Operators of essential services in Togo: what designation really changes for your organisation
Being designated an operator of essential services (OES) is not a badge: it is entry into a regime of enforceable obligations, coupled with an annual audit and penalties. An overview of the Togolese framework and its practical friction points.
Togo's digital transformation has a measurable downside. Between 2021 and 2024, the National Cybersecurity Agency (ANCy) reports having recorded and handled more than 333,000 incidents nationwide, with annual volumes rising from 39,168 cases in 2021 to 181,088 in 2024. In its review presented in December 2025, the Agency noted that close to 80% of recorded cyber threats consist of online fraud and scams, and confirmed the continuation of the National Cybersecurity Strategy 2024-2028. Against this background, compliance by operators of essential services ceases to be a technical matter and becomes one of directors' responsibility.
1. A three-tier framework
The Togolese OES regime rests on a straightforward normative architecture, though one often poorly identified by the businesses concerned.
01. The law
Law No. 2018-026 of 7 December 2018 on cybersecurity and combating cybercrime, as amended by Law No. 2022-009, which lays down the principle: operators whose activity underpins national defence, public safety, economic stability or national security are subject to security rules designed to protect their infrastructure.
02. The "OES" decree
Decree No. 2019-095/PR of 8 July 2019 on operators of essential services, essential infrastructure and the related obligations sets out the criteria and procedures for designating OES, the declaration of essential infrastructure (EI) and the attaching obligations. The list of essential services appears in the annex to the decree.
03. The operational order
Order No. 2022-040/PMRT of 29 June 2022 adopting the cybersecurity rules in the Togolese Republic, made under article 11 of the OES decree. This is the operational text: it contains the framework the OES must apply, on pain of penalties.
Two institutional actors
L'ANCy, established by Decree No. 2019-022/PR of 13 February 2019, is the national information systems security authority: it designates OES, sets the rules and monitors their application. The semi-public company Cyber Defense Africa (CDA), as the ANCy's delegatee, operates CERT.tg and the national SOC and is entrusted, under a public service delegation contract, with the annual inspection of OES.
2. Four domains, fourteen sub-domains
The cybersecurity rules are organised around four domains, broken down into fourteen control sub-domains, each accompanied by precise controls and sub-controls:
Governance (G)
Governance and leadership, security policy and operator security plan (OSP), compliance and audit, risk management, human resources, supplier relations.
Protection (P)
Access control, asset management, network and communications security, acquisition and maintenance of information systems, operations security, physical and environmental security.
Defence (D)
Security incident management, underpinned by a service for monitoring, detecting, analysing and characterising security events (SOC).
Resilience (R)
Business continuity management.
This framework is not a straightforward transposition of ISO 27001. It draws on it (as it does on NIST 800-53, the CIS controls and PCI DSS) but adds quantified, directly verifiable requirements which, once the operator is designated, become legal obligations rather than good practice.
3. The quantified requirements not to be missed
Experience from the first accreditation cycles shows that non-conformities bear less on strategy than on dated operational points. Among the most structural:
- G1.1.5Appointment of a CISO for each OES, with a training plan comprising at least an ISO/IEC 27001-type certification or equivalent.
- D1.3.2/.6A logging, correlation and analysis system operating 24/7, with time-stamping, centralisation and archiving of events for at least six months.
- P3.3.5A prohibition on essential infrastructure connecting directly to the internet: traffic must pass through a next-generation firewall gateway, separate from DNS, mail and proxy servers.
- D1.4.4Monthly identification of internet-facing vulnerabilities, with remediation within two weeks of identification.
- G3.3.2Independent external cybersecurity assessment, including penetration testing, at least once every two years.
- R1.4.2Continuity plan testing at least twice a year, with an interval of four to six months between tests.
- P1.4.8Renewal of secret authentication credentials at least quarterly, and systematically where compromise is suspected.
4. Notification obligations: the first reflex after designation
Notification of designation as an OES triggers deadlines that start running immediately. They are frequently missed, for want of having been identified.
These notifications are not formalities: they determine the ability of the ANCy and its delegatee to characterise an incident and to mobilise the right counterpart in a crisis.
5. The annual inspection and accreditation cycle
Compliance monitoring follows a cycle that must be anticipated in the company's calendar. The OSP is implemented across the essential infrastructure; the delegatee conducts the annual audit; an audit report (covered by professional secrecy) establishes whether the level of security achieved conforms to the objectives of the OSP, having regard to known threats and vulnerabilities, and makes remediation recommendations; the OES addresses the non-conformities; the OSP is then updated as part of the accreditation procedure, taking account of events over the past year. The rules themselves are subject to revision at least every two years.
The OES must further maintain an up-to-date accreditation file containing the risk analysis and the security objectives for the essential infrastructure, the security procedures and measures applied, together with residual risks, the mitigation measures adopted and the reasons for accepting them (G1.2.2).
6. Three legal blind spots
A. The supplier chain
Sub-control G6.3.1 requires some fifteen stipulations to be built into supplier contracts: a confidentiality agreement backed by real penalties, source code escrow, an SLA for remediating vulnerabilities, access to source code during and after the contract for critical software, supplier insurance against loss arising from defective performance, and a formalised escalation procedure. Few IT contracts currently in force in Togo satisfy this requirement. A contractual review of the supplier portfolio is, in practice, the heaviest piece of compliance work.
B. The interface with data protection
The framework refers expressly to confidentiality and to the protection of personal data (G3.1.4). Law No. 2019-014 of 29 October 2019 and the now-effective activity of the Personal Data Protection Authority (IPDCP) create a second line of requirements, whose perimeters overlap without merging. An incident affecting essential infrastructure and involving personal data falls under both regimes.
C. Management responsibility
The framework expressly designates the board of directors as bearing overall responsibility for the state of the OES's cybersecurity, and the chief executive as responsible for accepting and approving the requirements. It requires the establishment of a cybersecurity steering committee chaired by the chief executive or their delegate, and recommends that the cybersecurity function should not report to the IT department, so as to avoid any conflict of interest. OES compliance is therefore, in law, a matter of corporate governance before it is a technical matter.
In practice
Whether you have already been designated, are in the middle of adversarial proceedings, or are simply liable to be designated in light of the list annexed to the OES decree, four questions warrant resolution without delay:
- ?Is the perimeter of your essential infrastructure correctly delineated?
- ?Are your notification deadlines being met?
- ?Is your OSP documented and auditable?
- ?Would your supplier contracts withstand a review against sub-control G6.3.1?
AMELEGAL advises designated and prospective operators across the entire chain.
Characterising the perimeter, safeguarding the adversarial designation procedure, bringing the supplier chain into contractual compliance, managing the interface with the data protection regime, and handling incidents from a legal standpoint.
Reference texts: Law No. 2018-026 of 7 December 2018 on cybersecurity and combating cybercrime, as amended by Law No. 2022-009; Decree No. 2019-022/PR of 13 February 2019 on the powers, organisation and functioning of the ANCy; Decree No. 2019-095/PR of 8 July 2019 on operators of essential services, essential infrastructure and the related obligations; Decree No. 2019-098/PR of 11 July 2019 establishing the company Cyber Defense Africa; Order No. 2022-040/PMRT of 29 June 2022 adopting the cybersecurity rules in the Togolese Republic (Cybersecurity Rules, version 1.0, June 2022); Law No. 2019-014 of 29 October 2019 on the protection of personal data; National Cybersecurity Strategy 2024-2028; incident data supplied by the ANCy (2025 review).
This article provides general information and does not constitute legal advice. AMELEGAL