Tunisia’s Prime Minister Tightens Digital Security Rules for Public Administration
Tunisian Prime Minister Sarra Zaâfrani Zenzeri has issued new directives to strengthen digital security within the government. Her Circular No. 5, dated September 2, 2026, is addressed to ministers, secretaries of state, governors (walis), and heads of public institutions and enterprises.
The circular mandates the implementation of a technical note issued by the National Agency for Information Security (ANSI), specifically targeting Chief Information Security Officers (CISOs) within the public sector.
Stricter Requirements for Public Websites and Data
The new regulations build upon existing legal frameworks, including the 2004 Organic Law on Personal Data Protection, as well as laws adopted in 2020 and 2023 concerning electronic exchanges and cybersecurity.
Key requirements include:
- Approved Hosting Providers: All administrative platforms must be hosted by accredited providers. This includes the National Computing Center, sectoral centers, licensed Internet Service Providers (ISPs), and authorized telecommunications operators.
- Secure Protocols: Public websites are required to use the HTTPS protocol with SSL/TLS certificates that are regularly renewed.
- Multi-Factor Authentication (MFA): MFA will be mandatory for all users accessing public administrative systems.
- Pre-Launch Security Audits: Before going live, websites must undergo a security audit conducted by an ANSI-accredited provider. This audit must be renewed at least annually.
- DDoS Protection: The use of solutions to protect against Distributed Denial of Service (DDoS) attacks is strongly recommended.
Regulations for Professional Messaging
The circular also establishes guidelines for the use of professional email services:
- Official communications must be conducted via email addresses ending in the “.tn” domain.
- Unused accounts must be deactivated.
- All login activities must be logged and monitored.
Economic Implications for the Tunisian Cybersecurity Sector
This new regulatory framework is expected to create significant opportunities for Tunisian companies specializing in cybersecurity. Demand is likely to rise in areas such as:
- IT security audits
- DDoS attack mitigation services
- Training programs for information security officers
These measures signal a broader commitment by the Tunisian government to enhance the resilience and security of its digital infrastructure.