Tunis: Head of Government Sarra Zaafrani Zenzri has issued a circular setting out mandatory measures to strengthen the security of national digital systems within public institutions against growing cyber threats, particularly those targeting official websites and online public service platforms. According to Agence Tunis Afrique Presse, the circular introduces a range of mandatory measures covering the protection of websites and online platforms, official electronic communications, as well as the prevention of cyberattacks. Public websites and online platforms must be hosted exclusively by the National Centre for IT, public sector data centres or authorised telecommunications operators, except in specific cases justified by national security and defence considerations. They must also use the HTTPS protocol and enable multi-factor authentication (MFA) for all users and administrators. The circular further requires a comprehensive audit of digital systems once a year and before the deployment of any major ne w release, to be conducted by auditing bodies accredited by the National Cybersecurity Agency. To secure official electronic communications and prevent data leaks, the circular prohibits the circulation or publication of administrative documents through mobile applications and social media platforms. It also requires the exclusive use of official national email accounts under the '.tn' domain for all official transactions and correspondence. Public institutions must regularly update their account databases, deactivate inactive accounts and those belonging to staff whose employment has ended, and activate systems for logging and archiving operations. The circular also requires public institutions to subscribe to Distributed Denial-of-Service (DDoS) protection services, strengthen cyberattack prevention and incident-response mechanisms, and immediately notify the National Cybersecurity Agency of any cyber incident or attack. It additionally prohibits the sharing of access credentials and requires sensitive da tabases to be isolated from external networks in accordance with international standards, alongside regular audits of information systems. Public institutions are also required to prepare and regularly update business continuity and disaster recovery plans, while coordinating in advance with the Ministry of Communication Technologies on any projects affecting digital infrastructure. The circular calls for regular cybersecurity training and awareness campaigns for staff and officials, to be incorporated into annual training programmes. Institutions must also ensure that the necessary human, technical and financial resources are available to implement and sustain these cybersecurity measures. Dated September 2, 2026, the circular was addressed to ministers, secretaries of state, governors, and heads of public institutions and enterprises. It forms part of broader efforts to strengthen the protection of Tunisia's national digital systems and data against cyber threats and ensure the continuity of public service s.
Home » Government Issues Circular to Strengthen Public-Sector Cybersecurity