A new government directive requires multi-factor authentication, secure hosting, and annual security audits for all state administrations and public companies.
Tunisian public administrations and companies must now comply with new cybersecurity regulations outlined in government circular number 05, dated September 2, 2026. Key mandates include implementing multi-factor authentication (MFA) for system access, hosting digital services with approved operators, and ensuring all communications use the HTTPS protocol. The circular also mandates immediate reporting of security incidents and prohibits the transmission of administrative documents via messaging apps or social media, restricting official exchanges to institutional email addresses ending in ".tn".
The directive aims to bolster the security of digital public services by requiring a second layer of verification beyond just a password for accessing systems. This will necessitate technical and organizational adjustments, particularly for entities lacking adequate infrastructure. Furthermore, the ban on using personal messaging applications for official document sharing will alter daily work habits, requiring clear guidelines and secure alternatives for public sector employees.
Public entities will also be required to conduct annual IT security audits to identify and rectify vulnerabilities proactively. Protection against distributed denial-of-service (DDoS) attacks is also stipulated to ensure the availability of public digital platforms. The effectiveness of these new rules, however, hinges on their practical implementation, including the timeline for compliance, allocated budgets for MFA deployment and audits, and the oversight mechanisms for enforcement.
Why it mattersPublic administrations and state-owned companies face new operational requirements and potential costs to comply with enhanced cybersecurity measures.
Read in the ASJ desk →