Tunisia adopts new measures to protect public digital systems from cyber threats
Translated from French and summarized by DistantNews. Read the original for the full story.
At a glance
- Tunisia has ordered public institutions to strengthen cybersecurity and ensure the continuity of digital services.
- The measures require secure hosting, HTTPS, multifactor authentication, annual audits and exclusive use of official .tn email for government correspondence.
- Public bodies must prepare for DDoS attacks and immediately notify the National Cybersecurity Agency of cyber incidents.
Tunisia is tightening the rules governing public-sector digital systems as cyber threats and risks grow. Prime Minister Sarra Zaafrani Zenzri issued a circular requiring stronger protection for official websites, electronic public-service platforms and the continuity of services for citizens and institutions.
Dated September 2, 2026, the circular applies to ministers, secretaries of state, governors and the heads of public institutions and companies. It requires public websites and platforms to be hosted exclusively by the National Computing Center, public sector data centers or approved telecommunications operators. Exceptions may be made for cases involving national security and defense considerations.
Public bodies must also adopt HTTPS and activate multifactor authentication for all users and administrators. They must carry out a complete audit of their systems every year and before launching any major new version. Accredited bodies approved by the National Cybersecurity Agency must conduct those audits.
The circular also bans the circulation or publication of administrative documents through mobile applications and social-media platforms. Official transactions and correspondence must use Tunisiaโs national email service under the .tn domain. Accounts must be updated regularly, inactive accounts must be disabled, and accounts belonging to staff who have left their positions must also be deactivated. Logging and archiving functions must remain active.
To strengthen protection against distributed denial-of-service attacks, public institutions are instructed to subscribe to DDoS protection services. They must also improve cyber-incident prevention and response, and immediately inform the National Cybersecurity Agency of any incident or cyberattack.
Originally published by La Presse in French. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.