Regulatory Intelligence

Kenya’s National Cybersecurity Agency (NCSA): What Legal Notice No. 89 Means for Regulated Institutions

Kenya has centralised cybersecurity oversight under a single autonomous agency with the power to audit and certify critical information infrastructure. Here is why the NCSA was created, what changes to expect, and how banks, SACCOs, microfinance institutions, payment service providers and insurers should prepare to comply with the regulation.

Sentinel Assurance Partners July 2026 16 min read IT Audit · Cybersecurity · Regulatory Compliance

In June 2026, Parliament approved the National Cybersecurity Agency Order, 2026 issued under Legal Notice No. 89, establishing the National Cybersecurity Agency (NCSA) as Kenya’s central institution for cybersecurity regulation, coordination and response. For every board that believed its cyber compliance story ended with its sector regulator, the landscape has just changed. A second regulator has arrived, and it carries explicit authority to audit and certify the resilience of the critical systems your institution depends on.

842M+
Cyber threat events detected by the National KE-CIRT/CC in a single quarter (Jul–Sep 2025).
~92%
Share of those events classified as system attacks driven by misconfiguration and brute force.
L.N. 89
Legal Notice establishing the NCSA under the State Corporations Act, 2026.
81%+
Of Kenyans transact through mobile money the country’s largest financial channel and attack surface.

Why the NCSA Matters

The NCSA is not another advisory committee. It is an autonomous regulatory and technical body established by presidential order under the State Corporations Act, with a mandate that cuts across government, the private sector and critical infrastructure operators. Three features make it consequential for regulated institutions:

First, it has audit and certification powers. The Agency is legally mandated to evaluate, audit and certify the cybersecurity resilience of designated critical information infrastructure (CII). If your institution is designated or depends on systems that are deemed critical, you now face a formal certification cycle in addition to your existing supervisory examinations.

Second, it sits above the sector regulators. The NCSA will manage the National Cybersecurity Operations Centre (NCOC) and provide technical support to Sectoral Cybersecurity Operations Centres including, in practice, coordination with the CBK’s Banking Sector SOC (BS-SOC). Incident reporting, threat intelligence and response coordination will increasingly flow through a national architecture, not just a sectoral one.

Third, its governance signals enforcement intent. The Agency’s board draws from the Ministry of Interior, the National Treasury, the ICT ministry, the Attorney-General’s office, the Kenya Defence Forces, the National Police Service, the National Intelligence Service and the Office of the Director of Public Prosecutions, alongside academia and the private sector. Cybersecurity in Kenya is now formally a national security function with the institutional muscle.

What Is Critical Information Infrastructure?

Critical Information Infrastructure refers to the systems, networks and data assets whose disruption or destruction would have a debilitating impact on national security, economic stability, public health or safety, or the delivery of essential services. Under Kenya’s framework, anchored in the Computer Misuse and Cybercrimes Act, 2018 and its 2025 Amendment, CII is formally designated, and designation carries binding obligations.

In practice, CII in Kenya spans sectors including banking and payment systems, telecommunications, energy, water, transport, health and core government services. For the financial sector, the implications are direct: national payment infrastructure, core banking platforms serving systemic institutions, mobile money rails and interbank switching systems are precisely the class of assets a CII regime exists to protect.

The strategic question every board should be asking is not simply “Are we designated?” but “Are we designated, do we operate a component of a designated system, or do we critically depend on one?” All three positions create exposure: designated operators face audit and certification directly, while dependent institutions will feel the requirements flow down through contracts, service level agreements and supervisory expectations.

Why Kenya Needed a National Cybersecurity Agency

The case for the NCSA has been building for a decade. Five forces converged to make a central agency unavoidable:

Rapid digital transformation

Kenya’s “Silicon Savannah” economy now runs on fibre, cloud and hyperscale data centres. Every digitised process from eCitizen services to core banking expands the national attack surface faster than the growth of defensive capacity.

Growth of mobile money and digital banking

With more than 8 in 10 Kenyans transacting through mobile money and digital lending now mainstream, the financial system’s dependence on always-on digital rails makes cyber disruption a direct threat to economic stability and household livelihoods.

Increasing ransomware attacks

Ransomware has moved from opportunistic to targeted, hitting Kenyan financial institutions, hospitals, universities and government platforms. Double-extortion tactics such as encryption plus data theft, turn every incident into both an availability crisis and a data protection breach.

Government digitisation

The push to bring thousands of government services online, alongside programmes such as the digital ID and e-procurement, concentrates citizen data and essential services on platforms that adversaries such as criminal and state-sponsored actively probe.

Rising cybercrime against businesses and citizens

Online fraud, identity theft, SIM-swap attacks, business email compromise and mobile loan fraud impose direct losses on businesses and citizens daily eroding the digital trust on which Kenya’s economy increasingly depends on.

