Law No. 9/26 of 28 September (the “Cybersecurity Law”) was recently published in the Official Gazette, fully repealing Law No. 7/17 of 16 February (Law on the Protection of Computer Networks and Systems). The Law establishes the legal framework applicable to the protection of citizens and public and private entities against cyber threats and cyberattacks, as well as to the security of the country’s networks, information systems, critical infrastructure and essential services.
Compared with the previous regime, the Law has a significantly broader scope, covering all natural and legal persons, public and private, that use or operate in Angolan cyberspace. It also applies to acts carried out within and outside the national territory, whenever such acts are directed at, or produce effects in, Angolan cyberspace.
Key Changes
The main changes introduced include:
Main duties of covered providers
The main duties of covered providers include:
The duties that actually apply will depend on the nature, size, risk and criticality of the activity carried out, and each entity should assess its regulatory position in light of the services provided, the networks and systems used and its relationships with customers, subscribers and third-party providers.
Penalties
Failure to comply with the obligations set out in the Law may constitute a minor, serious or very serious administrative offence, punishable by fines and, in certain cases, by additional penalties of temporary suspension of activities and a ban on participating in public procurement procedures for a period of up to 3 years. For legal persons, fines for very serious offences may reach 2,000 to 4,000 national minimum wages, without prejudice to the other consequences provided for in the Law. Oversight and the application of penalties are the responsibility of the National Cybersecurity Centre.
Entry into force and recommendations
The Law entered into force on its date of publication, 28 September 2026. Entities subject to registration have 180 days from the entry into force to register.
Entities potentially covered are advised to: (i) confirm their classification and the applicable obligations; (ii) complete registration and appoint responsible officers, focal points and response teams; (iii) document their risk management, technical and organisational controls, and continuity and recovery plans; and (iv) test their procedures for detection, containment, notification and preparation of the final report.