Addis Ababa, August 7, 2026 – The Director General of
the Information Network Security Administration (INSA), H.E. Tigist Hamid, has
announced that the newly enacted Critical Infrastructure Cybersecurity Protection
Proclamation No. 1426/2026 G.C. represents a significant strategic
milestone in protecting Ethiopia's digital transformation journey and
strengthening the nation's digital sovereignty.
Speaking at a press briefing, the Director General
emphasized that the Proclamation establishes a comprehensive legal framework to
safeguard critical infrastructure, protect national interests, and enhance data
sovereignty by securing citizens' and national information assets against
evolving cyber threats.
The Proclamation identifies 12 critical
infrastructure sectors that require enhanced cybersecurity protection,
including information and communications technology (ICT), finance, security
and public safety, transport, education, healthcare, water and energy,
government services, emergency services, agriculture, trade, and industry.
To strengthen cyber resilience across these sectors,
the Proclamation introduces 18 mandatory cybersecurity obligations for
critical infrastructure owners and operators. These include developing
cybersecurity strategies and policies, conducting cyber risk assessments,
obtaining cybersecurity audit certification, implementing corrective actions,
deploying qualified cybersecurity professionals, securing supply chains,
establishing Security Operations Centers (SOCs), and reporting cyber incidents
to the National Computer Emergency Response Team (CERT) within 48 hours.
The Director General also announced the establishment
of a Critical Infrastructure Cybersecurity Fund, which will provide
sustainable financing for capacity building, research and development, security
enhancement, and resilience initiatives across critical sectors.
To facilitate effective implementation, the
Proclamation grants institutions a one-year grace period from the date
of its publication in the Federal Negarit Gazette to strengthen their
organizational readiness, build human capacity, and secure their technological
infrastructure. During this transition period, INSA will issue implementation
directives, publish standards, and provide technical support to ensure smooth
compliance.
📖 Read the full proclamation on
INSA's official portal: https://insa.gov.et/documentations