-
Senegal plans tougher security rules for critical digital infrastructure.
-
The bill would create a national cybersecurity authority and CERT network.
-
The framework also seeks to support local cybersecurity firms and jobs.
Senegal plans to strengthen the protection of the digital infrastructure that supports government operations and essential services as recent cyber incidents highlight the vulnerability of public institutions.
The Ministry of Telecommunications and Digital Economy presented a bill on critical information infrastructure protection and digital security to the National Assembly on August 13. A joint committee comprising the Laws Committee and the Culture and Communication Committee examined the text, which aims to strengthen the country’s digital sovereignty and resilience to cyber threats.
The bill calls for the identification and registration of infrastructure considered critical, with security requirements based on risk levels. Standard information systems would follow a common set of requirements, while critical infrastructure would face tighter oversight.
The proposed measures include risk assessments, backup systems, encryption of sensitive data and regular resilience testing.
The reform comes after several Senegalese public institutions reported incidents that affected their information systems. The Public Treasury reported an incident on May 10, 2026, that affected part of its IT systems and prompted business continuity measures.
A month later, on June 15, the Court of Auditors also reported an incident involving its information system amid suspicions of a cyberattack. The incidents followed an October 2025 attack on the Directorate General of Taxes and Domains (DGID), highlighting the growing cyber risks facing public institutions.
A New National Cybersecurity Architecture
To address these risks, the bill provides for a national cybersecurity authority, a national Computer Emergency Response Team (CERT), sector-specific CERTs and services responsible for cybersecurity operations.
The proposed architecture aims to improve network monitoring, incident detection and coordination when strategic infrastructure is compromised.
The bill also sets rules for hosting public-sector data and outsourcing digital services. The government aims to gain greater control over the infrastructure used by public agencies and strengthen the continuity of essential services. The framework would also cover the security of connected devices, personal data protection and trust in digital services.
Beyond protecting public systems, Dakar wants the regulation to support the development of a domestic cybersecurity industry. The future framework is expected to promote accredited service providers, support Senegalese companies and start-ups, and create skilled jobs.
Senegal thus aims to strengthen both its cyber defense capabilities and its domestic technology ecosystem, in line with the ambitions of its New Deal Technologique and Senegal 2050 strategies.
Samira Njoya
