DGSSI Compliance Morocco 2026: Am I Affected? Law 05-20 & DNSSI
Are you an OIV, public body or IT provider? Check your DGSSI obligations (Law 05-20, DNSSI directive) in 5 minutes with our free self-assessment. Sanctions, security audit requirements and your 2026 action plan.
DGSSI at a glance. The Direction Générale de la Sécurité des Systèmes d'Information (DGSSI) is Morocco's national cybersecurity authority, created in 2011 under the National Defense Administration. It enforces Law 05-20 and the DNSSI directive, which impose security obligations on public administrations, public institutions, and operators of vital infrastructure (OIV). This guide covers who is subject to it, the exact obligations, the sanctions, and the practical steps to compliance in 2026.
What DGSSI Expects from Your Organization in 2026
Since 2020, Morocco has had a cybersecurity law (Law 05-20) and a national implementing directive that binds public administrations, public institutions, and operators of vital infrastructure. Yet many executives and IT directors still do not know precisely what this means for their organization.
This guide answers three concrete questions: are you subject to DGSSI compliance in Morocco? If so, what exactly are your obligations? And how do you meet them in a structured, auditable way?
It draws on official texts published by the DGSSI, the implementing decree no. 2-21-406, and the updated DNSSI (National Information Systems Security Directive) issued in January 2023.
DGSSI: Role, Structure and Authority
The General Directorate of Information Systems Security (DGSSI in French / Direction Générale de la Sécurité des Systèmes d'Information) was created by decree no. 2-11-509 of September 21, 2011. It operates under the National Defense Administration and is the competent national authority for cybersecurity in Morocco.
Its remit covers four broad domains:
- Threat intelligence and incident response: through the maCERT (Moroccan Computer Emergency Response Team), the monitoring center that detects cyberattacks, issues alerts, and coordinates responses to incidents affecting the State's information systems.
- Standards and audit: DGSSI formulates technical recommendations, publishes security frameworks, and conducts audits of information systems in public administrations and bodies.
- Legal framework and regulation: it proposes draft laws and regulations on information systems security, and manages declarations and authorizations for regulated cryptographic products.
- Development of secure solutions: it develops and provides security tools to public administrations.
maCERT in Numbers
The maCERT handles an average of more than 800 cybersecurity incidents per year according to its annual reports, a figure that has risen steadily since 2019. In 2023 alone, it issued nearly 400 security alerts to public and private actors. Incident reports can be sent directly to [email protected].
Law 05-20 on Cybersecurity: The Reference Framework
Promulgated by dahir no. 1-20-69 of July 25, 2020, Law 05-20 on cybersecurity is the foundational text of Morocco's framework. It was complemented by implementing decree no. 2-21-406 of July 15, 2021.
Scope of Application
The law applies to three categories of actors:
1. Public entities State administrations, local authorities, public institutions, and public-law legal entities.
2. Vital Infrastructure (OIV / Opérateurs d'Importance Vitale) Any installation, structure, or system indispensable to maintaining society's vital functions: health, security, supply, economy. The precise list of sectors is set by regulation and kept confidential, but according to available information includes energy, telecommunications, finance, healthcare, transport, water, and public security.
3. Private-sector operators Public telecommunications network operators, internet service providers, cybersecurity service providers, digital service providers, and editors of internet platforms.
200K MAD
Max fine (Article 50)
7
Identified OIV sectors
800+
maCERT incidents/year
5 years
Max imprisonment (Law 05-20)
Main Obligations Under Law 05-20
| Obligation | Affected entities | Description |
|---|---|---|
| Security policy | All | Establish and implement a documented information security policy |
| Asset classification | All | Classify information by sensitivity level |
| Designation of a CISO | All | Appoint an information security officer with functional independence |
| Periodic audit | OIVs and sensitive systems | Have systems audited by qualified PASSI providers |
| Incident reporting | All | Notify any incident affecting information systems to the national authority without delay |
| Business continuity plan | All | Establish and regularly test a continuity and recovery plan |
| System homologation | OIV | Obtain homologation before deploying any sensitive information system |
| Sensitive data hosting | All | Host sensitive data exclusively on national territory |
Sanctions
The law provides significant penalties for non-compliance:
- 2 to 5 years of imprisonment and a 100,000 MAD fine for violations resulting in data modification or deletion, or alteration of system operation.
