Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Law 05-20 & DGSSI

Morocco's cybersecurity legal framework, setting security obligations for critical infrastructure operators and public administration information systems.

Last updatedAugust 22, 2026

Who's affected

Critical infrastructure operators (IIV) designated by the competent authority, as well as public administrations and their information systems. Providers and subcontractors working on these systems are indirectly concerned, through contractual pass-down.

What the framework requires

Law 05-20 and its implementing decree 2-21-406 require the implementation of security measures, the performance of security audits, and compliance with the rules set out in the National Directive on Information Systems Security (DNSSI). DGSSI oversees and controls the application of this framework among the entities concerned.

Compliance steps

01

Determine the entity's status under Law 05-20 (critical infrastructure operator, administration, provider)

02

Perform a gap analysis against DNSSI requirements

03

Implement the required security measures

04

Have a security audit performed by a qualified provider

05

Track and remediate the gaps identified

Common mistakes

  • Assuming Law 05-20 only applies to large administrations
  • Treating DNSSI requirements as an optional recommendation
  • Delaying the security audit pending formal designation as a critical infrastructure operator

Cross-mapping to other frameworks (UCM)

FrameworkCovered
passi-maroc
iso-27001

Downloadable resource

Get the checklist by email.

Frequently asked questions

Who is subject to Law 05-20?

Primarily designated critical infrastructure operators and public administrations. Providers working on these entities' systems are indirectly concerned.

What is DNSSI?

The National Directive on Information Systems Security sets the security rules applicable under Law 05-20 and its implementing decree.

What is the role of DGSSI?

The General Directorate for Information Systems Security oversees the application of the legal framework, controls its implementation, and qualifies security audit providers.

Does Law 05-20 apply to private companies not designated as critical infrastructure operators?

Direct application targets designated entities and administrations. A non-designated company can still be indirectly concerned if it is a supplier or subcontractor to a regulated entity.

Does the audit required under Law 05-20 require a PASSI-qualified provider?

Using a PASSI-qualified provider is the reference for audits performed under this regulatory framework; the exact conditions depend on the type of engagement and the entity concerned.