Summary
- Cilix Software is a verifiable Mozambican company and network operator, not merely a reseller’s brand: the corporate gazette, the communications regulator and AFRINIC-linked routing records connect the same business to a 2004 registration, AS37556 and named local technical leadership.
- Its most defensible proposition is a reduction in operational handoffs. Cilix offers a chain that can include business connectivity, private or public cloud, backup, monitoring, site-reliability work and application modernisation. That can lower coordination cost, but it also concentrates knowledge and makes responsibility boundaries unusually important.
- Independent evidence shows real, if narrow, delivery: United States government spending records identify Cilix internet-service awards, while a Swiss-commissioned evaluation recorded Cilix performing daily and weekly cloud backups for a Mozambican microbank. Neither source proves the full breadth, scale or current service quality of the public catalogue.
- Mozambique’s cloud and data-centre regulations now make location, service levels, incident notification, retention and exit strategy contractual issues. Cilix’s public material does not disclose enough to establish facility classification, current licensing, restore performance, security assurance, price structure or route diversity; buyers should require evidence for each.
A Failure That Makes the Supplier Map Visible
Imagine a failure at 02:17 on a payroll night. The customer’s application is reachable, but transactions are not completing. A monitoring console reports healthy virtual machines. The database has stopped accepting writes. The most recent backup job is marked successful, although nobody has restored that copy into an isolated environment. The primary office circuit is up; the path to a third-party cloud is not. None of this describes a known Cilix incident. It is a procurement thought experiment, and it exposes the product that a managed-service customer is really buying.
One ticket could cross at least seven control surfaces: the customer’s application, the operating system and database, Cilix’s virtualisation layer, Cilix’s managed-service team, a local access circuit, a third-party fibre or transit provider, and a public-cloud or software platform. Add backup storage, identity management and a secondary data-centre site and the map grows again. Every component can be functioning according to its own narrow dashboard while the business service remains unavailable.
Cilix Software is interesting because it offers to compress much of that map into one commercial relationship. Its website groups cloud strategy and migration, private cloud, backup, connectivity, monitoring, site-reliability engineering and development services under the same name. In a market where a customer may otherwise coordinate a carrier, a facility, a systems integrator, several software vendors and an offshore cloud help desk, a local accountable party can be economically valuable. The saving is not only technical. It is fewer contracts to interpret, fewer escalation queues and less time spent proving which supplier should act first.
That convenience creates its own hazard. A bundle can hide the difference between infrastructure Cilix owns, capacity it leases, platforms it operates, products it implements and systems for which it merely provides first-line support. When a contract says “managed,” the customer still needs to know who can change a firewall rule, recover a key, replace a failed disk, reroute a circuit, restore a database and approve a production rollback. The central thesis of this assessment is therefore narrower than the familiar claim that local cloud is good for sovereignty or latency.
Cilix’s advantage, if it can prove it, is a local responsibility surface. Its risk is that the surface becomes a black box.
The timing matters. Mozambique’s new rules for cloud services and data centres turn several of those questions from optional diligence into explicit contracting and operational requirements. The best way to evaluate Cilix in 2026 is not to count the services in its catalogue. It is to follow one restore ticket from detection to business recovery, and then follow one customer’s data all the way out.
The Cilix Name Resolves to a Mozambican Operator
The identity bridge is strong enough to analyse the assigned company without substituting a similarly named brand, affiliate or network label. An official Mozambican corporate gazette published in August 2018 records Cilix Software, S.A. under NUEL 16484, traces its registration to September 23, 2004, and documents a May 2018 decision to change the company type from a limitada to a sociedade anónima. That is the legal anchor.
The communications record supplies a second bridge. The INCM consumer portal’s operator list includes “CILIX SOFTWARE, LIMITADA” as a data-transmission service operator and links to cilix.co.mz. Its legal form and address are historical, which is consistent with a list that was not updated after the 2018 conversion; the shared name, service and domain make it evidence of continuity, not evidence of a second Cilix. The list should not be treated as proof of every licence the business may need under regulations introduced years later.
The network record supplies a third bridge. AFRINIC-derived WHOIS and live BGP information for AS37556 names Cilix Software, identifies the organisation as ORG-CS9-AFRINIC in Mozambique and gives João Leopoldo and Leontina Malaze as administrative and technical contacts. Cilix’s current leadership page identifies João Leopoldo as chief technology officer and Leontina Malaze as chief network officer. The latter biography says she has spent eight years managing Cilix’s ISP network, service delivery, service-level compliance and customer care. Corporate, regulatory, network and operating records therefore converge on the same Mozambican business.
