Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity and Compliance in Tunisia

Mandatory periodic audits, penetration testing, and managed security monitoring for organizations operating in Tunisia, aligned with the regulatory framework overseen by ANSI and INPDP.

Last updatedAugust 22, 2026

The local regulatory framework

Information security in Tunisia is governed by Law No. 2004-5 of 3 February 2004, which established the National Agency for Computer Security (ANSI) and requires mandatory periodic audits of information systems for public bodies and certain categories of private companies. Personal data protection falls under Organic Law No. 2004-63, overseen by the National Authority for the Protection of Personal Data (INPDP). This dual framework places security auditing at the core of compliance obligations for Tunisian organizations.

Concrete obligations

Completion of a mandatory periodic information systems audit under Law No. 2004-5, carried out by qualified professionals

Implementation of technical and corrective recommendations issued by ANSI following audits

Declaration of personal data processing to INPDP in accordance with Organic Law No. 2004-63

Implementation of proportionate security measures for the protection of personal data

Notification of information security incidents to the competent authorities

Priority sectors

Banking and financial servicesTelecommunicationsPublic sector

Delivery modalities

Engagement mode

On-site missions in Tunis and remote delivery for the rest of the territory

Working language

French and Arabic, with deliverables available in English on request

Regulatory coordination

Support in preparing for the mandatory periodic audit required by ANSI

Local FAQ

What is the mandatory periodic audit required under Law No. 2004-5?

A legal requirement for public bodies and certain private companies to have their information systems periodically audited, under ANSI oversight.

Which organizations are subject to this obligation?

Law No. 2004-5 targets public bodies as well as private companies operating telecommunications networks or processing sensitive data, according to categories set out in the implementing texts.

How often must these audits be carried out?

The periodic audit must be performed at intervals set by the applicable regulation; we help organizations plan and meet these deadlines.

Which authority oversees personal data protection in Tunisia?

The National Authority for the Protection of Personal Data (INPDP), which enforces Organic Law No. 2004-63.

Are your audit reports recognized by ANSI?

Our audits follow rigorous methodologies designed to meet the substantive requirements of Tunisian regulation; formal recognition of the report ultimately rests with ANSI's assessment.

Do you work remotely or only on site?

Both. Technical phases can be delivered remotely, with on-site missions for work requiring physical access to infrastructure.

Which sectors are most affected by these obligations in Tunisia?

Banking and financial services, telecommunications, and the public sector are among the sectors most exposed to these audit and compliance obligations.

Get in touch