Security audits, penetration testing, and security advisory for organizations operating in the Democratic Republic of Congo, with a pragmatic approach grounded in international best practices and the principles of the Malabo Convention.
Last updated — August 22, 2026
The regulatory framework for cybersecurity and data protection in the Democratic Republic of Congo (DRC) is evolving under the coordination of the relevant national authorities. The DRC is part of the continental baseline set by the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention). EBH Security supports organizations operating in the DRC by applying the principles of the Malabo Convention and recognized international standards (ISO/IEC 27001, NIST), while staying closely aligned with the evolving national framework and applicable local sector requirements.
Engagement mode
On-site missions in Kinshasa, remote delivery for the rest of the territory
Working language
French
The national framework continues to evolve under the relevant authorities. We closely track this evolution and support organizations based on international best practices and the principles of the Malabo Convention.
The African Union Convention on Cyber Security and Personal Data Protection, which establishes a continental baseline of shared principles across several African states, including the DRC.
We recommend recognized international standards such as ISO/IEC 27001 and NIST, adapted to the organization's context and sector.
Yes, this sector is a priority given its economic criticality and growing exposure to cyber risk.
Yes, an audit objectively documents the state of your security controls and reduces your risk exposure regardless of the local regulatory framework's maturity.
Yes, technical engagements can be delivered remotely, with on-site visits arranged based on needs and site accessibility.