Current public-facing details have moved over time. Cilix’s LinkedIn company page describes a privately held company founded in 2004, with 11–50 employees and a current Maputo address in the Maryah Building. AFRINIC WHOIS retains an older JAT building address, while the INCM list has an earlier address again. Address drift is normal over two decades, but a buyer should contract with the current legal entity and verify its tax number, registered office, signing authority and applicable licences rather than copying a directory entry.
This evidence proves identity and operational continuity. It does not prove financial capacity, ownership of every advertised asset, certification status, customer satisfaction or the performance of any specific service. Those are separate claims requiring separate evidence.
What Cilix Is Actually Selling: Fewer Handoffs
Cilix’s catalogue spans four broad layers. Connectivity includes dedicated internet, Ethernet and wide-area networking, dark fibre, wavelengths and cloud connections. Infrastructure includes private compute, bare metal, storage, hybrid-cloud design and backup. Operations include monitoring, cloud management, incident work and site-reliability practices. The application layer includes development teams, modernisation, OpenShift and a core or digital-banking proposition. The catalogue is broad enough that “Cilix customer” can describe very different relationships.
At the simplest end, the customer buys a circuit. Public procurement evidence shows that this is not hypothetical. At the more integrated end, a customer might ask Cilix to assess existing servers and applications; decide which workloads remain on premises and which move to Cilix, AWS, Azure or IBM; build private connectivity; migrate data; operate virtual infrastructure; monitor applications; maintain backups; and provide local support. Cilix’s migration page expressly presents Cilix, AWS, Azure and IBM as possible destinations, including hybrid and multicloud combinations. That is a company claim about scope, not proof of a particular partnership tier or deployment.
The customer workflow should begin before a platform is selected. It starts with an inventory of applications, owners, users, data classes, interfaces, licences, recovery requirements and regulatory obligations. A serious assessment also measures current latency, failure rates, capacity peaks, patch status, unsupported components and the actual time needed to rebuild a service. Only then can a target design separate workloads suited to local private infrastructure from those that benefit from a public cloud’s managed services or geographic reach.
Implementation follows a dependency order. Identity and key management come before production access. Network routes, name resolution and time synchronisation come before application cutover. Backup policy comes before migration, because a migration without a tested recovery point is an irreversible experiment. Observability must cover the end-to-end business transaction rather than only virtual-machine health. Acceptance should include load, failure, security and restore tests. Runbooks, escalation contacts and change authority must be agreed before the first production incident.
After cutover, the service becomes a recurring operating process. Cilix’s cloud-management page says it provides unified monitoring across hybrid environments, 24-hour support and a governance portal covering requests, incidents, changes, availability, performance, invoices and reports. Its site-reliability offering describes capacity planning, stress testing and continuous reliability work. Those are the right categories. The procurement question is whether they appear as measurable deliverables: named dashboards, agreed service indicators, change windows, error budgets, escalation times, monthly capacity forecasts and post-incident reviews.
The economic value of the bundle is coordination. If the same team can see the circuit, the virtual host, the backup job and the application trace, diagnosis can start with shared telemetry rather than supplier argument. The corresponding concentration risk is operational memory. The more Cilix learns about undocumented dependencies and emergency workarounds, the harder it becomes for the customer or a replacement provider to operate the system. Documentation, customer access and exit rehearsal are therefore part of the product, not administrative extras.
From Circuit to Application: The Architecture Behind the Bundle
Cilix’s public material describes a plausible hybrid architecture, but not one standard architecture. Its private-cloud page says virtual machines run across redundant physical hosts and can be moved to another host after a failure. It also offers bare-metal servers and network- or API-accessible storage. This establishes the intended service model. It does not disclose the hypervisor in production, storage replication design, failure domains, oversubscription, power topology, patch cadence, management-plane separation or usable capacity.
The backup layer can span local and external infrastructure. Cilix says its cloud-backup service can protect bare metal and common databases, place copies on Cilix systems and in AWS or Azure, use dedicated buckets or geographic replication for retention beyond 30 days, encrypt stored files, deduplicate data, monitor jobs around the clock and re-run failed jobs. It also describes consumption-based charging. Each statement is useful as a design lead. None substitutes for a customer-specific recovery point objective, recovery time objective, retention schedule, immutability control, key-custody model or successful restore record.
Connectivity joins the layers. Cilix advertises dedicated internet of up to 1 Gbps and three points of presence in Maputo and Matola. Its dark-fibre page says it uses both its own network and third-party networks, with customer-specified routes and tailored restoration commitments. This qualification is important: a service sold by Cilix may depend on fibre it does not own. Route diversity must therefore be demonstrated at duct, building-entry and upstream levels. Two commercial circuits that share a trench, pole route, meet-me room or upstream are not two failure domains.
