On August 20, 2026, Senegal's National Assembly unanimously adopted—127 votes in favor, none against, and no abstentions—Bill No. 25/2026 on the protection of critical information infrastructure and digital security.
The vote is a major step, but terminology matters. A bill adopted by the Assembly does not automatically make every provision enforceable. As of September 12, 2026, the public sources reviewed document the vote and the bill, but not yet its promulgation under a final law number or publication in the Official Journal. Several obligations will also depend on decrees, standards, and classification decisions.
Another common confusion should be avoided. The bill primarily concerns cybersecurity and system resilience, especially for critical infrastructure. It does not replace Law No. 2008-12 on personal-data protection, which governs data processing and individual rights under the supervision of the CDP. The two regimes are complementary.
The digitalization of civil registration, finance, telecommunications, energy, healthcare, and transport can turn an IT outage into an economic and sometimes human risk. An attack can interrupt an essential service, destroy records, disrupt payments, or immobilize an entire public administration.
Until now, security requirements were spread across several laws, standards, and authorities. Bill No. 25/2026 seeks to create a cross-sector framework: identify critical infrastructure, impose a minimum level of risk management, and organize incident detection, reporting, and response.
In my Rewmi TV interview from 10:15, I supported this direction while emphasizing its real test: implementation. An ambitious law without trained teams, practical guidance, funding, and clear accountability can generate extensive compliance paperwork without improving actual security.
The public document identifies several structural measures.
Article 6 provides for a National Cybersecurity Authority with legal personality. It is intended to supervise standards, coordinate the national system, and operate within an architecture that also includes the national CERT, sectoral CERTs, and security operations centers.
Central coordination is valuable if it avoids institutional overlap. The DCSSI, CDP, ARTP, sector regulators, CERTs, and SOCs must know who leads a crisis, receives notifications, audits, imposes sanctions, and communicates publicly.
Article 27 gives critical information infrastructure operators six months after classification to develop a cybersecurity program. This means far more than purchasing antivirus software: asset inventories, risk analysis, access policies, vulnerability management, supplier security, business continuity, and executive-level governance.
Article 35 requires relevant incidents to be notified within 24 hours. This can accelerate national coordination and prevent the same attack from spreading silently across several operators.
Regulation will still need to define when the clock starts, which incident categories apply, what the initial report must contain, and which single channel should be used. During the first hours of a crisis, an organization rarely understands the full cause and scope. A workable model is a rapid initial alert followed by structured updates—not a complete forensic report that cannot realistically be produced in 24 hours.
Article 39 requires critical infrastructure operators to establish security operations services within one year. The objective is sound: continuous monitoring, detection, qualification, and response.
But requiring a SOC should not mean installing screens and a SIEM product. Organizations need usable logs, detection scenarios, an on-call team, tested procedures, and investigative capacity. For smaller entities, sectoral or shared SOCs will often be more realistic than an isolated center for every organization.
Article 12 establishes the principle that State and public-entity data should be stored in Senegal, subject to regulatory exemptions.
Digital sovereignty, however, cannot be reduced to server geography. Data hosted in Dakar but administered with keys controlled abroad, backed up without restoration tests, or accessible through excessively powerful accounts is not operationally sovereign. The assessment must cover:
Exemptions should be traceable, risk-based, and reviewed regularly.
Article 51 provides for significant administrative penalties for serious failures. They give the framework weight, but enforcement must be predictable and proportionate. Operators need to know the binding standard, remediation deadlines, adversarial procedure, and calculation criteria.
Penalties cannot compensate for a lack of support. They should follow readable requirements, coherent oversight, and a genuine opportunity to correct deficiencies.
Even before implementing regulations arrive, potentially affected bodies can begin work that will remain useful.
Technical assets must be linked to public services: which servers, applications, datasets, vendors, and connections are required for electricity, payments, healthcare, or civil registration? A hardware list alone cannot measure the impact of disruption.
Every critical service needs an RTO—the maximum acceptable interruption—and an RPO—the maximum acceptable data loss. These targets determine architecture, backups, redundancy, and exercises.
A backup only truly exists after restoration has been tested. The most critical data needs isolated or immutable copies so ransomware cannot encrypt production and backup data simultaneously.
Sensitive data must be encrypted in transit and at rest. Its protection depends on separation of duties, rotation, revocation, and secure key custody. Keeping the key beside the data is often equivalent to locking a door and leaving the key in it.
Organizations need an incident taxonomy, reachable on-call contacts, notification templates, a chain of evidence custody, and exercises involving technical, legal, executive, and communications teams. A 24-hour deadline is manageable only if the process exists before the crisis.
Cloud, telecoms, managed services, software, and maintenance create critical dependencies. Contracts should cover logs, reporting deadlines, audit rights, forensic cooperation, reversibility, and requirements imposed on subcontractors.
Compliance can be expensive for a startup, SME, or small public body. If every organization must recruit its own 24/7 team, purchase the same tools, and interpret the same obligations, the framework will become impractical or purely declarative.
The State should publish risk-proportionate requirement profiles and provide:
Support does not weaken the law. It increases the likelihood that the law produces security instead of files.
At least eight items should be tracked to evaluate implementation:
The adopted bill gives Senegal an opportunity to move from mainly reactive cybersecurity to measurable resilience. The direction is right. The outcome will depend less on the headline severity of penalties than on three capabilities: knowing what is critical, detecting early enough, and actually restoring the service.
This article is general information and not legal advice. The final promulgated text, its official publication, and implementing decrees must be verified before making compliance decisions.