Morocco - Cybersecurity Law (05-20)
Law No. 05-20 on Cybersecurity
Loi n° 05-20 relative à la cybersécurité
Morocco
RAI-MA-NA-0520000-202005-20
Morocco's primary legislation for securing critical information systems and establishing national cybersecurity governance.
Summary
Read full text ↗Plain English
Overview
Law No. 05-20 on Cybersecurity, promulgated by Dahir No. 1-20-69 on July 24, 2020, represents the cornerstone of Morocco's national legal framework for securing information systems. This legislation was introduced to address the growing complexity of cyber threats and to support the Kingdom's rapid digital transformation across both public and private sectors. The primary objective of the law is to establish a comprehensive set of rules and security standards designed to protect the information systems of State administrations, local authorities, public establishments, and specifically, 'Entities of Vital Importance' (Organismes d’Importance Vitale - OIV). By creating a structured legal environment, Morocco aims to enhance national sovereignty in cyberspace and ensure the continuity of essential services in the face of potential cyber-attacks or systemic failures. This law is a direct response to the 'Maroc Digital' strategies, ensuring that as the nation moves its services online, the underlying infrastructure remains resilient against state-sponsored actors, cybercriminals, and accidental disruptions. The law serves as a regulatory bridge between technical security requirements and the broader national security strategy of the Kingdom of Morocco, positioning the country as a regional leader in digital governance.
Definitions
The legislation provides precise legal definitions for several key concepts that are central to the enforcement of cybersecurity standards in Morocco. One of the most critical definitions is that of 'Cybersecurity' itself, which the law describes as the set of tools, policies, security concepts, safeguards, guidelines, risk management methods, actions, training, best practices, and technologies used to protect the cyber environment and the assets of organizations and users. This broad definition ensures that the law covers not just technical hardware and software, but also the human and procedural elements of security. Another pivotal term is the 'Organisme d’Importance Vitale' (OIV), which refers to any public or private entity whose activities are essential for the maintenance of vital societal functions, health, safety, and the economic or social well-being of the population. Additionally, the law defines 'Information Systems' as any organized set of resources (hardware, software, data, and personnel) used to process, store, or transmit information. The law also introduces the concept of 'Sensitive Information Systems,' which are those systems within an OIV that require a higher level of protection due to the nature of the data they handle or the criticality of the services they support. These definitions provide the necessary clarity for regulated entities to understand their obligations and for the judicial system to apply penalties in cases of non-compliance.
Governance and Institutional Framework
The governance structure established by Law No. 05-20 is centralized under the authority of the National Defense Administration, specifically through the General Directorate of Information Systems Security (Direction Générale de la Sécurité des Systèmes d'Information - DGSSI). The DGSSI acts as the national cybersecurity authority, responsible for coordinating the implementation of the law, defining technical standards, and overseeing the security of critical infrastructure. This institutional arrangement reflects the strategic importance of cybersecurity to national defense. The DGSSI is empowered to conduct inspections, approve security service providers, and issue binding directives to OIVs regarding the protection of their sensitive systems. It also hosts the National Computer Emergency Response Team (maCERT), which serves as the operational hub for incident detection and response. In addition to the DGSSI, the law establishes the Strategic Cybersecurity Committee (Comité Stratégique de Cybersécurité - CSSI). This committee is tasked with defining the national cybersecurity strategy, ensuring inter-ministerial coordination, and monitoring the overall state of the nation's cyber resilience. The CSSI is chaired by the Head of Government or a delegated authority and includes representatives from various key ministries and security agencies. This dual-layered governance model ensures that cybersecurity policy is integrated into broader national policy while maintaining the technical expertise required for effective enforcement.
Technical Standards and Certification
A core component of the law is the establishment of a national ecosystem of trusted cybersecurity service providers. The law stipulates that certain security services, such as auditing, incident response, and security monitoring (SOC), must be provided by entities that have been formally qualified or certified by the DGSSI. This ensures that the professionals handling Morocco's most sensitive infrastructure meet high standards of technical competence and integrity. The qualification process, known as PASSI (Prestataire d'Audit de la Sécurité des Systèmes d'Information), involves a rigorous evaluation of the provider's methodologies, personnel clearances, and technical tools. Furthermore, the law emphasizes proactive risk management, requiring entities to conduct regular vulnerability assessments and to develop comprehensive business continuity and disaster recovery plans. By focusing on these areas, the law aims to move the country from a reactive security posture to a proactive and resilient framework capable of withstanding sophisticated persistent threats. This certification regime also fosters the development of a local cybersecurity industry, reducing reliance on foreign providers for critical security functions and ensuring that sensitive data remains within a trusted national perimeter.