At the software-platform layer, Cilix markets managed cloud operations and monitoring, including a stated Dynatrace partnership. Its website also displays platform names and describes OpenShift and public-cloud work. Logos and product descriptions are evidence of what the company wants to sell, not of current certification, authorised-reseller status, support entitlement or the right to escalate directly to a vendor. A buyer should ask for the exact contracting chain: who holds each subscription, who can open a priority-one case, which support plan applies, which party pays unexpected consumption, and what happens to licences when the managed-services agreement ends.
The application layer increases both value and ambiguity. Cilix’s core and digital-banking page describes a cloud-agnostic, containerised, API-centred platform with 1,500 atomic financial operations, 5,000 workflows and a deployment that may take less than three months depending on scope. The page does not name the software producer, a live customer, a version, audited transaction capacity or an implementation boundary. The claims should be read as a product proposition, not as proof that Cilix developed the core or that a bank can safely replace its system in a quarter.
One useful architectural device is a responsibility matrix with four verbs for every component: design, operate, secure and recover. Cilix may perform all four for a local virtualisation cluster, only operate and monitor an AWS workload, coordinate but not repair a leased fibre segment, and provide first-line support for a third-party banking platform. A customer that maps those verbs can see gaps before an outage. A customer that buys a single label—“managed cloud”—may discover the gaps during one.
AS37556 Proves a Network, Not a Nationwide Backbone
Public routing data provides an unusually concrete view of Cilix’s operating surface. As observed on July 17, 2026, bgp.tools reported AS37556 as active, allocated under AFRINIC and originating four visible IPv4 routes: the aggregate 197.231.216.0/22 and three more-specific routes within that space. It showed no originated IPv6 route. The RIPEstat announced-prefixes feed independently showed the same four routes during its observation window.
This proves that Cilix controls an autonomous-system presence and originates public address space. It does not reveal customer count, domestic fibre kilometres, available capacity, latency guarantees or the physical location of every service. Nor does a BGP neighbour graph equal a supplier contract. At the evidence freeze, both bgp.tools and RIPEstat exposed Webmasters, AS37697, as the only visible adjacent network. Collector visibility is incomplete, private interconnections may not appear, and commercial or physical redundancy cannot be inferred from one public graph. The correct conclusion is not that Cilix has only one carrier.
It is that a buyer cannot prove diverse transit from the public record and should request route diagrams, carrier letters, last-mile maps and failover-test results.
There is a second discrepancy worth testing. Cilix’s dedicated-internet page says its backbone runs IPv4 and IPv6 simultaneously in a full mesh, yet current public observation showed zero IPv6 announcements from AS37556. An internal IPv6-capable network can exist without originating public IPv6 space, so the two facts are not necessarily contradictory. They do mean that a customer requiring public dual-stack service should ask for an assigned prefix, routing policy and acceptance test rather than rely on the catalogue.
Routing hygiene is another procurement signal. RIPE’s validator returned “not-found” for each observed Cilix route at the freeze, meaning no Route Origin Authorisation covered the aggregate or its visible more-specifics. “Not-found” is not “invalid”: networks that enforce route-origin validation will generally treat the routes as unknown rather than reject them. It does mean the public route origin lacks that cryptographic authorisation layer. AFRINIC-derived WHOIS also displayed no registered abuse contact for the ASN. Neither finding proves an insecure service, but both are inexpensive, observable controls that a security-conscious operator can explain or improve.
The sharpest boundary between current asset and ambition appears in Cilix’s 2026 Mozambique–EU Business Forum investment pitch. The company proposes a roughly 3,500-kilometre, resilient-ring national backbone connecting six cities, beginning at 100 Gbps per segment and scaling to 400 Gbps. It lists a project cost and financing need of €39 million. Because the page explicitly calls this a project pitch seeking debt, equity or grant funding, it is evidence of planned expansion, not evidence that Cilix already owns that national backbone. Any tender must separate the network in service today from the network that may be built tomorrow.
The Backup Customer Is Buying a Restore
Backup is where Cilix’s responsibility proposition becomes tangible. A successful job means that software read some source data and wrote some target data. Recovery means that the right version can be found, decrypted, transferred, reconstructed, started, validated by the application owner and returned to service within the promised time. The gap between those two conditions contains most of the risk.
Cilix’s backup page offers meaningful ingredients: application-aware protection for common databases, geographic copies, encryption, monitoring, deduplication and re-execution after a failed job. What it does not publish is more decisive. There is no public matrix of recovery times by data volume, no stated recovery-point commitment, no evidence of immutable or logically isolated copies, no key-ownership description, no clean-room recovery procedure, no published restore-success rate and no schedule of customer-witnessed exercises. These may exist in private service documents; they are simply not established by the public record.
