Data leak, intrusion, or suspected security incident? Report a security incident immediately.

Report security incident
EBH Security

Regulation

DGSSI and law 09-08: what every Moroccan business should know

EBH Security TeamJune 20, 20265 min read

DGSSI, Morocco's national cybersecurity authority

The Direction Générale de la Sécurité des Systèmes d'Information (DGSSI) is Morocco's authority in charge of information systems security, attached to the national defense administration. Its historical role first concerned public administrations and so-called sensitive infrastructure, before gradually extending to a reference role for the entire Moroccan ecosystem, including private companies that want to structure their security around a recognized framework. DGSSI publishes directives, reference frameworks and technical recommendations that form the basis of many security audits conducted in Morocco, whether organizational audits, penetration tests or configuration reviews. For a business, understanding DGSSI's role means understanding that there is a national reference authority in cybersecurity, whose principles shape much of the regulatory expectations and good practices expected in Morocco, even outside strictly regulated sectors. Many Moroccan security providers actually build their audit methodologies around these frameworks, which makes them a common language between companies, advisory firms and oversight authorities. A business preparing a compliance file or responding to a demanding tender has every interest in becoming familiar with this framework, even at a basic level, rather than discovering it only when a client or partner explicitly asks about it.

Law 09-08 and the protection of personal data

Law 09-08 is the Moroccan text governing the processing of personal data. It imposes now-classic principles of data protection: informing data subjects that their data is being collected, limiting collection to what is necessary, securing data against unauthorized access, and granting certain rights to individuals over their own information. Enforcement of this law falls under the CNDP (Commission Nationale de contrôle de la protection des Données à caractère Personnel), which notably receives declarations of data processing. For a Moroccan business collecting customer, employee or prospect data — which applies to virtually every organization — law 09-08 is not a theoretical text: it is a framework that must translate concretely into how data is stored, secured and shared. This applies just as much to data stored on internal servers as to data entrusted to external providers or hosted in the cloud: the responsibility for protecting data does not disappear simply because its processing is outsourced to a third party. A business remains accountable for how the data it collects is actually protected, regardless of where it transits or is kept.

What a business must concretely put in place

Beyond the legal text, DGSSI/CNDP compliance translates into very concrete measures. Mapping the personal data processed (HR, customers, prospects) and knowing precisely where it is stored, on which systems and through which providers if any. Putting in place proportionate security measures: access control, regular backups, encryption of the most sensitive data, logging access to the systems that host it. Documenting data processing activities and, where applicable, making the expected declarations to the CNDP. Raising awareness among teams who handle personal data or sensitive systems, since a large share of data-related security incidents stem from human error rather than sophisticated attacks. These elements are not solely a legal department matter: they directly involve IT, security and the internal organization as a whole, which is why an effective compliance approach generally requires coordination across several functions rather than isolated work.

Where to start without a dedicated security team

Many Moroccan SMEs have no CISO or internal compliance team. That does not exempt them from obligations, but it does mean priorities must be set intelligently rather than aiming for immediate completeness. A good starting point is to conduct a gap analysis to identify the difference between the current situation and regulatory expectations, then build a realistic roadmap rather than trying to fix everything at once. This roadmap should distinguish what is urgent (for example, unsecured access to sensitive data) from what can be addressed over several months (for example, fully formalizing internal policies). External support — audit, compliance advisory — often allows faster progress than attempting to manage everything internally without dedicated expertise available day to day, mainly because an outside perspective more easily spots blind spots that an internal team, absorbed in day-to-day operations, does not always see.

The most common mistakes

Three mistakes come up regularly among Moroccan businesses approaching this topic for the first time. Assuming compliance only concerns large companies or regulated sectors (banking, healthcare) — when the principles of law 09-08 apply as soon as personal data is processed, regardless of the organization's size or sector of activity. Treating compliance as a one-off project rather than an ongoing process: frameworks evolve, and so does the organization, whether through workforce growth, new tools, or a changing business activity. Focusing only on the documentation side (policies, charters) without implementing the corresponding technical measures, which leaves a gap between what is written on paper and what is actually applied day to day — a gap that becomes particularly visible during a security incident or an external audit.

FAQ

Frequently asked questions on this topic

Yes, in principle: as soon as an organization collects or processes personal data (employees, customers, prospects), the principles of law 09-08 apply. The precise level of obligations can vary depending on the nature of the data processed.

Next step

A question about your specific context?

Let's discuss your challenges and the security scope that makes sense for your company.