Ethiopia’s cybersecurity law creates fund and 48-hour incident reporting rule

A new critical-infrastructure cybersecurity framework creates a dedicated fund, sets compliance duties across 12 sectors and requires covered operators to report cyber incidents within 48 hours.

In short

  • A new critical-infrastructure cybersecurity framework creates a dedicated fund, sets compliance duties across 12 sectors and requires covered operators to report cyber incidents within 48 hours.
INSA Introduces Critical Infrastructure Cybersecurity Fund
INSA Introduces Critical Infrastructure Cybersecurity Fund

Ethiopia’s Information Network Security Administration has introduced a critical-infrastructure cybersecurity framework that creates a permanent security fund and requires covered organizations to report cyber incidents within 48 hours.

The Critical Infrastructure Cybersecurity Protection Proclamation covers 12 sectors, according to details reported by The Reporter Ethiopia on August 8, 2026. They include information and communications technology, finance, public safety, transport, education, healthcare, water and energy, government and emergency services, agriculture, trade and industry.

The fund is intended to finance security frameworks, technology platforms, research, training, exercises and public-awareness programs. Revenue is expected to come from monthly contributions by critical-infrastructure entities under regulations to be issued by the Council of Ministers, as well as administrative fines, service fees and voluntary contributions. The money will be held in an account opened by the Ministry of Finance.

Covered infrastructure owners and operators will be required to establish security operations centers, assess cyber risks, obtain audit certification, strengthen supply-chain security and employ qualified cybersecurity personnel. Incidents must be reported to the national computer emergency response team within 48 hours of detection.

Organizations have been given a one-year transition period from publication of the proclamation in the Federal Negarit Gazette to upgrade technology and staffing. INSA is expected to provide technical support and issue implementing standards during that period.

The reported framework provides for administrative fines of 1.5 million to 2 million birr for failures including not reporting an incident within the deadline or neglecting required corrective action. Further implementation details will depend on regulations and directives issued under the proclamation.