An independent source shows the service has been used in a real workflow. A Swiss Cooperation Office-commissioned external evaluation of Futuro MCB, based on work through 2023, described the microbank’s three recovery practices. It recorded local daily copies, a weekly disk kept by a director, and cloud recovery through Cilix, with servers in Maputo and Matola and daily and weekly backups. That is valuable evidence because it names the customer context, workload purpose, locations and frequency. It does not report a restore test, outage, recovery time, contract value or current continuation of the service.
The example also shows why geography alone is limited public evidence. Maputo and Matola can be distinct sites, but a buyer must test whether they share power dependencies, flood exposure, fibre routes, identity systems, management credentials or administrators. A ransomware event can reach two geographically separated repositories if both accept deletion through the same privileged account. A regional power or connectivity failure can affect both if the design shares upstream dependencies. Geographic replication is a useful control only when logical and operational separation are also understood.
A sound acceptance test starts with a declared failure. The customer selects a representative database and a point in time, disables access to the original environment, and asks the service team to recover into an isolated network. The clock continues until the application owner—not the storage console—confirms record consistency, authentication, interfaces and required reports. The exercise records the people involved, manual steps, missing credentials, transfer rates, actual data loss and actual time to resume. It then tests a second scenario in which Cilix’s normal administration plane is unavailable.
The commercial schedule should price this outcome. Storage consumption, retention and software components are only inputs. A buyer should know how many assisted restores are included, whether drills are chargeable, what data retrieval or public-cloud egress costs apply, who supplies temporary recovery compute, and whether emergency work attracts a premium. If nobody has budgeted for the restore, a cheap backup can become an expensive surprise precisely when bargaining power is weakest.
Mozambique Has Turned Good Procurement into Contract Law
Two decrees published on December 31, 2025 changed the diligence baseline. Decree 71/2025, the Data Centre Regulation, entered into force 90 days after publication. It requires registration and licensing of data-centre operators and facilities and creates four facility categories—Advanced, Standard, Limited and Basic—based on resilience and redundancy. It also addresses physical security, access records, incident plans and exercises, logical and physical redundancy, service levels and insurance. Existing operators and facilities receive one year from entry into force to adapt.
The regulation is especially consequential for essential services, a definition that includes public administration, health, education, energy, electronic communications, transport and finance. Their primary data centres must be in Mozambique, and facilities serving them must be Advanced or Standard. A foreign secondary site can be used with regulatory authorisation. For Cilix, public statements about a Maputo data centre or a two-city backup design are therefore the beginning of a compliance inquiry, not its conclusion.
A regulated customer should request the operator registration, facility licence, category, exact licensed address and any transition plan applicable to its service.
Decree 72/2025, the Cloud Computing Regulation, is even closer to the restore-ticket thesis. It covers cloud providers active in Mozambique whether or not they are established there. It requires security planning, real-time monitoring of suspicious activity, penetration testing at least annually, encryption in transit and at rest, multifactor authentication, vulnerability controls, incident response, record retention and civil-liability insurance. Existing cloud providers also receive a one-year adaptation period.
Article 22 makes the cloud contract a technical control. Written agreements must include a complete service description; service and data-processing or storage locations; technical-compliance provisions; detailed service levels and performance targets; termination grounds and notice; event-notification periods; post-termination data retention; whether a cancelled account can be reactivated; and exit strategies with a migration period. The rules also preserve a period for data access and portability when a provider’s registration or licence is suspended, cancelled or extinguished.
This is close to a statutory version of the responsibility and exit maps a careful buyer should already demand.
The wider cyber framework is moving at the same time, but its dates must be stated precisely. Mozambique published Cybersecurity Law 13/2026 and Cybercrime Law 14/2026 on July 1. According to INTIC’s official notice, they enter into force on September 29, 2026—after this article’s publication date. They are enacted but not yet operative at the evidence freeze. A comprehensive personal-data law is also not established as current law: the Council of Ministers approved a personal-data protection bill for submission to parliament in March 2026.
Regulatory transition creates an opportunity for Cilix. A local provider that can turn new requirements into a documented, auditable service may be more useful than a remote platform whose standard contract does not answer a Mozambican customer’s facility and sector questions. It also creates exposure. Broad marketing promises must now resolve into licences, locations, security evidence, incident duties and portable data.
The Security Question Sits in the Control Plane
The most important security boundary in a managed hybrid environment is often not a rack or a firewall. It is the control plane through which administrators create machines, change routes, read logs, reset credentials and delete backups. Cilix’s breadth gives its team potential visibility across several layers; that can accelerate defence, but a compromised privileged account could also have unusually broad reach.
