Somalia has launched a National Cybersecurity Risk Management Framework to strengthen cyber resilience and protect the country’s critical information infrastructure as digital transformation accelerates across key sectors.
Released in June 2026, the framework establishes a national approach to identifying, assessing, managing and mitigating cybersecurity risks across government institutions, telecommunications, financial services, critical infrastructure and other essential industries.
Developed by the Ministry of Communications and Technology (MoCT), the framework introduces baseline cybersecurity requirements, governance principles and risk management controls aimed at improving resilience, protecting critical digital assets and ensuring the continuity of essential services.
The National Communications Authority (NCA), Somalia’s lead cybersecurity regulator, said the framework provides organizations with a structured methodology for cybersecurity risk management while aligning with international standards such as ISO/IEC 27000 and ISO/IEC 27005.
Under the new framework, all public and private organizations operating Critical Information Infrastructure (CII) must conduct regular cybersecurity risk assessments, prioritize cyber risks and submit annual assessment reports to the NCA in line with the Somalia Cybersecurity Act.
The framework also introduces sector-specific business impact models, a national cybersecurity maturity model, emerging technology risk management guidelines and a roadmap for strengthening cyber resilience across Somalia’s growing digital economy
