The Legal Framework for Cybersecurity in Tunisia in 2025

Digital law and new technologies

The Tunisian legal framework for cybersecurity has been built up in successive stages since 2022, combining a repressive component, national governance and international harmonisation. Here is an overview of the main texts in force or under discussion.

Decree-Law No. 2022-54 of 13 September 2022: cybercrime

This criminal-law text governs offences committed by means of information systems. Its Article 24 criminalises the dissemination, over a computer network, of data, rumours or falsified documents likely to harm public safety, national defence or the rights of others. The penalties go up to five years’ imprisonment and a fine of 50,000 dinars, doubled where the victim is a public official or a person vested with public authority. The text applies to any natural or legal person, including journalists and economic and political actors.

Decree-Law No. 2023-17 of 11 March 2023: creation of the ANCS

This text creates the National Cybersecurity Agency (ANCS), which replaces the National Agency for Computer Security (ANSI). Its main missions are the development and implementation of the national cybersecurity strategy, the coordination of CERTs (computer emergency response teams), the security audit of public and private information systems, and the monitoring of incident management and the development of national standards. The ANCS has competence over public entities, operators of vital importance and operators of essential services, and has powers of inspection, compliance monitoring, mandatory recommendations and the prescription of corrective measures. This text strengthens the centralisation of cyber governance and provides a legal basis for binding controls.

Organic Law No. 2024-9 of 6 February 2024: accession to the Budapest Convention

By this law, Tunisia ratifies the Council of Europe Convention on Cybercrime (Budapest, 2001), the first binding international instrument in this field. Its objectives are to harmonise cybercrime offences, to facilitate international judicial and police cooperation, and to define common procedures for the collection and preservation of electronic evidence. This accession entails the obligation to adapt domestic law to European standards, facilitates mutual legal assistance with the other States Parties, and allows participation in the cooperation mechanisms of the Council of Europe, in particular the network of contact points available 24 hours a day, 7 days a week.

Bill No. 2024/036: security of public information systems

This bill aims to establish a unified legislative framework to secure public information systems and protect strategic data, with the creation of a national regulatory authority with binding powers. It provides for obligations for public entities and operators of vital importance and critical infrastructure: regular security audits, business continuity and disaster recovery plans, an obligation to notify incidents within a legally set deadline, and respect for digital sovereignty with hosting of critical data in Tunisia. A regime of administrative and financial sanctions, graduated according to the seriousness of the breach, is provided for.

Summary table

Text Subject Status Main scope
Decree-Law 2022-54 Cybercrime In force Criminal and repressive dimension
Decree-Law 2023-17 Cybersecurity and ANCS In force National governance and oversight
Organic Law 2024-9 Budapest Convention Promulgated International harmonisation
Bill 2024/036 Cybersecurity governance Under discussion Regulation of public information systems

The cyber landscape in Tunisia: some figures (2024)

More than 23 million threats were detected and blocked by the national technical monitoring tools in 2024, including 617,779 successful intrusion attempts, 279,026 backdoor detections and 148,130 password theft incidents. Ransomware rose by 140% compared with 2023 (37,076 incidents against 15,411), with financial institutions, telecom operators and public administrations remaining the priority targets.

The firm supports companies and institutions in analysing their obligations under this legal framework, which is still taking shape, in coordination with the competent technical providers. For any question, contact the firm.

References

Further reading

Related articles