What is Loi 05-20 ?
Law 05-20 on cybersecurity is the Moroccan legal framework that defines, across 52 articles, the obligations of public organizations, Operators of Vital Importance (OIV), and Essential Service Operators (OSE) regarding information system security. Published in the Official Gazette in 2020, it gives legal force to the DNSSI. The law establishes the institutional framework: the DGSSI, the Strategic Committee for information systems security, and maCERT as the national point of contact for incident management. It imposes three main obligations on OIV and OSE: notifying security incidents to maCERT, obtaining accreditation for their information systems, and cooperating with competent authorities. Non-compliance is punishable by fines ranging from 100,000 to 1,000,000 MAD and prison sentences of 1 to 5 years.
Key Points
- Legal framework giving legal force to the DNSSI and cybersecurity requirements
- Mandatory security incident notification to maCERT
- Mandatory system accreditation for OIV and OSE information systems
- Penalties: fines from 100,000 to 1,000,000 MAD, imprisonment from 1 to 5 years
- Institutional framework: DGSSI, Strategic SSI Committee, maCERT as national point of contact
Why Zaxyr
Zaxyr natively integrates Law 05-20 requirements alongside the DNSSI. The platform automates legal obligation tracking, including security incident notification to maCERT, facilitates accreditation preparation for OIV and OSE information systems, and generates compliance reports in French and Arabic. Mapping to the DNSSI and ISO 27001 enables a unified approach to Moroccan regulatory compliance, through a shared institutional framework with the DGSSI.