Morocco's cybersecurity legal framework, setting security obligations for critical infrastructure operators and public administration information systems.
Last updated — August 22, 2026
Critical infrastructure operators (IIV) designated by the competent authority, as well as public administrations and their information systems. Providers and subcontractors working on these systems are indirectly concerned, through contractual pass-down.
Law 05-20 and its implementing decree 2-21-406 require the implementation of security measures, the performance of security audits, and compliance with the rules set out in the National Directive on Information Systems Security (DNSSI). DGSSI oversees and controls the application of this framework among the entities concerned.
Deadlines
Compliance timelines — audit frequency, remediation deadlines — are set by the competent authority based on the nature of the entity and the criticality of the information system concerned. They are not uniform across all critical infrastructure operators and must be verified on a case-by-case basis.
Sanctions
The legal and regulatory framework provides for a sanctions regime in the event of non-compliance with security obligations. Their nature and amount are set by the applicable texts and assessed by the competent authority according to the severity of the breach.
Determine the entity's status under Law 05-20 (critical infrastructure operator, administration, provider)
Perform a gap analysis against DNSSI requirements
Implement the required security measures
Have a security audit performed by a qualified provider
Track and remediate the gaps identified
| Framework | Covered |
|---|---|
| passi-maroc | ✓ |
| iso-27001 | ✓ |
Get the checklist by email.
Primarily designated critical infrastructure operators and public administrations. Providers working on these entities' systems are indirectly concerned.
The National Directive on Information Systems Security sets the security rules applicable under Law 05-20 and its implementing decree.
The General Directorate for Information Systems Security oversees the application of the legal framework, controls its implementation, and qualifies security audit providers.
Direct application targets designated entities and administrations. A non-designated company can still be indirectly concerned if it is a supplier or subcontractor to a regulated entity.
Using a PASSI-qualified provider is the reference for audits performed under this regulatory framework; the exact conditions depend on the type of engagement and the entity concerned.