Morocco today

Prisons in Morocco: What the 2.75 Million Dirham IT Contract Includes

In 2026, Morocco’s prison administration prepared a nearly 2.75 million dirham acquisition of data storage and processing equipment, with implementation planned over three months.

By LMOS editorial team
Morocco news

The General Delegation for Prison Administration and Reintegration (DGAPR) prepared an acquisition of IT equipment dedicated to data storage and processing in 2026. The reported estimated budget for this operation is close to 2.75 million dirhams.

This project signals an effort towards technical modernisation, but three stages must be distinguished: announcing or publishing a contract, awarding it to a service provider, and then accepting an infrastructure that is actually operational. The information available when this article was verified mainly describes the need and the expected equipment; it is not sufficient to assert that the entire budget has already been spent or that data security is now guaranteed.

What can be confirmed

According to the case documents reviewed and reported by TelQuel on 24 March 2026, the operation involves the acquisition and commissioning of a storage solution. Its estimated value is stated at around 2.7 to 2.75 million dirhams, and the announced implementation period is three months.

The lot notably includes rack-mounted servers, a Full Flash NAS storage array, SSDs intended for professional use, and the accessories required for their installation. The equipment must be delivered new and integrated into the administration’s infrastructure.

This information supports describing it as an equipment project or an IT contract. On its own, it does not support announcing a complete transformation of all Moroccan prisons.

An estimated budget is not an executed expenditure

In a public contract, the budget estimate sets an approximate value for the tender. The amount ultimately committed may depend on the selected bid, the award conditions, and the execution of the contract.

Using the verb “invest” in the past tense can create the impression that the equipment has been delivered, paid for, and verified. Establishing this would require the award notice, the contract, the acceptance reports, and, ideally, an operational assessment.

The most accurate wording therefore remains: the DGAPR planned or launched an acquisition with a budget estimated at nearly 2.75 million dirhams. Any future update should specify the award date, the successful bidder, and the outcome of the acceptance process if this information becomes public.

What is a Full Flash infrastructure used for?

A Full Flash system stores data on electronic SSD media rather than on traditional mechanical drives. It can reduce access times and improve performance when many users or applications request the same information.

Within an administration, this improvement can facilitate access to files, the operation of business applications, server virtualisation, or the consolidation of several storage spaces. Actual performance nevertheless depends on the complete architecture: network, controllers, software, capacity, redundancy, and integration quality.

The word “flash” does not automatically mean that the solution is invulnerable, always available, or properly backed up. It primarily describes a storage technology.

Performance, availability, and security are three different issues

A fast infrastructure can remain vulnerable to human error, a failure, malware, or unauthorised access. Availability requires redundant components, monitoring, and procedures that allow service to continue when a component fails.

Security requires other controls: identity management, restricted access rights, logging, appropriate encryption, updates, network segmentation, and incident detection. Backups, meanwhile, must retain separate copies and enable tested restoration.

The purchase of servers or arrays does not prove that all these measures exist. It provides a hardware component that must fit into a broader technical and organisational policy.

Why prison data is particularly sensitive

A prison administration handles information that may concern the identity, legal status, health, movements, communications, or reintegration programmes of incarcerated people. Unavailability can disrupt the operation of facilities; unauthorised disclosure or alteration can harm individuals and the institution.

Confidentiality is therefore not the only concern. Data integrity — preventing alteration — and availability to authorised staff when needed must also be guaranteed.

The level of detail made public must itself remain cautious. Precisely describing the architecture, access points, or defence mechanisms of a sensitive system could create new risks.

Morocco’s cybersecurity framework

Moroccan Law No. 05-20 on cybersecurity establishes a framework intended to strengthen the security and resilience of public administrations’ information systems. The General Directorate of Information Systems Security (DGSSI) also publishes a National Information Systems Security Directive.

This directive covers organisational and technical measures: governance, risk management, protection, continuity, auditing, and incident handling. It reiterates that equipment is no substitute for risk analysis or the responsibility of the parties involved.

The DGSSI also publishes guides on data classification and business continuity. These references make it possible to assess an IT project beyond its speed or price.

Data protection and the DATA-TIKA programme

The National Commission for the Control of Personal Data Protection (CNDP) and the DGAPR announced a collaboration under the DATA-TIKA programme in 2021. It followed the distribution of videos from the prison environment that could affect privacy.

The statement provided for strengthening oversight of data use and personal data management within the prison administration. This precedent shows that technical modernisation must be accompanied by rules on purposes, access, retention, and the protection of individuals.

Law No. 09-08 constitutes Morocco’s general framework for personal data protection. Its application to certain data relating to prevention, law enforcement, or specific legislation involves particular rules. It would therefore be excessive to reduce compliance to the purchase of a storage system.

What the project does not yet demonstrate

The available information does not support asserting that all prison facilities will be connected to a single platform, that the data will be hosted in a specific location, or that every inmate file will be migrated immediately.

Nor does it prove the installation of specific firewalls, a five-year maintenance period, or the systematic use of a particular processor and memory model. These claims require the complete specifications or an official acceptance document.

Finally, an IT infrastructure measures neither the quality of reintegration, nor detention conditions, nor access to healthcare. It can support management, but it does not replace public policies and their evaluation.

Indicators to monitor after the award

The first verification concerns the administrative process: award, contractual amount, timeframe, and acceptance. Next come the technical results, which can be assessed without publishing sensitive information.

Useful indicators include application availability, restoration times, the frequency of backup tests, vulnerability management, and staff training. A security audit conducted according to the applicable framework provides more information than a simple commercial fact sheet.

Service continuity deserves particular attention. A backup has value only if it can be restored; a recovery plan is credible only if it is tested regularly.

Modernisation to be assessed over time

The acquisition planned by the DGAPR may improve the capacity and performance of its digital infrastructure. It forms part of an environment in which administrations must strengthen their resilience and protect particularly sensitive information.

The appropriate interpretation nevertheless remains cautious: nearly 2.75 million dirhams corresponds to a documented contract estimate from spring 2026, not to a security certification or an implementation assessment.

What follows must be judged on evidence: an awarded contract, accepted equipment, controlled integration, restorable backups, and measured compliance and continuity. Only under these conditions does an IT purchase become sustainable public service modernisation.

Verified sources