Key Focus Areas and Data Sovereignty
One of the primary focus areas of Law No. 05-20 is the mandatory protection of 'Entities of Vital Importance' (OIVs). The law requires these entities to identify their sensitive information systems and apply specific security standards defined by the national authority. This includes the implementation of robust access controls, encryption, and continuous monitoring. A significant requirement under this law is the obligation for OIVs to host their sensitive data and systems within the national territory (data sovereignty). This prevents the storage of critical state data on foreign servers where Moroccan authorities may lack jurisdiction or oversight, thereby mitigating risks related to international data transfers and foreign surveillance. This data residency requirement is particularly strict for systems classified as 'Sensitive,' ensuring that the Kingdom maintains full control over its most critical digital assets. Furthermore, the law addresses the security of cloud computing services used by public entities, mandating that such services meet specific security criteria and be hosted in data centers located in Morocco. This approach balances the benefits of digital transformation with the necessity of maintaining national control over critical information infrastructure.
Implementation Framework and the RSSI
The implementation of Law No. 05-20 is operationalized through Decree No. 2-21-406, which provides the technical details for the application of the law's provisions. The framework requires OIVs to appoint a 'Security Officer for Information Systems' (RSSI) who serves as the primary liaison with the DGSSI. This officer is responsible for internal compliance and for ensuring that the entity's security policy aligns with the national directive. One of the most rigorous components of the implementation framework is the mandatory security audit. OIVs must undergo an audit of their sensitive systems at least once every two years, performed by a DGSSI-qualified auditor. The results of these audits must be shared with the national authority, which can then issue recommendations or corrective measures. This ensures a cycle of continuous improvement and accountability. The RSSI role is critical, as it bridges the gap between technical implementation and executive management, ensuring that cybersecurity is treated as a strategic priority rather than just an IT issue. The law also mandates that OIVs develop and maintain an updated inventory of their information systems, which must be made available to the DGSSI upon request to facilitate national-level risk mapping.
Incident Response and maCERT
The law provides a legal basis for the intervention of specialized military and civilian authorities in the event of a national crisis, ensuring a coordinated and rapid response to large-scale incidents. The implementation framework mandates a strict incident reporting protocol. Any significant cyber-incident affecting a sensitive system must be reported immediately to the DGSSI/maCERT. This allows the national authority to aggregate threat intelligence and provide technical assistance if the incident has the potential to spread or impact other sectors. The law also provides for the creation of 'Sectoral Security Operations Centers' (SOCs) to provide specialized monitoring for specific industries like finance or energy. This decentralized yet coordinated approach allows for sector-specific expertise while maintaining a unified national situational awareness. maCERT acts as the central node in this network, disseminating alerts, providing technical support for incident remediation, and coordinating with international CERTs to mitigate cross-border threats. This structured response mechanism is designed to minimize the impact of cyber-attacks on the national economy and public safety, ensuring that essential services can be restored quickly in the event of a disruption.
Monitoring, Evaluation, and Inspections
Monitoring compliance with Law No. 05-20 is a continuous process led by the DGSSI. The authority has the power to conduct both scheduled and unannounced inspections of the facilities and information systems of OIVs. During these inspections, DGSSI agents are authorized to access technical documentation, interview personnel, and perform technical tests to verify that security controls are functioning as intended. If an inspection reveals deficiencies, the DGSSI issues a formal notice to the entity, specifying the corrective actions required and the timeline for implementation. This oversight mechanism is designed to ensure that cybersecurity is not treated as a one-time compliance checkbox but as an ongoing operational priority. Evaluation of the law's effectiveness is conducted at the strategic level by the CSSI. The committee reviews annual reports on the state of national cybersecurity, which include data on incident trends, the results of national audits, and the progress of the national cybersecurity strategy. This data-driven approach allows the government to identify emerging threats and adjust the regulatory framework or technical standards accordingly. The law also encourages the development of a national 'Cybersecurity Maturity Index' to benchmark the resilience of different sectors and drive competitive improvements in security posture.
