Cybersecurity

The Enterprise Guide to CNDP Law 09-08 & DGSSI Security Compliance in Morocco

Rising Group
Published on August 6, 2026

Understanding Data Protection & Governance in Morocco

As digital transformation accelerates across North Africa, corporate data protection has shifted from an operational luxury to a strict legal necessity. In Morocco, two primary frameworks govern enterprise information security: Loi 09-08 (administered by the CNDP) and security directives enforced by the DGSSI.

Key Pillars of CNDP Law 09-08

Under Moroccan law, any business processing personal data belonging to Moroccan citizens or employees must comply with strict data collection, storage, and processing rules:

  • Article 23 (Data Encryption & In-Transit Security): Requires mandatory 256-bit SSL/TLS encryption for all web applications.
  • Article 52 (Cross-Border Data Transfer Restrictions): Prohibits transferring personal data outside Moroccan territory without prior explicit CNDP authorization.

DGSSI Directives for Critical Infrastructure

For financial institutions, telecom operators, and government contractors, DGSSI security guidelines mandate regular Offensive Penetration Testing, zero-trust network segmentation, and automated log auditing.

Share This Article
Spread the knowledge across your network