← Back to the blog
Cybersecurity/OES

Operators of essential services in Togo: what designation really changes for your organisation

14 July 2026 · AMELEGAL

Being designated an operator of essential services (OES) is not a badge: it is entry into a regime of enforceable obligations, coupled with an annual audit and penalties. An overview of the Togolese framework and its practical friction points.

Togo's digital transformation has a measurable downside. Between 2021 and 2024, the National Cybersecurity Agency (ANCy) reports having recorded and handled more than 333,000 incidents nationwide, with annual volumes rising from 39,168 cases in 2021 to 181,088 in 2024. In its review presented in December 2025, the Agency noted that close to 80% of recorded cyber threats consist of online fraud and scams, and confirmed the continuation of the National Cybersecurity Strategy 2024-2028. Against this background, compliance by operators of essential services ceases to be a technical matter and becomes one of directors' responsibility.

333,000+
incidents handled (2021-2024)
39,168
incidents in 2021
181,088
incidents in 2024
~80 %
online fraud and scams

1. A three-tier framework

The Togolese OES regime rests on a straightforward normative architecture, though one often poorly identified by the businesses concerned.

01. The law

Law No. 2018-026 of 7 December 2018 on cybersecurity and combating cybercrime, as amended by Law No. 2022-009, which lays down the principle: operators whose activity underpins national defence, public safety, economic stability or national security are subject to security rules designed to protect their infrastructure.

02. The "OES" decree

Decree No. 2019-095/PR of 8 July 2019 on operators of essential services, essential infrastructure and the related obligations sets out the criteria and procedures for designating OES, the declaration of essential infrastructure (EI) and the attaching obligations. The list of essential services appears in the annex to the decree.

03. The operational order

Order No. 2022-040/PMRT of 29 June 2022 adopting the cybersecurity rules in the Togolese Republic, made under article 11 of the OES decree. This is the operational text: it contains the framework the OES must apply, on pain of penalties.

Two institutional actors

L'ANCy, established by Decree No. 2019-022/PR of 13 February 2019, is the national information systems security authority: it designates OES, sets the rules and monitors their application. The semi-public company Cyber Defense Africa (CDA), as the ANCy's delegatee, operates CERT.tg and the national SOC and is entrusted, under a public service delegation contract, with the annual inspection of OES.

2. Four domains, fourteen sub-domains

The cybersecurity rules are organised around four domains, broken down into fourteen control sub-domains, each accompanied by precise controls and sub-controls:

Governance (G)

Governance and leadership, security policy and operator security plan (OSP), compliance and audit, risk management, human resources, supplier relations.

Protection (P)

Access control, asset management, network and communications security, acquisition and maintenance of information systems, operations security, physical and environmental security.

Defence (D)

Security incident management, underpinned by a service for monitoring, detecting, analysing and characterising security events (SOC).

Resilience (R)

Business continuity management.

This framework is not a straightforward transposition of ISO 27001. It draws on it (as it does on NIST 800-53, the CIS controls and PCI DSS) but adds quantified, directly verifiable requirements which, once the operator is designated, become legal obligations rather than good practice.

3. The quantified requirements not to be missed

Experience from the first accreditation cycles shows that non-conformities bear less on strategy than on dated operational points. Among the most structural:

4. Notification obligations: the first reflex after designation

Notification of designation as an OES triggers deadlines that start running immediately. They are frequently missed, for want of having been identified.

These notifications are not formalities: they determine the ability of the ANCy and its delegatee to characterise an incident and to mobilise the right counterpart in a crisis.

5. The annual inspection and accreditation cycle

Compliance monitoring follows a cycle that must be anticipated in the company's calendar. The OSP is implemented across the essential infrastructure; the delegatee conducts the annual audit; an audit report (covered by professional secrecy) establishes whether the level of security achieved conforms to the objectives of the OSP, having regard to known threats and vulnerabilities, and makes remediation recommendations; the OES addresses the non-conformities; the OSP is then updated as part of the accreditation procedure, taking account of events over the past year. The rules themselves are subject to revision at least every two years.

The OES must further maintain an up-to-date accreditation file containing the risk analysis and the security objectives for the essential infrastructure, the security procedures and measures applied, together with residual risks, the mitigation measures adopted and the reasons for accepting them (G1.2.2).

6. Three legal blind spots

A. The supplier chain

Sub-control G6.3.1 requires some fifteen stipulations to be built into supplier contracts: a confidentiality agreement backed by real penalties, source code escrow, an SLA for remediating vulnerabilities, access to source code during and after the contract for critical software, supplier insurance against loss arising from defective performance, and a formalised escalation procedure. Few IT contracts currently in force in Togo satisfy this requirement. A contractual review of the supplier portfolio is, in practice, the heaviest piece of compliance work.

B. The interface with data protection

The framework refers expressly to confidentiality and to the protection of personal data (G3.1.4). Law No. 2019-014 of 29 October 2019 and the now-effective activity of the Personal Data Protection Authority (IPDCP) create a second line of requirements, whose perimeters overlap without merging. An incident affecting essential infrastructure and involving personal data falls under both regimes.

C. Management responsibility

The framework expressly designates the board of directors as bearing overall responsibility for the state of the OES's cybersecurity, and the chief executive as responsible for accepting and approving the requirements. It requires the establishment of a cybersecurity steering committee chaired by the chief executive or their delegate, and recommends that the cybersecurity function should not report to the IT department, so as to avoid any conflict of interest. OES compliance is therefore, in law, a matter of corporate governance before it is a technical matter.

In practice

Whether you have already been designated, are in the middle of adversarial proceedings, or are simply liable to be designated in light of the list annexed to the OES decree, four questions warrant resolution without delay:

  • ?Is the perimeter of your essential infrastructure correctly delineated?
  • ?Are your notification deadlines being met?
  • ?Is your OSP documented and auditable?
  • ?Would your supplier contracts withstand a review against sub-control G6.3.1?

AMELEGAL advises designated and prospective operators across the entire chain.

Characterising the perimeter, safeguarding the adversarial designation procedure, bringing the supplier chain into contractual compliance, managing the interface with the data protection regime, and handling incidents from a legal standpoint.

Reference texts: Law No. 2018-026 of 7 December 2018 on cybersecurity and combating cybercrime, as amended by Law No. 2022-009; Decree No. 2019-022/PR of 13 February 2019 on the powers, organisation and functioning of the ANCy; Decree No. 2019-095/PR of 8 July 2019 on operators of essential services, essential infrastructure and the related obligations; Decree No. 2019-098/PR of 11 July 2019 establishing the company Cyber Defense Africa; Order No. 2022-040/PMRT of 29 June 2022 adopting the cybersecurity rules in the Togolese Republic (Cybersecurity Rules, version 1.0, June 2022); Law No. 2019-014 of 29 October 2019 on the protection of personal data; National Cybersecurity Strategy 2024-2028; incident data supplied by the ANCy (2025 review).

This article provides general information and does not constitute legal advice. AMELEGAL

Thank you ! A confirmation email has just been sent to you. Click the link it contains to confirm your subscription, and do check your spam folder if it does not appear in your inbox.
Newsletter

AMENEWS

Your African legal and digital newsletter.

Each month, a selection of analysis and practical resources : personal data protection, the Malabo Convention, cybersecurity, artificial intelligence and digital governance in Africa.

Add a comment