Ethiopia's private-sector security posture rests on two currently enacted instruments plus one duty-to-report provision inside its computer-crime statute, with several adjacent regimes named here but not filed as instruments because their bound party is a status this profile's declared activities cannot express, or because they fall outside this topic's four registered families.
The Critical Infrastructure Cybersecurity Proclamation No. 1426/2026, published in the Federal Negarit Gazette (Year 32, No. 41) on 21 July 2026 and entering into force, under its own Article 28, one year later on 21 July 2027, lets the Information Network Security Administration designate, by Directive, specific institutions within twelve named sectors (information technology and communication, finance, security and safety, transport, education, health, water and energy, government services, disaster management, agriculture, trade, and industry) as critical infrastructure, and imposes eighteen obligations on each designated owner: building a national-framework-aligned cybersecurity program, classifying and protecting critical assets, conducting regular risk assessments, holding current cyber-audit and cybersecurity-inspection-and-evaluation certificates, employing certified cybersecurity professionals, securing the technology supply chain, obtaining security clearance before integrating a new or upgraded information and communication technology system, establishing a center to monitor, report on, and respond to cyberattacks, and notifying the National Computer Emergency Response Center of a cyber incident within 48 hours.
An owner may delegate these duties to a licensed cybersecurity service provider unless the Administration has designated the infrastructure as non-delegable on national-security grounds.
Breach of these duties carries administrative fines set article by article from 300,000 up to 2,000,000 Birr, doubled in some bands for a repeat violation and halved for a negligent one, and separately exposes an officer, employee, manager, or owner who intentionally commits the underlying failure to imprisonment of up to one year, rising to seven to ten years where the failure damages the infrastructure's service or harms national security, public health, life, or the environment.
The Proclamation's own text, and the Information Network Security Administration's public statements, both describe the twelve months after publication as a grace period for institutional readiness, and no designation Directive naming specific covered institutions is confirmed in the primary text, so which institutions are bound today, as distinct from which sectors could eventually be reached, is not yet settled.
Separately, and predating the Critical Infrastructure Proclamation, Article 27 of the Computer Crime Proclamation No. 958/2016, in force since its own publication on 7 July 2016, requires any service provider, meaning a person who provides technical data-processing or communication service or alternative infrastructure to users by means of a computer system, or any government organ, that becomes aware that a crime under that Proclamation is being committed, or that a third party is disseminating illegal content, through the computer system it administers, to notify the Information Network Security Agency (now the Administration) immediately and report the crime to the police; no provision of that Proclamation attaches a penalty to breach of this particular duty.
Part Four of the 2026 Proclamation (arts. 16 to 21) separately licenses and regulates persons who sell cybersecurity products or services, a narrow licensed-vendor status this profile's declared activities do not identify, so it is named here rather than filed.
The Information Technology Products Security Clearance and Control Proclamation No. 1310/2023, also administered by the Administration, is a national-security import, export, and use control and permit regime for technology products the Administration and the National Intelligence and Security Service designate as prohibited or restricted; it does not set a security-by-design or vulnerability-handling standard a product must meet to reach the market generally, so it does not fit any of this topic's four registered law families and is named here without being filed.
The Critical Mass Cyber Security Requirement Standard, version 2.0, issued by the Administration under Article 13 of the Council of Ministers Regulation No. 320/2014 that executes the Administration's own establishment proclamation, states in its own text that it is mandatory for Ethiopia's federal and regional governments and for unspecified 'key private organizations'; the primary text does not define which private organizations meet that description, so its private-sector reach is not filed here either.
Whether the National Bank of Ethiopia has issued its own binding cybersecurity or information-technology risk directive for licensed banks is not confirmed in the primary text: the National Bank's own directives listing serves only a JavaScript shell to the crawler on both the compliant and the browser tier.
No separate, general-application baseline security statute reaching an ordinary, undesignated business was located, so that research dimension is a researched absence outside the designated-critical-infrastructure and computer-crime duties above.
This jurisdiction's own privacy row, the Personal Data Protection Proclamation No. 1321/2024, in force since 24 July 2024, carries the breach-notification duty a data controller owes the Ethiopian Communications Authority within 72 hours; that duty, and the Proclamation's own security-of-processing article, are researched there and are not restated here.