A buyer should begin with identity. Are Cilix personnel issued individual accounts in the customer environment? Is access time-bound and approved per change? Does strong multifactor authentication apply to cloud, hypervisor, backup, network and monitoring consoles? Are emergency accounts vaulted, tested and reviewed? Can the customer export immutable administration logs to a security domain Cilix cannot alter? A statement that files are encrypted is incomplete unless the parties identify who controls keys, who can decrypt a recovery copy and how key loss or administrator departure is handled.
Backup needs a separate trust boundary. At least one recoverable copy should resist deletion through the ordinary production administration path. Network management, virtualisation and backup credentials should not all depend on one directory. Recovery documentation and critical keys need an offline or independently controlled copy. The annual penetration tests required by the cloud regulation should cover exposed services and management interfaces, but a summary of scope, severity and remediation is more useful to a customer than a bare assertion that testing occurred.
Network controls are part of the same picture. The absence of a covering RPKI authorisation and a public abuse contact are not evidence of compromise. They are watchpoints about route-origin protection and reporting hygiene. A procurement team can ask whether Cilix has a route-security roadmap, filters customer announcements, protects routing sessions, maintains out-of-band access, participates in a computer-security incident response process and measures time to contain malicious traffic.
Cilix’s public privacy policy creates a different documentation question. It is framed around Brazil’s LGPD, refers to Brazil’s data-protection authority, selects São Paulo law and forum, and discusses Brazil-oriented transfer language. A website privacy notice is not an enterprise data-processing agreement, and this text does not prove how a Mozambican managed service handles customer data. It does show why a buyer should not treat the website notice as the governing document. The contract needs a Mozambique-specific data map, roles, subprocessors, cross-border locations, breach process, deletion proof and precedence clause.
Financial-sector customers have additional evidence needs. The Bank of Mozambique’s 2025 cyber-risk self-assessment circular requires institutions to submit a remediation plan with measures, deadlines, owners and supporting documents. Its technological and cyber-incident notice standardises detection, reporting, mitigation and recovery. Any Cilix service used by a bank must produce evidence the bank can use in those processes; a managed-service dashboard cannot be a closed supplier view.
Local Support Is a Product That Must Be Measured
Local support is Cilix’s most intuitive advantage over a remote platform, yet it is easy to leave undefined. The company says it provides 24-hour support for backup and cloud management, operates a network-operations centre and supplies customer-facing governance information. Its leadership description assigns service delivery, service-level compliance and customer care to the chief network officer. Those statements indicate an operating organisation rather than a catalogue with no local team.
Hiring evidence adds texture without proving the installed estate. A current systems-administrator vacancy asks for Linux and Windows administration, VMware, Hyper-V or Proxmox virtualisation, SAN and NAS storage, Veeam or similar backup, hardening, incident resolution and monitoring tools such as Zabbix, Grafana, OpenSearch, Nagios or Datadog. A field-engineer vacancy covers installation, configuration, maintenance, customer training and travel. These are role requirements, not confirmation that each named product runs in Cilix’s cloud. They do support the inference that local infrastructure and field work are material to delivery.
Support quality still needs measurement. A contract should distinguish response, engagement, workaround, restoration and permanent resolution. It should define severity in business terms, not merely device status. It should name the staffed hours for each role, after-hours escalation path, language coverage, on-site response area, spare-parts responsibility and authority to contact third-party vendors. The buyer should see anonymised ticket statistics and conduct an escalation drill before production.
Team concentration also matters. Public sources describe an organisation in the 11–50 employee range while advertising a wide technical surface. That does not establish understaffing; small expert teams can be effective. It does make succession, on-call depth and simultaneous-incident capacity legitimate questions. The customer needs to know whether two critical services depend on the same specialist and how knowledge is transferred when personnel change.
Pricing the Bundle Without a Price List
Cilix does not publish a general enterprise price list in the reviewed material. Quote-based pricing is normal for circuits, migrations and managed infrastructure because access construction, capacity, workload size and support scope vary. It also means a customer cannot compare offers until the cost model has been decomposed.
The likely stack contains at least seven charge families. Connectivity may include installation, a last-mile tail, port capacity, committed bandwidth, public addresses and route diversity. Private cloud adds reserved compute, memory, storage performance, licences and data protection. Public cloud adds metered compute, storage, managed services and egress. Backup adds protected capacity, retention, application components, replicated copies and restore work. Managed service adds monitoring, service desk, administration and specialist hours. Migration adds assessment, data transfer, testing and cutover.
Application work adds development, platform subscriptions and continuing maintenance. This is an inference from the advertised architecture, not a disclosed Cilix tariff.
Historical government awards offer a reality check, not a current price card. USAspending award 72065623P00047 records $19,200 to Cilix Software S.A. for internet services at the USAID mission director’s and temporary-duty guest house, with a performance period from September 2023 to September 2025. An earlier award records $15,000 for 10 Mbps internet at two residences, and another records $16,007.69 for a 20 Mbps service at the JAT building. Award values can include different periods, locations and terms; they should not be divided into an implied monthly tariff without the underlying contract.
