Prime Minister Issues Circular to Strengthen Public Sector Cybersecurity

Written by: Adel Khelifi on September 4, 2026

The head of government, Sarra Zaafrani Zenzri, published a circular concerning the securing of national digital systems within public structures in the face of the multiplication of threats and cyber risks, notably with regard to the protection of official sites and electronic platforms for public services, in order to guarantee the continuity of these services for the benefit of citizens and businesses.

The circular provides a series of mandatory measures relating to the protection of electronic sites and platforms, official messaging, and the prevention of cyberattacks.

Regarding the security of public electronic sites and platforms, the circular requires their exclusive hosting by the National Center for Informatics, sectoral public centers, or licensed telecommunications operators, with exceptions in certain special cases dictated by considerations related to security and national defense.

The text also provides for the mandatory use of the HTTPS protocol and the activation of multifactor authentication (MFA) for all users and administrators.

It also mandates a full audit of systems once a year, as well as before the launch of any major new version, by audit bodies approved by the National Cybersecurity Agency.

Regarding electronic exchanges, the circular prohibits the transmission or publication of administrative documents via mobile applications and social networking platforms, as part of securing official correspondence and documents and reducing the risk of data leakage.

It also requires the exclusive use of the nationally approved electronic messaging service under the domain “.tn” for all operations and official correspondence.

The circular further provides for the regular updating of databases relating to accounts, the deactivation of inactive accounts or those belonging to agents who have left their posts, along with the activation of logging and archiving functions for operations.

On an organizational level, the circular stresses the need to subscribe to protection services against distributed denial-of-service (DDoS) attacks and to strengthen prevention mechanisms as well as the capacity to respond to cyber incidents.

The affected structures are also required to immediately inform the National Cybersecurity Agency of any incident or cyberattack.

In this framework, the circular forbids sharing access accounts and calls to isolate sensitive databases from external networks in accordance with international standards. It also imposes periodic audits of information systems.

The text obliges public structures to develop and update their business continuity and disaster recovery plans, while mandating prior coordination with the Ministry of Communications Technologies when adopting projects affecting the digital infrastructure.

The circular also calls for regularly organizing training sessions and awareness campaigns for the benefit of staff and executives, and to integrate them into annual training plans.

It finally emphasizes the need to mobilize human and technical resources as well as the financial resources necessary to implement cybersecurity requirements and ensure their sustainability.

Dated September 2, 2026, the circular was addressed to ministers, secretaries of state, governors, as well as to presidents of companies and public institutions, in the context of strengthening the protection of national systems and data against cyber risks and ensuring the continuity of public services.

Adel Khelifi

Adel Khelifi

My name is Adel Khelifi, and I’m a journalist based in Tunis with a passion for telling local stories to a global audience. I cover current affairs, culture, and social issues with a focus on clarity and context. I believe journalism should connect people, not just inform them.