Penalties, Liability, and Appeals
Law No. 05-20 introduces a robust regime of administrative and criminal penalties to enforce compliance. Failure to comply with the security requirements, such as neglecting to perform mandatory audits or failing to report a significant incident, can result in substantial fines. For instance, the law specifies fines ranging from 50,000 to 500,000 MAD for entities that fail to implement the required security measures for sensitive systems. In more severe cases, particularly those involving the compromise of national security or the intentional obstruction of DGSSI inspections, the law provides for criminal charges and imprisonment for the responsible officials. Liability under the law extends to the heads of the regulated entities, emphasizing that cybersecurity is a leadership responsibility. However, the law also provides mechanisms for administrative appeals. If an entity disagrees with a decision or a penalty imposed by the DGSSI, it can challenge the action through the administrative court system. The law ensures that while the state has broad powers to protect national security, these powers are exercised within a framework of legal accountability and due process. Additionally, the law clarifies the liability of third-party service providers, who can be held responsible if their failure to meet certified standards leads to a security breach in an OIV's system.
Relationship to Other Instruments
Law No. 05-20 does not operate in isolation but is part of a broader legal ecosystem in Morocco. It is closely linked to Law No. 09-08 relating to the protection of individuals with regard to the processing of personal data. While Law No. 05-20 focuses on the security of systems and infrastructure, Law No. 09-08 focuses on the rights of data subjects. Together, they provide a holistic framework for data governance. Furthermore, Law No. 05-20 complements Law No. 43-20 on digital trust, which provides the legal basis for secure digital transactions. The law also aligns with the Moroccan Penal Code, particularly the sections concerning computer-related crimes (Articles 607-3 to 607-11). Internationally, Morocco has designed Law No. 05-20 to be consistent with international best practices, reflecting the principles of the Budapest Convention on Cybercrime and drawing inspiration from the European Union's NIS Directive. Morocco is also a signatory to the Malabo Convention (African Union Convention on Cyber Security and Personal Data Protection), and Law No. 05-20 serves as a key instrument in fulfilling the Kingdom's commitments under this regional treaty. This integration with both domestic law and international standards ensures a coherent and comprehensive regulatory environment for technology in Morocco, facilitating international cooperation and mutual recognition of security standards.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Promulgation of Law No. 05-20 | 2020-07-24 | Official publication in the Bulletin Officiel (Dahir 1-20-69). |
| Publication of Application Decree 2-21-406 | 2021-07-01 | Detailed technical rules and governance procedures established. |
| Identification of OIVs | 2021-12-31 | Initial list of Entities of Vital Importance finalized by CSSI. |
| First Mandatory Audit Cycle | 2022-01-01 | OIVs began the first cycle of biennial security audits. |
| Qualification of Service Providers | 2022-06-30 | DGSSI began certifying private cybersecurity service providers (PASSI). |
Compliance Checklist
| Check | Required Action |
|---|---|
| OIV Designation | Determine if the entity is classified as an Organisme d’Importance Vitale (OIV) by the CSSI. |
| RSSI Appointment | Appoint a dedicated Security Officer for Information Systems and notify the DGSSI. |
| Sensitive System Mapping | Identify and document all 'Sensitive Information Systems' within the organization. |
| Security Policy Alignment | Ensure internal security policies meet the minimum standards set by DGSSI directives. |
| Data Residency Compliance | Verify that all sensitive data and processing systems are hosted within Moroccan territory. |
| Incident Reporting | Establish internal protocols for immediate reporting of cyber-incidents to maCERT. |
| Biennial Audit | Schedule and complete a security audit by a DGSSI-qualified third party every two years. |
Morocco's Law No. 05-20 on Cybersecurity establishes a comprehensive framework to secure critical information systems and govern national cybersecurity, primarily impacting public entities and private organizations deemed "Entities of Vital Importance" (OIVs).
This law, effective July 24, 2020, applies to all state administrations, local authorities, public establishments, and OIVs – which are any public or private entity essential for maintaining vital societal functions, health, safety, or economic well-being. The General Directorate of Information Systems Security (DGSSI) identifies these OIVs and acts as the national cybersecurity authority, defining standards and overseeing compliance.