A comparable quote should show units, quantities and adjustment rules. It should separate one-time implementation from recurring service, identify foreign-currency components, state tax treatment, cap or alert on consumption, and model normal growth plus a recovery event. Public-cloud egress and emergency recovery compute are especially important because they arise when a customer has little choice about spending. Service credits should not be the only remedy for a failure that costs far more than the monthly fee.
The €39 million backbone proposal also illustrates capital logic. If Cilix raises and deploys that investment, its network economics and available routes could change materially. Until then, customers should price the service against current assets and binding supplier commitments. They should not prepay for an aspirational footprint unless milestones, security and remedies are explicit.
The Exit Test Reveals the Real Switching Cost
Every layer in Cilix’s bundle creates a different switching cost. A dedicated circuit may require a new building entry, router configuration, public-address change and domain-name cutover. Dark fibre may carry long commitments and customer optical equipment. Virtual machines are portable in principle but can depend on a specific virtual network, storage performance, backup format and licensing model. A container platform reduces some infrastructure coupling while leaving identity, secrets, observability, registry and operator practices to migrate.
Managed service creates knowledge lock-in. Cilix staff may learn which nightly task must finish before a branch opens, which interface fails after a certificate change and which undocumented script reconciles a report. If those facts live only in tickets or individual memory, replacing the provider becomes a discovery project. Application modernisation can deepen the dependency when the same supplier writes code, operates the platform and monitors production.
Backup has a particularly sharp exit edge. The customer needs an inventory of every retained copy, its format, encryption method, key owner, location and deletion date. It needs enough bandwidth and time to export the data, plus software capable of reading it after the contract ends. Deduplication can reduce stored capacity while making a repository less useful outside the original system. A contractual promise of “portability” is not complete until a sample export and independent restore have worked.
Mozambique’s cloud regulation now requires exit strategies and a migration period in the written contract. A strong schedule would go further: export formats, data-transfer rate, assistance hours, continued security and backup during transition, licence handover, configuration and log exports, credential rotation, deletion certificates, maximum fees and cooperation with the successor. It should preserve a read-only period long enough to compare results.
The exit test is also a buying test. Before signing, ask Cilix to demonstrate how one virtual workload, one database backup, one month of logs and one network configuration would be handed to another competent provider. If the answer is clear and inexpensive, the managed relationship is more trustworthy. If the answer depends on tools, keys or knowledge the customer cannot access, the apparent convenience has already become leverage.
Customer Evidence Is Real but Narrow
The public customer record supports two parts of Cilix’s proposition. USAspending identifies repeated internet-service procurement by USAID from 2019 onward, including services at multiple Maputo locations. Those records verify the legal supplier name, a demanding institutional buyer, actual connectivity delivery and order-of-magnitude historical award values. They do not disclose uptime, complaints, competitive evaluation, route design or whether the services remain active after the recorded end dates.
The Futuro MCB evaluation verifies a more complex use: recurring cloud backup in Maputo and Matola for a regulated microbank. It is stronger than an anonymous testimonial because it describes the bank’s wider recovery workflow and was prepared for an external public institution. Yet the evaluation also illustrates the limit of supplier inference. It discusses weaknesses in the bank’s core system and manual processes, but it does not attribute those problems to Cilix. Cilix’s identified role was backup.
It would be wrong to treat the document either as proof of Cilix’s whole banking catalogue or as evidence that Cilix caused the bank’s application difficulties.
Cilix and local media have also associated the company with financial-sector technology discussions. A 2018 Mozambican news report covered Cilix and SAS presenting risk and fraud tools to financial institutions. That establishes an event and partner context, not a named deployment or measured result.
The evidentiary gap is therefore not “no customers.” It is the absence of detailed public case studies across the current portfolio. A useful reference would specify the workload, starting condition, architecture, Cilix-owned and third-party components, migration duration, measured availability, recovery exercise, security scope and customer-approved outcome. Until those exist, a buyer should request references closely matched to its own service rather than accept a general list of organisations.
Competition Comes from Both Facilities and Platforms
Cilix competes on several fronts at once. A customer can buy public cloud directly from AWS, Azure or IBM and hire separate local connectivity and support. It can keep compute on premises and purchase only backup or monitoring. It can use a carrier or systems integrator for a wider managed service. It can also place equipment in a specialist local facility and assemble its own provider set.
The facility benchmark has become more explicit. Raxio’s MZ1 page describes a carrier-neutral, Tier III-certified site in Matola with up to 400 racks, 3 MW of IT power, two meet-me rooms, two fibre intake points, 2N rack-power distribution, 48 hours of on-site fuel and eight connectivity providers. These are supplier claims, though the named certification and detailed specification make them directly testable. Cilix’s public pages do not provide comparable facility detail.