- Fines from 100,000 to 200,000 MAD (Article 50) for telecommunications operators, ISPs, cybersecurity providers, and digital platform editors that fail to meet their legal obligations.
These penalties apply without prejudice to provisions of the Moroccan Criminal Code on information offenses.
DNSSI: The Operational Directive
The National Information Systems Security Directive (DNSSI / Directive Nationale de la Sécurité des Systèmes d'Information) translates Law 05-20's legal requirements into concrete technical and organizational measures. The first version dates from 2014 (Head of Government circular no. 3/2014). The version currently in force was published by circular no. 2/2023 of January 12, 2023.
Who Is Subject to the DNSSI?
The DNSSI applies to all of the following entities:
- State administrations
- Local authorities
- Public institutions and public enterprises
- Public-law legal entities
- Vital infrastructure, whether public or private
Affected entities had six months from the publication of the January 2023 circular to establish a roadmap for implementing the required measures.
The A, B, C Classification System
The DNSSI introduces an information system classification scheme on three sensitivity levels, defined jointly between the entity and the DGSSI:
| Class | Sensitivity level | Implications |
|---|---|---|
| Class A | Highly sensitive | Maximum security measures, mandatory homologation before deployment, regular audits by qualified PASSI |
| Class B | Sensitive | Strengthened measures, periodic audits, mandatory incident reporting |
| Class C | Standard | Baseline measures, security policy, staff training |
Classification determines the intensity of measures to put in place and the frequency of mandatory audits. OIVs operating Class A or Class B systems are subject to the most stringent requirements.
Domains Covered by the DNSSI
The directive covers several security domains, drawn from international best practice and the Moroccan standard NM ISO/IEC 27002:
- Security policy: formalization, validation, and dissemination of an information security policy across the organization
- Security organization: definition of roles, responsibilities, and security governance structures
- Asset management: inventory, classification, and accountability of information assets
- Human resources security: awareness, training, and offboarding procedures
- Physical and environmental security: protection of premises, equipment, and media
- Operations and communications management: operating procedures, network access control, malware management
- Access control: identity, rights, and authentication management
- Acquisition, development, and maintenance: security in projects and the application lifecycle
- Incident management: detection, response, and reporting of security incidents
- Business continuity: regularly tested business continuity and disaster recovery plans
- Compliance: meeting legal, regulatory, and contractual requirements
PASSI: The DGSSI-Qualified Auditors
A central concept for OIVs and entities operating sensitive information systems: security audits must be conducted by PASSI providers (Information Systems Security Audit Providers / Prestataires d'Audit de la Sécurité des Systèmes d'Information) qualified by the DGSSI.
PASSI qualification is not a simple administrative accreditation. It requires that:
- The provider covers at least three audit domains: organizational and physical audit, architecture audit, configuration audit, penetration testing, source code audit, or industrial systems audit.
- For Class A engagements, the provider's share capital must be majority-owned by Moroccan nationals, and auditors must hold Moroccan citizenship.
- The organizational structure must be exclusively dedicated to information systems security audit.
This system ensures that organizations subject to mandatory audits use providers whose competence has been verified by the national authority. For entities not directly subject to PASSI requirements, using a qualified provider remains a best practice that reinforces audit credibility.
For more depth, the 6 domains the qualification covers, the Class A / Class B distinction, and above all how to verify a provider is genuinely qualified : see our complete guide to PASSI qualification in Morocco.
You can also learn more about our approach to security audits and how we support organizations preparing for these reviews.
