Your devices secured, your access under control, your company ready for audit.
SafeRock IT manages Windows, Android, Mac and iPhone to the same standard for Moroccan companies. We prepare the technical part of your CNDP filings and the evidence your clients and auditors ask for. A team in Rabat and Casablanca, with engineering experience gained in the USA, for Morocco first, then the EU, Africa and the Gulf.
According to figures presented to Parliament by the minister in charge of the National Defence Administration, the DGSSI recorded 644 cyberattacks in 2024 and 879 in 2025. Here are six points we check first.
Your monitoring tools go through the CNDP
Cameras, GPS trackers, HR software, access control and MDM process your employees' data: depending on the tool, Law 09 08 requires a declaration or an authorisation before use.
We list what each tool collects and prepare the technical part of your filing.
Fingerprint time clocks: a purpose the CNDP excludes
The CNDP excludes the management of employee attendance time as a purpose for biometric processing (deliberation 478 2013).
We review your attendance tools and propose a badge or an app.
A lost phone is a security incident
Law 09 08 (Article 23) requires measures against the accidental loss of data.
Encryption, locking and remote wipe on Windows, Android, Mac and iPhone, backed by evidence.
Windows 10: no more free patches for your company PCs
Its support ended on 14 October 2025; Extended Security Updates are paid for businesses. About a quarter of Windows web traffic in Morocco still comes from Windows 10 (StatCounter, August 2026).
We inventory your PCs and plan your move to Windows 11.
Was your Microsoft 365 tenant created before 2019?
Tenants created before 22 October 2019 do not always have the security defaults, which include MFA for everyone and the blocking of legacy authentication.
We audit Microsoft 365, Google Workspace or Okta.
Supplier to a public administration? The DNSSI concerns you
By contract, it also covers providers who work on the systems of public administrations and infrastructure of vital importance: an inventory, an access review at least once a year, a leaver procedure, a mobile device policy.
We prepare the evidence they ask for.
Services
One team for your devices, your access and your audits
Device management
Windows, Android, Mac and iPhone enrolled, encrypted and patched to the same standard, with Intune, Android Enterprise, Jamf or your MDM.
Identity and access
Entra ID, Okta or Google Workspace; SSO, MFA, named accounts, automated joiners and leavers.
Security hardening
CIS configurations, patching, tested backups, secured Microsoft 365 and Google Workspace.
Preparation for compliance and certification
From the technical part of your CNDP filing to supplier questionnaires and the ISO 27001 audit.
Helpdesk and support
From first line to engineering, in French, English, Spanish and Arabic.
Advisory
Roadmaps, tool selection, part time IT leadership.
New offer, now launching
Your MDM, hosted where you decide
We deploy and run your device management platform, and place its data and backups in the location you choose.
Morocco
Your MDM database and backups stay on servers in Morocco; only technical flows, which we document for your CNDP filing, leave the country.
European Union
In an EU country recognised by the CNDP, we prepare the transfer notification with you.
Region of your choice
For your subsidiaries in Africa or the Gulf, following the local rule; for Moroccan data hosted outside the countries recognised by the CNDP, a CNDP authorisation or a legal exception is required.
Your servers
On your premises or in your cloud, with the access you grant us.
Some enrolment and notification services are still provided by the operating system vendors; we document these flows.
Three frameworks to know: Law 09 08, Law 05 20 and the rules of Bank Al Maghrib.
Law 09 08: declaration to, or authorisation from, the CNDP before a processing operation is put in place (cameras, geolocation, HR files, your MDM depending on what it collects); security measures and a contract with each provider that processes data on your behalf (Articles 12 and 23).
Transfers: notified to the CNDP even to a recognised country (deliberation 236 2015, which includes the EU except Croatia); elsewhere, a legal exception or a CNDP authorisation.
Law 05 20 and DNSSI: public administrations, infrastructure of vital importance and the providers of their sensitive systems; sensitive data of these bodies hosted exclusively in Morocco (Article 11); their use of the cloud for these systems governed by Decree 2 24 921.
Online sales platforms, cloud services and data hosting providers: technical logs kept for one year, and incidents with a significant impact reported to the DGSSI (Law 05 20, Articles 26 and 33).
Credit institutions: prior approval from Bank Al Maghrib to outsource significant functions to the cloud, an exit plan, audit rights (Directive 4/W/2022).
European Union
GDPR clauses, NIS2 questionnaires: what your European clients expect from a provider in Morocco.
GDPR: a data processing agreement with each provider that processes data on your behalf (Article 28). Morocco has no adequacy decision: for the European Data Protection Board, even remote access from Morocco is a transfer, most often covered by standard contractual clauses and a transfer impact assessment.