Key obligations for OIVs include: identifying and protecting sensitive information systems according to DGSSI standards; appointing a Security Officer for Information Systems (RSSI) to liaise with the DGSSI; hosting all sensitive data and systems within Moroccan territory; undergoing mandatory security audits by DGSSI-qualified auditors at least every two years, with the first cycle starting January 1, 2022; and immediately reporting any significant cyber-incidents to the DGSSI/maCERT (National Computer Emergency Response Team).
Failure to comply can lead to significant penalties, including fines ranging from 50,000 to 500,000 Moroccan Dirhams for neglecting security measures or incident reporting. Severe cases, such as compromising national security or obstructing DGSSI inspections, can result in criminal charges and imprisonment for responsible officials, with liability extending to entity heads. A practical surprise for many might be the strict data sovereignty rule, requiring sensitive data and systems to be physically located within Morocco, potentially affecting cloud strategies or international data flows.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 14 marked completePlain-English obligations under Morocco - Cybersecurity Law (05-20). Not legal advice — verify against the official text before relying on it.
- #1CriticalKey Focus Areas and Data Sovereignty
Applies to: Entities of Vital Importance (OIVs)
“obligation for OIVs to host their sensitive data and systems within the national territory (data sovereignty).”
- #2CriticalKey Focus Areas and Data Sovereignty
Applies to: Public entities using cloud computing services
“mandating that such services meet specific security criteria and be hosted in data centers located in Morocco.”
- #3CriticalKey Focus Areas and Data Sovereignty
Applies to: Entities of Vital Importance (OIVs)
“The law requires these entities to identify their sensitive information systems”
- #4CriticalKey Focus Areas and Data Sovereignty
Applies to: Entities of Vital Importance (OIVs)
“apply specific security standards defined by the national authority.”
- #5CriticalImplementation Framework and the RSSI
Applies to: Entities of Vital Importance (OIVs)
“requires OIVs to appoint a 'Security Officer for Information Systems' (RSSI)”
- #6CriticalImplementation Framework and the RSSI⏰ Every two years, starting 2022-01-01
Applies to: Entities of Vital Importance (OIVs)
“OIVs must undergo an audit of their sensitive systems at least once every two years”
- #7CriticalImplementation Framework and the RSSI⏰ After each biennial audit
Applies to: Entities of Vital Importance (OIVs)
“The results of these audits must be shared with the national authority”
- #8CriticalIncident Response and maCERT⏰ Immediately upon discovery
Applies to: Entities of Vital Importance (OIVs)
“Any significant cyber-incident affecting a sensitive system must be reported immediately to the DGSSI/maCERT.”
- #9CriticalMonitoring, Evaluation, and Inspections⏰ As specified by DGSSI
Applies to: Entities of Vital Importance (OIVs)
“If an inspection reveals deficiencies, the DGSSI issues a formal notice to the entity, specifying the corrective actions required”
- #10CriticalTechnical Standards and Certification⏰ After 2022-06-30
Applies to: Entities of Vital Importance (OIVs)
“must be provided by entities that have been formally qualified or certified by the DGSSI.”
- #11CriticalPenalties, Liability, and Appeals
Applies to: Cybersecurity service providers to OIVs
“clarifies the liability of third-party service providers, who can be held responsible if their failure to meet certified standards”
- #12ImportantImplementation Framework and the RSSI
Applies to: Entities of Vital Importance (OIVs)
“OIVs develop and maintain an updated inventory of their information systems”
- #13ImportantTechnical Standards and Certification
Applies to: Entities of Vital Importance (OIVs)
“requiring entities to conduct regular vulnerability assessments”
- #14ImportantTechnical Standards and Certification
Applies to: Entities of Vital Importance (OIVs)
“to develop comprehensive business continuity and disaster recovery plans.”
Related Regulations
Ley N° 21.663 — Ley Marco de Ciberseguridad (Framework Law on Cybersecurity and Critical Information Infrastructure)
Chile88% similar
Digital X.0 Framework Law
Morocco88% similar
Bill for the Establishment of the National Agency for AI Governance
Morocco88% similar
“Kiberxavfsizlik to‘g‘risida”gi O‘zbekiston Respublikasi Qonuni
Uzbekistan88% similar
Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data
Morocco88% similar
© Regulations.AI — created on 09-Jan-2026 using Gemini 3 Flash Preview