Tunisia's public enterprises will face significant changes in their approach to cybersecurity following the introduction of a new circular on September 2, 2026. The circular will require these enterprises to implement a range of measures, including multi-factor authentication, DDoS protection, regular audits, data backup, and business continuity planning. This shift from a project-based approach to a permanent, ongoing process will necessitate increased recurring budgets for cybersecurity.
The new circular will have far-reaching implications for public enterprises, affecting not only their cybersecurity practices but also their budgeting and financial planning. For the first time, cybersecurity will need to be factored into their regular budgets, rather than being treated as a one-off expense. This will require significant changes in the way these enterprises allocate resources and prioritize their spending.
Private companies that work with public enterprises will also be impacted by the new circular. To do business with the public sector, they will need to demonstrate compliance with the new cybersecurity requirements. This may lead to a situation where only companies with the necessary certifications and capabilities will be able to compete for public sector contracts. The list of approved cloud providers published by the ANCS on September 17, 2026, currently only includes six entries.
The new requirements may lead to a shift towards more integrated offerings and consortiums in the market. Smaller technology companies may need to adapt by forming partnerships with larger players or investing in new skills and competencies. This could lead to a more concentrated market, with a smaller number of larger players dominating the public sector cybersecurity market.
The circular also highlights the importance of business continuity and disaster recovery planning for public enterprises. By January 1, 2027, these enterprises will be required to have in place a business continuity plan (PCA) and a disaster recovery plan (PRA), as well as to be certified to the ISO 22301 standard. This will require significant investment in new skills and technologies.
The market for cloud and cybersecurity services in Tunisia is already significant, with several large contracts awarded in recent months. The CNI cloud contract, awarded in January 2026, was worth over 24.9 million TND. The total value of four cloud and security contracts cited in the report was calculated to be around 27.2 million TND.
The new cybersecurity rules will have a profound impact on the way public enterprises and private suppliers operate in Tunisia. As the country continues to evolve its approach to cybersecurity, it is likely that we will see significant changes in the market for cloud and cybersecurity services. The emphasis on compliance and certification will create new opportunities for companies with the right skills and capabilities.
Key points
- The new circular will require public enterprises to implement a range of cybersecurity measures, including multi-factor authentication and business continuity planning.
- Private companies will need to demonstrate compliance with the new requirements to do business with the public sector.
- The market may shift towards more integrated offerings and consortiums in response to the new requirements.