Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity and Compliance in the Democratic Republic of Congo

Security audits, penetration testing, and security advisory for organizations operating in the Democratic Republic of Congo, with a pragmatic approach grounded in international best practices and the principles of the Malabo Convention.

Last updatedAugust 22, 2026

The local regulatory framework

The regulatory framework for cybersecurity and data protection in the Democratic Republic of Congo (DRC) is evolving under the coordination of the relevant national authorities. The DRC is part of the continental baseline set by the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention). EBH Security supports organizations operating in the DRC by applying the principles of the Malabo Convention and recognized international standards (ISO/IEC 27001, NIST), while staying closely aligned with the evolving national framework and applicable local sector requirements.

Concrete obligations

Monitoring guidance issued by the relevant national authorities on digital security

Adopting security best practices aligned with the principles of the Malabo Convention

Implementing risk-proportionate security measures, aligned with recognized international standards and the principles of the Malabo Convention

Priority sectors

Mining and natural resourcesFinancial servicesPublic sector and government

Delivery modalities

Engagement mode

On-site missions in Kinshasa, remote delivery for the rest of the territory

Working language

French

Local FAQ

Does the DRC have a dedicated cybersecurity law?

The national framework continues to evolve under the relevant authorities. We closely track this evolution and support organizations based on international best practices and the principles of the Malabo Convention.

What is the Malabo Convention?

The African Union Convention on Cyber Security and Personal Data Protection, which establishes a continental baseline of shared principles across several African states, including the DRC.

What international standards do you rely on to support engagements locally?

We recommend recognized international standards such as ISO/IEC 27001 and NIST, adapted to the organization's context and sector.

Do you work with the DRC's mining sector?

Yes, this sector is a priority given its economic criticality and growing exposure to cyber risk.

What value does an EBH Security audit bring in this context?

Yes, an audit objectively documents the state of your security controls and reduces your risk exposure regardless of the local regulatory framework's maturity.

Do you operate outside Kinshasa?

Yes, technical engagements can be delivered remotely, with on-site visits arranged based on needs and site accessibility.

Get in touch