Cloud computing has ceased to be an option and become a strategic necessity for organisations across all sectors. The gains in scalability, efficiency, resilience, security, and operational agility have made cloud computing one of the primary catalysts of digital transformation, enabling organisations to modernise infrastructure, optimise costs, and respond more effectively to business demands.
It is against this backdrop that Mozambique approved the Cloud Computing Regulation (Decree No. 72/2025) and the Data Centre Regulation (Decree No. 71/2025), establishing a new regulatory framework governing the use of cloud services and data centre infrastructure in the country. These regulations introduce specific requirements for registration, licensing, security, operational continuity, and data protection, with particularly significant implications for organisations operating in sectors deemed essential.
More than a regulatory change, this represents a significant shift in how organisations must approach the management of their digital infrastructure. In practice, compliance no longer depends solely on the technology used or the reputation of contracted vendors. It demands an integrated view encompassing data, applications, service providers, technology architecture, security, contracts, processes, and business continuity mechanisms.
The regulations also introduce new requirements related to the classification of cloud providers and data centres, as well as the sensitivity of the information they process. Certain sectors are subject to heightened requirements regarding the providers they may use and the levels of security and availability demanded.
For sectors considered essential, the new regulatory framework carries even greater weight. In these cases, the regulations establish specific requirements concerning the location of primary data centres, the use of appropriately classified infrastructure, and the implementation of robust security and operational continuity mechanisms.
But what does this mean in practice for organisations? One of the most significant aspects of the new regulatory framework is that responsibility for compliance no longer rests with the organisation alone. The new regulations place an increased burden on the entities that use these services. Ensuring internal compliance is no longer sufficient.
In practice, this responsibility translates into a set of areas that organisations must examine carefully: verifying the cloud provider’s legal representation in Mozambique; ensuring the appropriate category classification of the cloud service provider; implementing the enhanced security controls required for cloud services; guaranteeing that primary data centres are located on national territory; ensuring that secondary data centres meet the location, continuity, and recovery requirements defined by the regulations; and securing the security, resilience, and operational continuity of data centres.
The message is clear: compliance has become an end-to-end exercise. It is not enough for the organisation to meet its own internal requirements — it must equally ensure that the cloud services and data centres supporting its operations are aligned with applicable regulatory demands.
Compliance is no longer solely an organisational concern. It now depends on vendors also meeting their regulatory obligations. However, one of the greatest challenges for many organisations may lie not in the technology itself, but in identifying the interdependencies between different regulatory requirements. An organisation may believe it is compliant because it uses an internationally recognised cloud provider, yet still face non-compliance risks related to data localisation, information classification, adopted continuity mechanisms, or contractual clauses agreed with its suppliers.
It is precisely this combination of factors that makes compliance a more complex exercise than it may initially appear. In many organisations, the adoption of cloud services has occurred over several years, involving multiple vendors, different technology solutions, and diverse data types. As a result, a consolidated view of the actual level of regulatory exposure — or of the effort required to fully satisfy the new requirements — does not always exist.
Additionally, the regulations introduce new obligations in areas such as the maintenance of evidence, updating of records, contractual requirements, and oversight by the regulatory authority. Preparing for this new framework therefore requires a clear understanding of the technical, operational, and legal implications associated with each organisation’s technology model.
Despite the challenges, this new regulatory environment should also be viewed as an opportunity. Organisations that use this moment to review their technology architectures, strengthen security controls, increase operational resilience, and reinforce governance models will not only be better prepared to meet regulatory requirements — they will also be better positioned to accelerate their digital transformation in a sustainable manner.
Ultimately, ensuring compliance with the new Cloud and Data Centre Regulations is not merely a matter of legal obligation. It is about ensuring that technology continues to serve as an enabler of growth, innovation, and digital trust. Organisations that embark on this journey in a structured and timely manner will be better equipped to transform a regulatory requirement into an opportunity for value creation and a genuine competitive advantage.
Source: Diário Económico
Original article: https://www.diarioeconomico.co.mz/?p=531354











