Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity and Compliance in Morocco

Security audits, penetration testing, and managed security monitoring for organizations operating in Morocco, delivered by a Moroccan firm with deep command of the DGSSI, CNDP, Bank Al-Maghrib, and ACAPS regulatory framework.

Last updatedAugust 22, 2026

The local regulatory framework

Morocco's cybersecurity framework rests on Law No. 05-20 on the cybersecurity of information systems, its implementing decree No. 2-21-406, and the National Directive on Information Systems Security (DNSSI), overseen by the Directorate General for Information Systems Security (DGSSI). Personal data protection falls under Law No. 09-08, supervised by the National Commission for the Control of Personal Data Protection (CNDP). Banking and financial institutions are further subject to Bank Al-Maghrib's directive on information systems security, while the insurance and social welfare sector falls under the requirements of the Insurance and Social Welfare Supervisory Authority (ACAPS). Based in Morocco, EBH Security supports organizations through every stage of adapting to this regulatory framework.

Concrete obligations

Compliance with Law No. 05-20 on information systems cybersecurity and its implementing decree No. 2-21-406 for critical infrastructure

Application of the National Directive on Information Systems Security (DNSSI) for government bodies, public institutions, and critical infrastructure operators

Declaration and protection of personal data processing in accordance with Law No. 09-08, under CNDP oversight

Compliance with Bank Al-Maghrib's directive on information systems security for banking and payment institutions

Compliance with ACAPS information systems security requirements for insurance companies and social welfare bodies

Priority sectors

Banking and financePublic sectorIndustry

Delivery modalities

Engagement mode

On-site missions in Casablanca, Rabat, and throughout the Kingdom, plus remote delivery

Working language

Arabic, French, and English

Local presence

Firm based in Morocco, with direct command of the national regulatory framework (DGSSI, CNDP, BAM, ACAPS)

Local FAQ

Which authority oversees cybersecurity in Morocco?

The Directorate General for Information Systems Security (DGSSI), which administers Law No. 05-20, its implementing decree No. 2-21-406, and the National Directive on Information Systems Security (DNSSI).

Is EBH Security PASSI qualified?

Our team includes an auditor who holds a PASSI auditor certificate issued under the DGSSI framework, and our audit methodologies are aligned with the requirements framework for PASSI qualification (V2.1).

Which authority oversees personal data protection in Morocco?

The National Commission for the Control of Personal Data Protection (CNDP), which enforces Law No. 09-08.

Are our banking systems subject to specific requirements?

Yes, banking and payment institutions must comply with Bank Al-Maghrib's directive on information systems security.

Does the insurance sector have a dedicated framework?

Yes, ACAPS sets information systems security requirements specific to insurance companies and social welfare bodies.

Do you operate across the whole of Morocco?

Yes, our engagements cover Casablanca, Rabat, and the entire Kingdom, delivered on-site or remotely depending on the mission.

Do you work with the public sector and critical infrastructure operators?

Yes, our services are designed to meet DNSSI requirements applicable to government bodies, public institutions, and critical infrastructure.

Which sectors carry the highest cyber risk in Morocco?

Banking and finance, the public sector, and industry are among the most exposed sectors, given their advanced digitalization and the sensitivity of the data and systems they operate.

Get in touch