Senegal's National Assembly unanimously adopted Bill No. 25/2026 on the protection of critical information infrastructures (CII) and digital security on August 20, 2026, with 127 votes in favour and none against. The text sets security standards for the State, private organisations and individuals, places CII operators under specific duties supervised by the competent administrative authorities and the National Cybersecurity Authority, and creates administrative and criminal sanctions for non-compliance. The official account is on the National Assembly release of August 20, 2026.

The vote closes an extraordinary session opened on August 10, 2026. The bill still needs presidential promulgation and publication in the Journal Officiel before it binds operators; no entry-into-force date was announced at adoption. For banks, telecoms, utilities, hospitals, state digital infrastructure and cybersecurity vendors selling into Senegal, the practical clock starts now: map likely CII exposure, inventory systems that support activities on Senegalese territory, and prepare for designation and security-norm obligations once the implementing layer lands.

What did the National Assembly actually adopt on August 20, 2026?

Bill No. 25/2026 is a voted statute (loi), not a soft strategy paper. It builds a reference framework for information-system security, defines the norms and standards applicable to the State, private organisations and individuals, and subjects CII operators to specific obligations under administrative oversight and the National Cybersecurity Authority. It also sets rules for the supply of cybersecurity products and services, and attaches an administrative and criminal sanction regime so those duties are enforceable.

The Assembly's framing is strategic: rising cyber threats, more sophisticated attacks, and deeper dependence on digital infrastructure. The purpose is to preserve Senegal's overall security, protect sovereign interests, and strengthen the State's capacity to anticipate, prevent and respond to digital threats. For compliance teams, the novelty is clear: Senegal is moving from fragmented cybercrime and digital-economy rules toward an explicit CII statute with a dedicated national authority and a dual administrative-penal stick.

Who is in scope, including from outside Senegal?

The law covers networks and information systems that support activities carried out in Senegal and that are wholly or partly established on national territory. That catches classic on-soil CII operators: telecom networks, banking and payment rails, energy and water control systems, hospital clinical systems, and government digital platforms such as those run through ADIE and related state digital infrastructure.

Scope can also extend to certain digital services provided to Senegal through equipment located abroad. Those situations will be framed by regulation or international cooperation agreements; foreign cloud, SaaS and managed-security providers that deliver into Senegal should treat extraterritorial reach as a live design question, not a remote risk. Where network operation is already governed by an international agreement, the law applies only to the extent that agreement allows, so treaty-bound systems need a carve-out analysis rather than a blanket assumption of coverage.

ActorImmediate exposure under Bill No. 25/2026
On-territory CII operators (banks, telecoms, utilities, hospitals, state digital infra)CII designation risk; security norms; oversight by administrative authorities and the National Cybersecurity Authority; administrative and criminal sanctions
Cybersecurity product and service providers selling into SenegalDedicated supply rules for cybersecurity products and services; compliance and sanction exposure
Foreign digital-service providers using equipment abroadPossible extraterritorial extension via future regulation or cooperation agreements
Operators under international agreementsApplication only to the extent the agreement permits

What must compliance teams do before promulgation?

Promulgation and Journal Officiel publication are still outstanding, and no implementing decree calendar was published with the vote. Waiting for the JO text is not a plan. Operators should stand up an applicability file now: list systems that support activities in Senegal, flag those wholly or partly established on national territory, and identify services delivered into Senegal from abroad that could fall under the extraterritorial clause once regulated.

Governance should name a single owner for National Cybersecurity Authority engagement, align security-control baselines with the forthcoming norms, and stress-test incident and vulnerability processes against a dual administrative and criminal enforcement model. Vendors of cybersecurity products and services should map contractual warranties and localisation claims to the new supply rules. Continuous, per-jurisdiction regulatory monitoring is how teams catch the promulgation notice, the JO publication and the first implementing decrees the day they appear, rather than weeks later through secondary press.

How does this sit next to Senegal's existing digital statutes?

Senegal already runs a layered digital stack: Loi 2008-11 on cybercrime, Loi 2008-12 on personal data (CDP), and the Code du Numérique (Loi 2023-13) on electronic commerce, signatures and intermediary liability. Bill No. 25/2026 does not repeal those instruments; it adds a CII-centred security and resilience layer with a National Cybersecurity Authority and operator duties that those earlier laws did not organise as a critical-infrastructure regime. Teams should keep the cybercrime, data-protection and digital-code workstreams, and open a parallel CII track rather than folding this vote into an existing GDPR-style or e-commerce control set.

Take advantage of this real-time watch

Senegal: personal data protection reform and AI governance frameworkLive
Monitor Senegal's digital-governance legislative pipeline for the AI, data and digital-governance industry, jurisdiction Senegal.
Hourly Email 10+ news
This live monitoring job detected the news you are reading.
Activate this watch free now

Confirm whether any of your networks or services support activities in Senegal or sit partly on Senegalese territory, open an applicability and designation file before the JO text lands, brief legal, CISO and vendor-management teams on the National Cybersecurity Authority oversight model and the dual sanction regime, and watch for presidential promulgation plus the first implementing regulations on extraterritorial digital services. Obsidian surfaces this class of national CII statute the moment the legislator and the Journal Officiel publish the next step.