That does not mean Cilix must own the largest or most certified building to compete. Its advantage may be orchestration: combining a suitable facility, its own AS, leased routes, public cloud, backup and local operations into one outcome. A carrier-neutral facility can even be a supplier rather than only a rival. The critical commercial distinction is disclosure. If Cilix hosts a service in its own site, a partner site or both, the customer should know which facility licence, category, resilience and contract apply to each copy.
Hyperscalers offer depth, global scale and large service catalogues, but they do not automatically provide a Maputo engineer, a local access route, Portuguese-language escalation or a single party responsible for the application. Local facilities offer transparent physical specifications but may not operate the customer’s software. Cilix can occupy the integration gap. It will defend that position only if it makes third-party dependencies more visible than a customer could make them alone.
What the Public Record Does Not Establish
The reviewed sources do not establish Cilix’s current revenue, profitability, ownership structure beyond the legal form, insurance coverage or balance-sheet capacity to absorb a serious service failure. The EU forum page gives self-reported revenue and employee bands, but those are pitch fields rather than audited accounts. Financial diligence remains necessary for a long-term or critical contract.
The record does not establish the current licence and classification of any Cilix data-centre or cloud service under the 2025 regulations. It does not identify a public facility address for each advertised cloud copy, published power or cooling design, independent availability certification, environmental approval, capacity figure or measured utilisation. The company’s forum pitch says it owns a Maputo data centre; the Futuro evaluation referred to servers in Maputo and Matola. Neither source supplies the new regulatory title or a detailed facility specification.
It does not establish public service-level performance. No credible public status history, availability report, latency series, restore-success metric or incident post-mortem was located in the frozen evidence. No verified material Cilix outage or breach was identified either. That absence is not evidence of an incident-free history: a private B2B operator can resolve events without public reporting, and the public archive may be incomplete.
The sources do not establish a current ISO, SOC, PCI DSS or Uptime certification for Cilix; nor do they establish that no such assurance exists. They do not verify the partner tier or support entitlement behind each technology name on the website. They do not identify the producer and version of the advertised core-banking platform, a live deployment of it, or tested transaction performance.
Finally, the website contains claims that need localisation to the actual network. Its Ethernet page refers to “Openreach” access and unbundled exchanges, terminology associated with the United Kingdom, while claiming national Mozambican reach. That does not disprove Cilix’s service, but it shows why generic web copy cannot serve as a technical schedule. Buyers need local route lists, serviceable buildings, access suppliers and acceptance criteria.
These are evidence gaps, not accusations. Many enterprise suppliers disclose sensitive material only under confidentiality. The correct response is a structured diligence room, not an assumption that missing public evidence is either false or true.
A Procurement Test for Cilix
The first test is identity and authority. The bidder should be Cilix Software, S.A., tied to the current corporate registration, tax identity and signing officers. Cilix should provide the communications permissions relevant to the proposed circuit, plus its cloud-provider and data-centre registrations, licences and facility categories under the new rules. Historical records using “Limitada” should be reconciled in writing. Insurance limits and subcontracting authority should match the contract.
The second test is an asset and dependency map. For every circuit, rack, host, storage system, backup copy, monitoring platform and public-cloud account, the proposal should say whether Cilix owns, leases, resells, manages or merely supports it. It should name the physical site and jurisdiction, third-party operator, support contract and failure domain. Planned backbone segments should be separated from live routes. Partner logos should be supported by current credentials where the status matters.
The third test is the network. Cilix should provide logical and physical diagrams, upstream and peering design, last-mile supplier, building entries, duct diversity, points of presence, public-address allocation and IPv6 scope. The customer should witness loss of the primary path and measure convergence, packet loss, latency and application recovery. The design should explain the single neighbour visible in public BGP data, without assuming that the observation captures every link. A route-origin security and abuse-response plan should address the public hygiene findings.
The fourth test is the facility. The customer should verify the licensed site, regulatory category, power feeds, generator and fuel plan, UPS autonomy, cooling redundancy, fire detection and suppression, flood and access risk, physical-access records, carrier rooms and spare capacity. If Maputo and Matola form a recovery pair, Cilix should show that they do not share the same critical power, fibre, management and credential dependencies. Essential-service customers should obtain specific evidence that the primary and secondary design meets the relevant location rules.
The fifth test is recovery. The service schedule should specify recovery points and times by workload, backup frequency, retention, replication lag, immutability, encryption, keys, malware scanning and the owner of application validation. Before acceptance, the parties should restore a representative database and application into isolation while timing the full process. At least one exercise should assume Cilix’s normal administration system is unavailable. Results and remediation should be signed by the customer’s business owner.
