The Assembly of the Republic of Mozambique has passed two foundational pieces of legislation: the Cybersecurity Law and the Cybercrime Law. This legislative package is a direct response to the escalating cyber threats facing the nation, which saw 173,770 cyberattacks in 2024. The laws will establish a national cybersecurity regulatory body, impose security obligations on all public and private organizations, and create a penalty framework for non-compliance. This represents a major advancement in Mozambique's national strategy to build a secure and resilient digital ecosystem, protecting critical infrastructure, businesses, and citizens.
The new legal framework introduces a comprehensive, top-down approach to national cybersecurity governance.
The new legislation imposes several key obligations on affected organizations:
While the laws have been approved by Parliament, the specific timeline for the establishment of the regulatory body and the enforcement of penalties has not yet been detailed. However, organizations are expected to begin preparing for compliance immediately.
The introduction of these laws will have a significant operational and financial impact on businesses in Mozambique. Organizations will need to invest in cybersecurity technologies, personnel, and processes to meet the new legal standards. This will likely drive demand for cybersecurity services and solutions within the country. While this presents a compliance burden, the long-term goal is to create a more stable and secure business environment, reducing the economic damage caused by cybercrime and enhancing trust in Mozambique's digital economy.
Non-compliance with the new regulations will result in financial penalties. The law specifies fines ranging from one to 160 times the minimum wage in the public sector. This penalty structure is designed to be scalable and applicable to organizations of different sizes. The regulatory authority will be empowered to levy these fines and conduct audits to ensure compliance.
Organizations in Mozambique should take the following steps to prepare:

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats