Insurance: Data center providers are required to secure and maintain adequate insurance coverage against cyber risks and inform subscribers of the policy details.

Incident Notification Requirements

Organizations must immediately notify CERT.ao (the operational arm of the National Cybersecurity Center) and their respective sectorial CSIRTs of any cybersecurity incident carrying a significant impact. An incident is categorized as significant if it causes severe operational disruption, substantial financial loss, prolonged service unavailability, or triggers a personal data breach. Notifications must include the incident’s nature, estimated impact, and mitigation measures taken, followed by a detailed final resolution report.

Enforcement and Financial Sanctions

The National Cybersecurity Center holds the authority to supervise, audit, and penalize non-compliant entities. Violations are categorized under a three-tiered administrative offense system:

  • Light Offenses: Such as the late submission of periodic reports. Corporate fines range between 70 and 150 national minimum wages.
  • Grave Offenses: Such as failing to register the activity, neglecting to notify incidents, or failing to maintain an incident response plan. Corporate fines range between 300 and 500 national minimum wages.
  • Very Grave Offenses: Such as failure to implement mandatory security requirements, falsifying audit reports, or obstructing inspections. Corporate fines range between 2,000 and 4,000 national minimum wages.
  • Ancillary Penalties: Severe or repeated offenses can lead to a temporary suspension of activities or a ban on participating in public procurement contracts for up to 3 years.

Effective Date and Grace Period

The law entered into force immediately upon its publication on September 28, 2026. However, the statute grants a 180-day transitional grace period for all applicable entities to successfully finalize their mandatory operational registration with the National Cybersecurity Center.

SHARE

CALL NOW

962 694 881

BUSINESS DAYS: 9:00 AM TO 7:00 PM

OR LEAVE US YOUR CONTACT

We call you