The sixth test is operations. Service indicators should follow the user journey, not only device uptime. The contract should define severity, response, engagement, workaround, restoration and permanent-resolution targets; maintenance notice; change approval; capacity thresholds; on-site support; vendor escalation; and post-incident review. The customer should receive raw or exportable telemetry and ticket data. A tabletop exercise should test after-hours contacts and simultaneous failures.
The seventh test is security and compliance. Cilix should provide its responsibility model, security plan, independent penetration-test summary, vulnerability remediation status, privileged-access design, administrator-screening policy, log-retention design, incident-notification workflow and list of subprocessors. The documents should map to the cloud and data-centre regulations and, for banks, to Bank of Mozambique reporting and remediation evidence. A Mozambique-specific data-processing agreement should replace reliance on the Brazil-oriented website notice.
The eighth test is commercial. The bid should expose recurring and one-time units, third-party pass-throughs, currency, indexation, taxes, minimum terms, consumption alerts, cloud egress, assisted restores, emergency compute, site visits and transition assistance. A three-year scenario should include ordinary growth, one major restore and one exit. Credits and liability caps should be evaluated against business impact, not merely monthly fees.
The ninth test is people. Cilix should name the service manager, on-call roles, escalation executive, network and security leads, and the qualified substitutes for each critical person. The customer should inspect a redacted on-call rota, training and certification records relevant to its stack, staff turnover plan, field coverage and knowledge-transfer process. A broad catalogue delivered by a compact team can work well only when depth and substitution are deliberate.
The tenth test is exit. Before go-live, Cilix should export one virtual workload, backup set, network configuration, identity-role list, runbook, ticket history and monitoring data in agreed formats. The parties should measure how long an independent competent operator takes to understand them. The final agreement should specify continued service during transition, data-transfer capacity, access after termination, deletion proof, licence treatment and maximum exit fees.
Passing these tests would not guarantee that nothing fails. It would show that failure has owners, evidence and an executable path to recovery. That is the appropriate standard for a provider whose value proposition is to reduce handoffs.
Watchpoints: What Would Change the Assessment
The first watchpoint is regulatory disclosure. A public or customer-verifiable Cilix cloud registration, operator licence and facility classification would materially reduce uncertainty, especially if it identifies the Maputo and Matola roles. The adaptation period is temporary; procurement teams should track when transition evidence becomes final.
The second is network expansion. Financing, construction awards, fibre rights, completed segments and live BGP changes would distinguish the €39 million national-backbone proposal from the present footprint. New independently routed upstreams, public IPv6 origination, published service regions and route-origin authorisations would make network claims easier to verify. None should be inferred merely from an announcement.
The third is recovery evidence. An anonymised annual report showing restore attempts, success rates, achieved recovery times and remediated failures would be more informative than additional backup features. Named customer references for private cloud, hybrid operations and application recovery would broaden the evidence beyond connectivity and one microbank backup workflow.
The fourth is assurance and incident practice. Current independent security or availability certifications, a public service-status page, a vulnerability-reporting route, an abuse contact and useful post-incident summaries would improve confidence. If a verified serious incident emerges, the assessment should focus on detection, disclosure, containment, recovery and control improvement rather than the mere fact that an incident occurred.
The fifth is product ownership. Cilix should identify the producer, support chain and live reference architecture behind its core-banking and major platform propositions. Clear partner status and support entitlement would help customers distinguish Cilix-developed intellectual property from implemented third-party software.
The Verdict: Buy the Responsibility Map
Cilix Software has more substance than a broad website might initially reveal. The legal and network records establish a long-lived Mozambican operator. Public procurement establishes repeated institutional connectivity work. The Futuro evaluation establishes a real cloud-backup role in a regulated customer environment. Current hiring and leadership material supports the existence of local operating and field capability. These are meaningful foundations.
The public evidence does not yet justify treating every catalogue claim as one proven, vertically owned platform. Cilix’s network is observable but modest in public routing terms. Its proposed national backbone is still a financing project. Its facility, security, performance and partner details are not sufficiently public to answer a critical buyer’s questions. Its most ambitious software claims lack named deployments and measurable outcomes.
That combination does not make Cilix an unsuitable provider. It defines the purchasing strategy. A customer should buy the company’s potential strength—local coordination across connectivity, cloud, backup and operations—while refusing to let the bundle obscure ownership, dependencies or exit. The decisive artefact is a responsibility map connected to a tested restore, a compliant contract and a rehearsed handover.
If Cilix can show that map, execute the exercise and export the result, its local presence becomes more than proximity. It becomes accountable operational capacity. If it cannot, one telephone number merely conceals seven owners.

