Security audits, penetration testing, and managed security monitoring for organizations operating in Morocco, delivered by a Moroccan firm with deep command of the DGSSI, CNDP, Bank Al-Maghrib, and ACAPS regulatory framework.
Last updated — August 22, 2026
Morocco's cybersecurity framework rests on Law No. 05-20 on the cybersecurity of information systems, its implementing decree No. 2-21-406, and the National Directive on Information Systems Security (DNSSI), overseen by the Directorate General for Information Systems Security (DGSSI). Personal data protection falls under Law No. 09-08, supervised by the National Commission for the Control of Personal Data Protection (CNDP). Banking and financial institutions are further subject to Bank Al-Maghrib's directive on information systems security, while the insurance and social welfare sector falls under the requirements of the Insurance and Social Welfare Supervisory Authority (ACAPS). Based in Morocco, EBH Security supports organizations through every stage of adapting to this regulatory framework.
Engagement mode
On-site missions in Casablanca, Rabat, and throughout the Kingdom, plus remote delivery
Working language
Arabic, French, and English
Local presence
Firm based in Morocco, with direct command of the national regulatory framework (DGSSI, CNDP, BAM, ACAPS)
The Directorate General for Information Systems Security (DGSSI), which administers Law No. 05-20, its implementing decree No. 2-21-406, and the National Directive on Information Systems Security (DNSSI).
Our team includes an auditor who holds a PASSI auditor certificate issued under the DGSSI framework, and our audit methodologies are aligned with the requirements framework for PASSI qualification (V2.1).
The National Commission for the Control of Personal Data Protection (CNDP), which enforces Law No. 09-08.
Yes, banking and payment institutions must comply with Bank Al-Maghrib's directive on information systems security.
Yes, ACAPS sets information systems security requirements specific to insurance companies and social welfare bodies.
Yes, our engagements cover Casablanca, Rabat, and the entire Kingdom, delivered on-site or remotely depending on the mission.
Yes, our services are designed to meet DNSSI requirements applicable to government bodies, public institutions, and critical infrastructure.
Banking and finance, the public sector, and industry are among the most exposed sectors, given their advanced digitalization and the sensitivity of the data and systems they operate.