Law 09-08 and the Role of the CNDP
DGSSI compliance cannot be separated from Law 09-08 on the protection of natural persons with regard to the processing of personal data. The two texts complement each other and address the same organizations.
What Law 09-08 Requires
Any organization that collects, processes, or stores personal data in Morocco must:
- Declare its processing activities to the CNDP (National Commission for the Control of Personal Data Protection / Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel) for non-sensitive processing.
- Request authorization from the CNDP for sensitive data processing (health data, political opinions, religious beliefs, biometric data).
- Respect the fundamental principles: legality, fairness, transparency, purpose limitation, proportionality, limited retention, security, and confidentiality.
- Inform data subjects of their rights and obtain prior consent.
- Guarantee the rights of access, rectification, and objection of data subjects.
Sanctions Under Law 09-08
| Type of violation | Sanction |
|---|---|
| Processing without declaration or authorization | Warning to 200,000 MAD fine |
| Failure to implement security measures | 20,000 to 200,000 MAD fine |
| Serious violation with damage | 3 months to 1 year imprisonment + fine |
Connection with DGSSI Compliance
The DGSSI itself lists Law 09-08 among the regulatory texts organizations must respect as part of their information security compliance. The reason is straightforward: an inadequately secured information system is a potential vector for personal data breach. The two frameworks reinforce each other.
In practice, a well-structured compliance program addresses both requirements together, avoiding duplicated effort: the same processing inventory serves both DNSSI asset classification and CNDP declarations.
Our GRC team supports organizations in managing these two regulatory obligations simultaneously.
Who Is Actually Affected? The Scope in Practice
The question Moroccan SME executives most often ask: "Are we affected?" The answer depends on your status and sector.
Directly Subject to Law 05-20 and the DNSSI
| Category | Examples in Morocco |
|---|---|
| State administrations | Ministries, regional directorates, devolved services |
| Local authorities | Municipalities, provinces, regions |
| Public institutions | OCP, ONEE, ONCF, university hospitals, public universities |
| OIV - Energy | ONEE, oil and gas operators |
| OIV - Telecommunications | Maroc Telecom, Orange Morocco, INWI |
| OIV - Finance | Bank Al-Maghrib, banks, insurers (BMCE, CIH, etc.) |
| OIV - Healthcare | Public hospitals, university hospitals, military health services |
| OIV - Transport | ONCF, ONDA, ports |
| Private digital operators | ISPs, hosting providers, cybersecurity providers, cloud providers |
Private SMEs Outside the OIV Perimeter
A private SME in industry, trade, or services that is not classified as an OIV is not directly subject to Law 05-20 obligations in the same terms. It remains, however, subject to Law 09-08 as soon as it processes personal data, which covers virtually every business.
That said, even without direct legal obligation, SMEs working with public entities or OIVs increasingly face security requirements in tenders and contracts. DGSSI compliance has become a measurable competitive advantage in those contexts.
DGSSI Compliance and ISO 27001: Understanding the Articulation
The question comes up regularly: should you choose between DGSSI compliance and ISO 27001 certification, or can both coexist?
The answer is clear: they complement each other. The DNSSI is explicitly inspired by the Moroccan standard NM ISO/IEC 27002, the local equivalent of ISO 27002 (the security control catalog of ISO 27001). The domains covered by the DNSSI map almost point-for-point to the controls of Annex A in ISO 27001.
Mapping (Simplified)
| DNSSI domain | Matching ISO 27001 control |
|---|---|
| Security policy | A.5 - Information security policies |
| Security organization | A.6 - Organization of information security |
| Asset management | A.8 - Asset management |
| Access control | A.9 - Access control |
| Cryptography | A.10 - Cryptography |
| Physical security | A.11 - Physical and environmental security |
| Incident management | A.16 - Information security incident management |
| Business continuity | A.17 - Business continuity for information security |
| Legal compliance | A.18 - Compliance |
An organization that runs an ISO 27001 project for its information security management system (ISMS) simultaneously meets the vast majority of DNSSI requirements. The reverse is less true: DNSSI alone is not enough to obtain ISO 27001 certification, which requires a systemic risk approach and a certification audit by an accredited body. For complete details on stages, costs, and certification bodies, see our ISO 27001 certification guide for Morocco.