NIS2 (Article 21): your clients subject to NIS2 must take into account the cybersecurity practices of their direct suppliers. As of 1 October 2026, transposition laws apply in Belgium and Germany, among others; transposition is still incomplete in France and Spain.
DORA (Article 30): the contracts of financial entities must state where the service is provided and where the data is processed and stored.
A note on the CLOUD Act
This US law requires providers of electronic communication services or remote computing services that are subject to US jurisdiction to respond to warrants and orders from US authorities for data they possess or control, wherever that data is stored. Article 48 of the GDPR governs these requests: a judgment of a court or a decision of an administrative authority of a third country is recognised or enforceable only if it is based on an international agreement, such as a mutual legal assistance treaty, without prejudice to the other grounds for transfer under the GDPR. The EU US Data Privacy Framework remains valid; an appeal is pending before the Court of Justice of the EU.
Africa
One law and one authority per country; several regulate hosting data outside the country.
Tunisia (Organic Law 2004 63, INPDP) and Algeria (Law 18 07, amended in 2025, ANPDP): prior declaration, and the authority's authorisation for any transfer abroad.
Côte d'Ivoire (Law 2013 450, ARTCI): prior declaration, and authorisation for transfers to a third country.
Senegal (Law 2008 12, CDP): prior declaration, the CDP informed before any transfer, a reform under way.
Egypt (Law 151 of 2020, PDPC): a licence is mandatory, a separate licence for transfers, compliance expected before 1 November 2026.
Nigeria, Kenya, South Africa: registration with the authority, depending on the case. In Nigeria, sovereign data stays in the country (NITDA guidelines); in Kenya, a server or a copy of the data in the country for certain public sector processing, basic education and healthcare.
Gulf countries (GCC)
Saudi Arabia and the United Arab Emirates: recent laws, which also cover foreign companies that process residents' data.
Saudi Arabia: the PDPL has applied in full since 14 September 2024 under the supervision of SDAIA, whose committees issued 48 penalty decisions in 2025; data breaches must be notified within 72 hours.
Transfers outside the Kingdom are regulated: adequate countries, standard clauses, binding rules, risk assessment; registration with SDAIA in some cases.
NCA controls ECC 2:2024 and CCC 2:2024: mandatory for public entities and critical infrastructure, recommended for others. Under the CST cloud rules, government entities' data must not leave the Kingdom.
UAE: Federal Decree Law 45 of 2021 in force, implementing regulation awaited; separate regimes in the DIFC and ADGM free zones; health data kept in the country, with exceptions.
International standards
ISO 27001
ISO 27001:2013 certificates stopped being valid on 31 October 2025. We prepare your move to the 2022 version; the certification body issues the certification.
CIS
We harden your Windows, Android, Mac and iPhone devices against the CIS Benchmarks and the CIS Controls, and measure the gaps.
SOC 2
To sell in the USA: we prepare the technical controls and the evidence; the SOC 2 report is issued by an independent accounting firm licensed in the USA (CPA).
Information up to date as of 1 October 2026. General information, not legal advice.
Deliverables
What we deliver to you
Audit ready evidence
Reports on devices, patches, encryption and access.
Security policies
Adapted to your company.
An inventory
Of your assets and your access.
A data processing agreement
Signed with you.
Plans and method
From helpdesk to engineering
Level 1
Helpdesk
User support, passwords and MFA, device preparation.
Each plan is sized after a free discovery call. A migration or an audit preparation can be done without a support contract.
Our method
1
Discovery call
Your devices and your obligations.
2
Assessment
Devices, identities, access, providers.
3
Phased rollout
A pilot, then the switchover.
4
Operations and evidence
Monitoring, patching, monthly reports.
FAQ
Your questions, our answers
Which CNDP formalities apply to our cameras, GPS trackers and MDM?
In the workplace, video surveillance requires a prior declaration and vehicle geolocation a standard declaration, with retention limited to 3 months for images and one year for location data; some cases, such as healthcare establishments, require an authorisation. For the MDM, we work with you to describe what it collects, so that the right formality can be chosen. You submit the filing, as the data controller.
Do you issue ISO 27001 certification?
No. We prepare your company for the audit: gap analysis, technical measures, policies and evidence. The certification body you choose issues the certification.
Do you support our subsidiaries in Africa and the Gulf?
Yes, from Morocco: the same standard for devices and access, the formalities identified for each country, including for our team's access from Morocco, and your MDM hosted in the region when local rules require it.
In which languages is support provided?
In French, English, Spanish and Arabic, by our team in Rabat and Casablanca. Response times are those set in your contract.
Free discovery call
Let's talk about your devices and your obligations
Describe your devices, your tools and your hosting constraints. An engineer will reply, in French, English, Spanish or Arabic.