If your organisation runs electronic transactions in Guinea, you owe a security audit, and if you were already operating in May 2026 the practical deadline is around 21 November 2027.
Unlike the decree in the previous post, this one is not a press report. Décret D/2026/0159/PRG/SGG is published, numbered, in the Secretariat General’s registry, and we have read all eleven pages of it. Everything below comes from the text.
What it is
The decree governs the audit, control and certification of information systems. It is taken under articles 44 and 46 of Loi L/2016/035/AN of 28 July 2016, the electronic-transactions law, which is where ARPT’s authority over this area comes from. Article 24 makes it effective on signature.
It did not arrive alone. Two sister decrees were signed the same day: D/2026/0160/PRG/SGG, which adopts the technical reference framework audits are conducted against, and D/2026/0158/PRG/SGG, which creates a digital compliance levy and its associated platform and fund. The audit obligation is the one with a date attached.
Who it reaches
Article 4 covers every legally constituted public or private enterprise in Guinea carrying on electronic-transaction activity. Then it goes further, and this sentence is the one worth reading twice:
Sont également soumis au présent décret les prestataires établis hors du territoire guinéen qui offrent des services de transactions électroniques à des résidents en République de Guinée, dans les conditions fixées par décision de l’ARPT.
Providers established outside Guinean territory who offer electronic-transaction services to residents of Guinea are also subject to the decree, under conditions set by ARPT decision. Being incorporated elsewhere is not, on the face of the text, an exit.
Article 4 also carries a duty that is easy to miss because it is not about audits at all: an entity that ceases, suspends or transfers its electronic-transaction activity has 30 calendar days to tell ARPT.
The cadence
Article 5 sets a security audit every three years, with a tighter rhythm for entities ARPT classifies as high-criticality.
Pass, and article 13 provides for a certificate of conformity issued by ARPT. Fail, and the decree does not jump straight to penalties: a follow-up control is scheduled between three and twelve months later, and the audited body files a corrective action plan and implements it once ARPT has validated it.
That is a workable structure. The pressure only starts when nothing happens at all.
What happens if nothing happens
Article 16 comes first. Miss the audit and ARPT issues a formal notice giving you 30 days. If that expires, ARPT informs the sector authority and moves to articles 17 and 18.
Article 17 sets out two financial regimes, and states explicitly that they are not cumulative for the same facts:
A daily penalty payment. 50,000,000 GNF per day, running from the expiry of the article 16 notice, capped at 4,500,000,000 GNF. It stops as soon as the audit actually begins.
Or a punitive fine. Proportionate to the seriousness of the breach and to any advantage gained from it, capped at 3,000,000,000 GNF, and doubled in the event of a repeat.
Those are the figures in the text. The daily penalty is the one to plan against, because it accrues on the calendar rather than on a decision, and the thing that stops it is starting the audit — not finishing it.
The date
Article 23 is the transitional provision. Entities already carrying on electronic-transaction activity when the decree entered into force get 18 months to come into full compliance. Counted from 21 May 2026, that lands around 21 November 2027. An operator that has not completed a first audit by then falls directly into articles 17 and 18.
One caution on that arithmetic. The Secretariat General’s registry dates the decree 21 May 2026. ARPT’s own page shows 22 June 2026, which appears to be ARPT’s posting date rather than the signature date. The registry is the record of authority, so 21 November 2027 is the figure to work from — but the discrepancy is worth confirming with counsel before you set an internal milestone on it, because it moves the deadline by a month.
What is not settled yet
Two things the decree promises but does not itself contain, and both are load-bearing.
The criticality classification. ARPT is to publish a classification of entities by criticality level, together with differentiated rules by size, nature and volume of activity. Until it does, you cannot know which tier you are in, and therefore cannot know whether the three-year cadence or something tighter applies to you.
The conditions for approving auditors. ARPT is also to publish the conditions under which audit providers are approved. Until then, there is no published list of who can perform an audit that counts.
Article 23 places both inside the 18-month window, which is a sensible design and an uncomfortable one: the clock runs while the details arrive.
What to do this year
Establish whether article 4 reaches you. Broadly, if your organisation does business electronically in Guinea, or serves Guinean residents from abroad, assume it does until counsel tells you otherwise. The foreign-provider clause is explicit, and its practical conditions are left to an ARPT decision that has not been published.
Write down the 30-day notification duty. It is the easiest obligation in the decree to breach by accident, because it triggers on a business event nobody thinks to route past compliance.
Do the work an audit would find, before an auditor does. Access control, logging, backups, incident response, who holds which key. None of that waits on the criticality classification, and all of it is what a first audit will look at.
Budget for it in the 2027 cycle, not the 2028 one. Approved auditors will be a small population in the first year, and everyone will be looking for one at the same time.
Watch ARPT for the two missing decisions. Their publication is what turns the general obligation into a specific one for your organisation.
The honest caveat
This post describes what a published decree says. It does not tell you whether it applies to your organisation, what tier you would be classified in, or what a satisfactory audit would look like for you. Those are questions for Guinean counsel and for ARPT itself, and the parts that are genuinely unsettled are unsettled for everyone right now, including every provider you might ask.
General information, not legal advice. Contact reaches a person if you want to talk through what the audit obligation would mean for your setup.

