Kenya: Directive on use of digital certification services by critical information infrastructure (CII) providers enters into force

Description

Directive on use of digital certification services by critical information infrastructure (CII) providers enters into force

On 1 January 2026, a Directive on the use of digital certification services by Critical Information Infrastructure (CII) providers enters into force. It requires designated CII systems in sectors such as telecommunications, banking, and healthcare to use digital certificates and Public Key Infrastructure services exclusively from licensed and accredited Electronic Certification Service Providers. The Directive follows a determination by the National Computer and Cybercrimes Coordination Committee and aims to strengthen cybersecurity by ensuring system and user authentication and by securing data in transit through cryptographic keys.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
infrastructure provider: internet and telecom services, infrastructure provider: network hardware and equipment
Implementation Level
national
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2026-01-01
in force

On 1 January 2026, a Directive on the use of digital certification services by Critical Information…