Cybersecurity is no longer a matter for IT specialists alone: it has become a legal obligation and a question of survival for Moroccan companies. In 2025, the General Directorate of Information Systems Security (DGSSI) recorded 879 cyberattacks and carried out 109 direct interventions. Faced with this pressure, Morocco has adopted a binding framework, Law 05-20 on cybersecurity, while the international standard ISO/IEC 27001 has established itself as the most widely recognised management response. This article reviews, with official sources to hand, what the law requires, what the standard delivers, and how the two complement each other.

The key points in brief

  • Law 05-20 on cybersecurity, enacted by dahir no. 1-20-69 of 25 July 2020, and its implementing decree no. 2-21-406 of 15 July 2021 (source: DGSSI).
  • 879 cyberattacks recorded by the DGSSI in 2025, including 109 direct interventions (source: DGSSI, as reported in the press).
  • ISO/IEC 27001:2022: 93 security controls organised into 4 themes, replacing the 114 controls of the 2013 version (source: ISO).
  • Mandatory security audit at least every two years for critical infrastructures.

Why cybersecurity has become a boardroom issue

Morocco ranks among the African countries most exposed to cyberattacks, driven by the rapid digitalisation of the economy and public administration. The rise of ransomware, phishing and data breaches now affects businesses of every size, with micro-enterprises and SMEs particularly exposed, as they are often less well protected and used as entry points towards larger clients. Beyond the financial and reputational risk, a major incident can halt operations and expose directors to liability. It is in this context that the Moroccan legislator has made information systems security enforceable, and that ISO 27001 certification is becoming a commercial asset as much as a shield.

The Moroccan legal framework: Law 05-20 and its implementing decree

Law no. 05-20 on cybersecurity establishes, for the first time, a complete regulatory foundation for the protection of information systems in Morocco. It is led by the DGSSI, which reports to the National Defence Administration, and detailed by decree no. 2-21-406. Its objective: to raise the security level of the information systems of the State and of the actors deemed sensitive to the Nation.

Who is concerned?

The text targets first and foremost State administrations, local authorities, public institutions and, above all, critical infrastructures and organisations of vital importance (OIV): the facilities and systems essential to the functioning of society (energy, telecommunications, finance, health, transport, water, security). A crucial point for the private sector: a company that provides services to these entities, or that operates in these sectors, potentially falls within the scope of the obligations. Compliance thus spreads through the subcontracting chain.

The key obligations

  • Security approval of sensitive systems before they are brought into service.
  • Periodic security audit, at least once every two years for OIVs, carried out by a qualified audit provider (PASSI).
  • Incident notification to the DGSSI, via maCERT (the national incident response team), within defined timeframes.
  • Classification of information systems according to three levels of sensitivity (classes A, B and C), defined together with the DGSSI.
  • Implementation of the technical and organisational measures of the National Directive on Information Systems Security (DNSSI), the operational framework that translates the law into concrete terms.

This framework forms part of the National Cybersecurity Strategy towards 2030 published by the DGSSI, which aims to build the Kingdom's digital resilience on a lasting basis (source: DGSSI, National Cybersecurity Strategy 2030).

Not to be confused: cybersecurity and personal data protection

Law 05-20 protects systems. The protection of personal data falls under a separate text: Law 09-08, Morocco's equivalent of the GDPR, overseen by the National Commission for the Control of Personal Data Protection (CNDP). A genuinely compliant company handles both aspects together: securing the infrastructure (05-20 / DNSSI) and governing the processing of data (09-08 / CNDP). A well-built information security management system naturally covers both requirements.

ISO/IEC 27001: the international management response

Where the law sets obligations, the ISO/IEC 27001 standard provides the method. It is the international reference standard for establishing, implementing and improving an Information Security Management System (ISMS). Its logic is not purely technical: it rests on risk analysis, management commitment and continual improvement (the PDCA cycle), so that security becomes a living process rather than a list of tools.

What the 2022 version changed

The ISO/IEC 27001:2022 revision modernised Annex A, which lists the security controls. The 114 controls spread across 14 domains have been reorganised into 93 controls grouped into 4 themes:

  • A.5 Organisational controls (37 controls): policies, roles, supplier management, incident management.
  • A.6 People controls (8 controls): awareness, remote working, confidentiality.
  • A.7 Physical controls (14 controls): access control, security of premises and equipment.
  • A.8 Technological controls (34 controls): encryption, logging, backups, development security.

Eleven new controls were introduced, reflecting current threats: threat intelligence, cloud security, data leakage prevention (DLP), activity monitoring, web filtering and secure coding. Organisations certified under the former 2013 version had to complete their transition before 31 October 2025 (source: ISO/IEC 27001).

ISO 27001 and DNSSI: competing or complementary?

Good news for Moroccan companies: the two frameworks share the same conceptual foundation. The DNSSI draws heavily on the good practices of ISO/IEC 27002, so much so that a well-run ISO 27001 project covers the vast majority of the DNSSI requirements. Building an ISMS therefore means progressing simultaneously towards regulatory compliance and towards an internationally recognised certification, valuable for export and in tender processes.

One caveat, however: Moroccan compliance adds specific features that the standard does not cover on its own, notably the A/B/C classification defined together with the DGSSI, the requirement for security approval before deploying sensitive systems, and the notification of incidents to maCERT. The right approach is to build an ISO 27001 ISMS and to graft these local requirements onto it.

Roadmap towards compliance and certification

  1. Define the scope and identify whether the organisation is concerned by Law 05-20 (sector, OIV clients).
  2. Carry out a risk analysis and a current-state review (the gap between what exists, ISO 27001 and the DNSSI).
  3. Classify the systems (A/B/C) and define the Statement of Applicability for the 93 controls.
  4. Deploy the controls, both technical and organisational, and raise team awareness.
  5. Have the ISMS audited (internal audit and then, where applicable, PASSI audit and certification audit).
  6. Improve continually: monitoring, incident management, management review.

Free resource

ISO/IEC 27001:2022 ISMS conformity audit grid

Self-assess your information security management system, clause by clause (4 to 10), with a conformity score and dashboard computed automatically. HEMC Excel file, 24 requirements, available in French, English, Spanish and Arabic.

Download the free grid

How HEMC supports companies

Information security is one of HEMC's areas of expertise. We help organisations map their risks, close the gap with Law 05-20 and the DNSSI, build an ISMS compliant with ISO/IEC 27001 and prepare for audits, connecting Moroccan regulatory compliance with international certification. To find out more, discover our information security expertise or speak with our consultants.

This article is provided for information purposes and does not constitute legal advice. The reference texts prevail: consult the official publications of the DGSSI and the text of the ISO/IEC 27001 standard.