< Back to all clusters
[TECHNOLOGY] · Tunisia · 2 sources

started · updated

Tunisia mandates new cybersecurity protocols for public institutions

Tunisian government head Sarra Zaafrani Zenzri has issued a circular to strengthen the cybersecurity of public institutions in response to increasing cyber threats. The directive, dated September 2, 2026, imposes strict new obligations on ministers, state secretaries, governors, and heads of public enterprises.

Key technical requirements include the mandatory use of HTTPS protocols and multi-factor authentication (MFA) for all users and administrators. Digital services and websites must be hosted exclusively by the National Center for Informatics, sectoral public centers, or approved telecommunications operators. Additionally, systems must undergo a full annual audit by agencies certified by the National Cybersecurity Agency before any major version updates.

To secure official communications, the circular prohibits the use of social media and mobile messaging applications for transmitting administrative documents. All official correspondence must now use the national ‘.tn’ email domain. Administrative bodies are also required to maintain updated account databases, ensuring the immediate deactivation of accounts for inactive users or departed staff.

Entities

National Center for Informatics · National Cybersecurity Agency · Sarra Zaâfrani Zenzri