Compliance · July 2026

DGSSI and CNDP Compliance: A Practical Guide for Moroccan Businesses

Compliance is a baseline, not a ceiling. Navigating Morocco's regulatory landscape — DGSSI directives for information systems security, CNDP requirements for personal data protection — can feel like an administrative hurdle stacked on top of the technical work you're already doing. Treating these frameworks as paperwork misses the point: they exist as a battle-tested roadmap for protecting your business and your customers' trust, built from lessons other organizations already learned the hard way.

DGSSI: securing information systems

The Direction Générale de la Sécurité des Systèmes d'Information (DGSSI) sets security directives that apply directly to operators of vital importance and government-linked entities, and increasingly shape best-practice expectations across the wider private sector. For businesses in scope, this typically means formal risk assessments, defined security architecture requirements, and periodic security audits — including penetration testing — rather than ad hoc improvements made only after something goes wrong.

CNDP: protecting personal data

The Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) oversees Morocco's data protection law (Law 09-08), which governs how businesses collect, process, and store personal data — customer records, employee files, transaction histories. If your business handles personal data (and almost every business does), CNDP obligations apply regardless of your sector. That includes registering certain data processing activities, securing the data you hold, and being able to demonstrate — not just assert — that you're doing so.

Where compliance and security actually overlap

The businesses that struggle with compliance are usually the ones treating it as a separate track from their actual security work — a folder of policy documents that doesn't reflect what's happening on the network. The ones that succeed treat the regulatory requirement and the technical control as the same project:

  • A documented risk assessment isn't just a DGSSI expectation — it's the same exercise that tells you where to spend your security budget first.
  • Encrypting personal data at rest satisfies CNDP expectations and closes off one of the most common ransomware extortion levers.
  • A regular penetration testing cadence is both a DGSSI-aligned control and simply good practice for any business handling sensitive data.

Where to start

Start with an honest inventory: what personal data do you hold, where does it live, and who can access it? From there, map your current controls against the gaps — technical and documentary — and prioritize by actual risk rather than by whichever requirement feels easiest to check off first. This guide is a starting point, not a substitute for reviewing the current DGSSI directives or CNDP guidance directly, or for legal counsel on your specific obligations.

Bridging the gap between technical reality and regulatory compliance

NetFortress helps Moroccan businesses align their cybersecurity program with both local regulatory requirements and international best practices — without treating compliance as busywork disconnected from real security.

Talk to Us About Compliance