Security audits, penetration testing, and security oversight for organizations operating in Mauritania, grounded in international best practices and the principles of the Malabo Convention.
Last updated — August 22, 2026
In Mauritania, the regulation of telecommunications and information technologies falls under the Autorité de Régulation (ANRPTS), within a context where the national cybersecurity landscape is developing in step with the regional momentum driven by the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention). EBH Security supports Mauritanian organizations by applying recognized international frameworks (ISO/IEC 27001, NIST recommendations) and maintaining continuous monitoring of guidance issued by ANRPTS and regional bodies, so that clients' security posture remains aligned with best-in-class standards as the national regulatory landscape continues to mature.
Engagement mode
On-site missions in Nouakchott and remote delivery for the rest of the territory
Working language
French and Arabic, with deliverables available in English on request
Methodological approach
Application of international frameworks (ISO/IEC 27001, NIST) and the principles of the Malabo Convention
Our engagements draw on recognized international frameworks, including ISO/IEC 27001 and NIST recommendations, as well as the principles of the Malabo Convention on cybersecurity and personal data protection.
The Autorité de Régulation oversees the telecommunications and information technology sector in Mauritania; we maintain continuous monitoring of its guidance to keep our services aligned with the national context.
It is the African Union Convention on Cyber Security and Personal Data Protection, which sets out regional reference principles for digital security and data protection; we incorporate its guidance into our engagement methodologies.
Yes, our engagements are scoped to the size, sector, and digital maturity of each organization, whether a one-off audit or ongoing support through an outsourced CISO model.
Both. Technical audits and penetration tests can be delivered remotely, with on-site missions for phases requiring physical access.
The banking and financial sector, telecommunications, and the public sector are among those where securing information systems is a priority concern.