For OIVs and public institutions, a pragmatic strategy is to use the ISO 27001 project as the foundation of the DGSSI compliance program, then add Moroccan specifics on top (A/B/C classification, homologation, maCERT notification). Our ISO 27001 certification support systematically integrates this local regulatory dimension.
Practical Steps to Achieve Compliance
Here is the structured path we recommend for organizations starting a DGSSI compliance program. This plan applies equally to public institutions and to private-sector OIVs.
Step 1: Initial Assessment and Scoping (Weeks 1-4)
The first decision is the classification of your information systems. Which systems handle sensitive data? Which are critical to your operations? This inventory work produces a map of your information systems with a first-pass classification.
You also identify your current maturity level against the DNSSI domains. An initial risk assessment gives an honest picture of the gaps to close. RMG Solutions' GRC team regularly conducts this type of evaluation for public institutions and private operators subject to Law 05-20.
Before mobilizing a PASSI provider, our DGSSI compliance evaluator measures in 5 minutes the gap between your current situation and DNSSI requirements across the eleven domains.
Step 2: Formal Gap Analysis (Weeks 4-8)
The gap analysis compares your current situation to DNSSI requirements domain by domain. For each requirement, three states are possible: compliant, partially compliant, or non-compliant. The result is a gap report with a residual risk rating for each item.
This is the stage at which you decide compliance priorities based on your classification and identified risks.
Step 3: Roadmap and Implementation Plan (Weeks 8-12)
Based on the gap analysis, you define your compliance schedule. The DNSSI explicitly requires that this schedule distinguish:
- Immediate measures (critical fixes, high-impact low-cost actions)
- Short-term measures (3 to 6 months)
- Medium-term measures (6 to 18 months)
This plan is shared with the DGSSI as part of reporting obligations for affected entities.
Step 4: Implementation of Measures (Variable Duration)
The implementation phase is the longest. It typically covers:
- Drafting and validation of the information security policy and associated procedures
- Setting up access control and identity management
- Deployment of monitoring and incident detection tools (SIEM, EDR)
- Staff training and awareness
- Establishment or update of the business continuity plan (BCP)
- Review of third-party contracts on security clauses
Our continuous monitoring service can be integrated from this phase to ensure real-time detection of security events. For broader threat protection context, see our cybersecurity guide for Moroccan SMEs.
Step 5: Internal Audit and Preparation for External Audit
Before submitting your systems to a PASSI audit or a DGSSI inspection, an internal audit identifies and corrects any remaining gaps. This step avoids unpleasant surprises and significantly improves external audit results.
Step 6: PASSI Qualified Audit (For OIVs and Sensitive Systems)
OIVs operating sensitive information systems must have their systems audited by a DGSSI-qualified PASSI at least every three years. The audit covers the domains defined during qualification and produces a report of recommendations. A remediation plan must then be established and tracked.
Step 7: Continuous Monitoring and Improvement
Compliance is not a frozen state. It requires continuous monitoring of security events, periodic review of the security policy, and updating of the compliance plan as regulations and threats evolve.
Need expert guidance?
Leave your details and an RMG Solutions expert will contact you within 24h.
The 2030 National Cybersecurity Strategy: What's Coming
In July 2024, the DGSSI presented the 2030 National Cybersecurity Strategy. This long-term planning document rests on four pillars and eleven strategic objectives.
The four pillars:
- National cybersecurity governance: strengthening the legal framework, improving national coordination among actors.
- Security and resilience of the national cyberspace: enhanced protection of OIVs, mechanisms for collecting national indicators.
