The one located product-security or sector-cyber-resilience duty on a private operator sits inside the National Communication Act, 2012 (Act No. 24): Section 88(3) requires every Licensee holding a National Communication Authority (NCA) licence to construct, install or operate a communication network to provide protection, technical security and safety for its facilities, equipment and communication networks, so as to ensure system efficiency and reliability, and Section 88(1) places a parallel duty on the Authority and Licensees together to protect communication networks against intrusion and vandalism.
Section 11 gives the Authority its own regulatory mandate to take appropriate measures protecting the security of information and communication networks against intrusion when regulating Internet domain names and electronic signatures, a power the Authority holds rather than a duty stated directly on a private operator, so it is recorded here as regulatory context rather than as its own instrument.
No general product-security or connected-device market-placement duty reaching an ordinary software product or app, no duty to report an exploited vulnerability or a security incident to an authority or to users on any clock, and no reasonable-security or information-security-programme statute reaching a business simply because it holds covered data was located in any South Sudanese instrument checked.
No personal-data-protection or breach-notification statute for South Sudan was located either, so no privacy-topic cross-reference is available to record here.
The Cybercrimes and Computer Misuse Provisional Order, 2021 and the Cybercrime and Computer Misuse Bill, 2025 that succeeded it, and Chapter XXVII of the Penal Code Act, 2008 (Sections 388 to 393, computer and electronic related offences), are all offence statutes directed at the person who attacks a system, a court, a network or a cardholder rather than at the person who operates one; a Ministry of Justice and Constitutional Affairs announcement of the 2021 order's launch lists 35 such offences, from unauthorized data transmission and computer hacking to identity-related offences and disclosure of passwords, with sentences of four to twenty years.
All three stay filed under this jurisdiction's scraping-topic computer-misuse family and are not restated here. mojca.gov.ss, the Ministry of Justice and Constitutional Affairs' own site, answers with an expired TLS certificate rather than a page, and the Internet Archive mirror otherwise used to reach its published Acts was itself unreachable, so the Cybercrime and Computer Misuse Bill 2025's own text, and the Ministry's complete published list of laws, are not described here.
Enforcement of the Section 88(3) duty runs to the National Communication Authority alone, through Section 97's administrative process rather than through a criminal charge or a private right of action: no criminal offence listed at Section 98 reaches a Licensee's own failure to secure its network, and no provision giving a beneficiary a private right of action over that failure was located.