- Capacity building and awareness: cybersecurity culture in society, human resource training, support for the national ecosystem.
- Regional and international cooperation: participation in forums and strengthening Morocco's positioning globally.
The 2030 strategy includes 26 initiatives and 60 concrete actions. For private companies, the signal is clear: security requirements will continue to tighten, and regulatory attention on private actors will grow in coming years. Anticipating this evolution is less expensive than reacting to it under constraint.
In parallel, decree no. 2-24-921 was adopted concerning the use of cloud service providers by entities and OIVs operating sensitive information systems. The decree imposes qualification requirements on cloud providers handling sensitive data of those entities, a strong signal for the cloud market in Morocco.
The RMG Solutions Approach
DGSSI compliance and operational security, not just a report. Many GRC firms produce a gap analysis document, list non-conformities, and leave you with an 80-page PDF and no execution capacity. At RMG Solutions, we run the diagnostic AND we implement the corrective measures, because we are also a cybersecurity provider and an infrastructure provider. The DNSSI gap analysis identifies a missing access control? We deploy the solution. The mapping reveals no monitoring? We stand up the SIEM and the managed SOC. The A/B/C classification of your systems requires sovereign hosting? We operate it from our Moroccan servers. Our team, based in Hay Riad (Rabat), runs the full journey: gap analysis, risk treatment plan, control implementation, preparation for PASSI audits, and support toward ISO 27001 certification. A single point of contact, from the initial free assessment through to effective compliance.
Contact us to schedule your free 30-minute audit.
Frequently Asked Questions
What is the DGSSI and what is its role in Morocco?
The DGSSI (General Directorate of Information Systems Security) is Morocco's competent national authority for cybersecurity. Created in 2011 and attached to the National Defense Administration, it defines security rules applicable to public administrations and vital infrastructure, publishes the DNSSI directive, qualifies audit providers (PASSI), and oversees the maCERT, the national computer incident response center.
Is my private company subject to Law 05-20?
Not necessarily directly. Law 05-20 applies primarily to State administrations, public institutions, vital infrastructure operators (OIVs), and operators of digital networks and services (ISPs, hosting providers, cybersecurity providers). An SME in industry or trade that is not classified as an OIV is not subject to the same obligations. It remains, however, subject to Law 09-08 on personal data protection as soon as it processes data of customers, employees, or partners.
What is the difference between Law 05-20 and the DNSSI?
Law 05-20 is the legislative text that sets the general cybersecurity framework in Morocco: definitions, scope, general obligations, sanctions. The DNSSI is the technical and organizational directive that translates these obligations into concrete measures. It covers eleven security domains and introduces an information system classification scheme on three classes A, B, and C. The latest version of the DNSSI dates from January 2023.
Is ISO 27001 certification enough to be DGSSI compliant?
ISO 27001 and the DNSSI share the same conceptual foundation: the DNSSI is largely inspired by ISO/IEC 27002. A well-conducted ISO 27001 project covers the vast majority of DNSSI requirements. However, DGSSI compliance includes Moroccan specifics that ISO 27001 does not cover: A/B/C classification defined with the DGSSI, homologation obligation before deployment of sensitive systems, incident notification to maCERT, and mandatory use of DGSSI-qualified PASSI for audits. The two approaches are complementary, and it is efficient to run them jointly.
What are the sanctions for non-compliance with Law 05-20?
Law 05-20 provides for imprisonment of 2 to 5 years and a fine of 100,000 dirhams for violations resulting in data modification or deletion, or alteration of information system operation. For telecommunications operators, ISPs, cybersecurity providers, and digital platform editors, Article 50 of the law provides for fines from 100,000 to 200,000 dirhams for failure to meet obligations. These sanctions are in addition to penalties under Law 09-08 on data protection, which can impose fines up to 200,000 MAD.
By RMG Solutions
Certified Odoo Partner | Cybersecurity | Infrastructure | GRC
Last updated : July 25, 2026