The Driving Factors Behind the NCSA’s Creation

Beyond the broad backdrop, six specific factors drove the government to act:

1
Escalating cyber attack volumesThe National KE-CIRT/CC detected over 842 million threat events in a single quarter of 2025, with an earlier quarter logging 33.9 million malware attempts against critical infrastructure. Volumes at this scale exceed what a distributed, part-time institutional response can absorb.
2
Protection of Critical Information Infrastructure (CII)Designated CII such as payment systems, telecoms, energy, water, health requires a dedicated authority to assess, audit and certify resilience, rather than relying on each operator’s self-assessment.
3
National security concernsCyber operations against government systems and critical infrastructure are now a recognised national security threat, requiring integration with the defence, intelligence and law enforcement communities reflected directly in the NCSA’s board composition.
4
Digital trustKenya’s ambitions as a regional technology and investment hub depend on citizens, businesses and foreign investors trusting its digital ecosystem. A credible national cybersecurity authority is a trust signal and its certifications may ease cross-border licensing and partnership negotiations.
5
International cybersecurity obligationsKenya’s commitments under regional and international frameworks, including consultations on accession to the African Union’s Malabo Convention require a competent national authority able to participate in global threat intelligence exchange and cooperative response.
6
Coordination gaps between agenciesThe absence of a single coordinating institution slowed incident response and limited information sharing between agencies. Fragmented mandates meant no one owned the national cyber picture end-to-end.

The Landscape Before the NCSA: A Fragmented Architecture

Before Legal Notice No. 89, cybersecurity responsibilities were spread across multiple institutions, each with a partial mandate. The Communications Authority of Kenya (CA) operated the National KE-CIRT/CC, handling national threat detection and incident coordination from a telecommunications regulator’s perch. The National Computer and Cybercrimes Coordination Committee (NC4), established under the Computer Misuse and Cybercrimes Act, 2018, coordinated cybercrime policy and CII matters. Sector regulators such as the CBK for banks and payment providers, SASRA for deposit-taking SACCOs, the IRA for insurers issued their own cybersecurity guidelines and examined their own licensees. Law enforcement — the DCI and the ODPP — investigated and prosecuted cybercrime, while the ODPC enforced data protection.

Each institution did real work. But the model produced overlapping reporting obligations, inconsistent standards, slow cross-sector intelligence sharing and critically no single body accountable for national cyber resilience. The NCSA is the structural answer to that fragmentation.

“The NCSA does not replace your sector regulator. It adds a national layer above it which means institutions must now design compliance programmes that satisfy both, without running two parallel control environments.”

The Mandate of the National Cybersecurity Agency

The Order gives the NCSA a deliberately broad mandate. Its expected responsibilities include:

1
National cybersecurity strategyFormulating and overseeing implementation of national cybersecurity strategies across both public and private sectors.
2
CII audit and certificationAuditing and certifying the cybersecurity resilience of designated critical information infrastructure. The mandate with the most direct compliance impact on regulated institutions.
3
National Cybersecurity Operations CentreManaging day-to-day operations of the NCOC and providing technical support to Sectoral Cybersecurity Operations Centres.
4
Vulnerability assessmentConducting vulnerability assessments across government and private networks, and deploying analytics and forensic tools to identify emerging threats.
5
Incident response coordinationProviding a coordinated national framework for preventing, detecting, responding to and recovering from cyber incidents, including systemic events affecting multiple sectors.
6
Cybersecurity Centre of ExcellenceEstablishing a centre for indigenous research, tool development and innovation, a state-backed anchor for advanced capability building.
7
Professional certification and skillsDeveloping professional certification curricula and skills programmes to address the national cybersecurity talent gap.
8
International cooperationParticipating in global technical forums for real-time threat intelligence exchange and representing Kenya in international cybersecurity engagements.

How the NCSA Differs from Existing Agencies

The most common board-level question we hear is: “Don’t we already have regulators for this?” The answer is that each existing institution holds a partial mandate. The comparison below clarifies where the NCSA sits:

InstitutionLegal BasisPrimary FocusScopeRelationship to NCSA
National Cybersecurity Agency (NCSA) NCSA Order 2026 (Legal Notice No. 89) National cybersecurity strategy, CII audit & certification, NCOC operations, incident coordination All sectors i.e public, private and critical infrastructure The apex coordinating and regulatory authority
Communications Authority (CA) / KE-CIRT/CC Kenya Information & Communications Act Telecoms/ICT sector regulation; national threat detection and CIRT services Licensed communications operators; national threat monitoring Expected to feed into and coordinate with the NCOC under NCSA leadership
NC4 Computer Misuse & Cybercrimes Act, 2018 Cybercrime policy coordination, CII designation framework, investigation support Inter-agency committee spanning security organs Policy and criminal-justice coordination alongside NCSA’s operational/regulatory role
ODPC Data Protection Act, 2019 Personal data protection: registration, breach notification, complaints, audits, penalties All data controllers and processors Complementary — a cyber incident involving personal data triggers both regimes
CBK (incl. BS-SOC) Banking Act, NPS Act, CBK guidelines Prudential cybersecurity supervision of banks, PSPs and digital lenders; sector SOC CBK-licensed institutions Sectoral SOC expected to interoperate with the NCOC; supervision remains with CBK
SASRA / IRA Sacco Societies Act / Insurance Act Sector prudential supervision, including ICT risk and cybersecurity requirements Regulated SACCOs / licensed insurers Sector requirements continue; NCSA adds a national layer, especially where licensees touch CII

How the NCSA Aligns Kenya with Global Frameworks

The NCSA brings Kenya’s institutional architecture into line with internationally recognised models. Peer economies have long operated central cyber authorities such as Singapore’s Cyber Security Agency, the UK’s National Cyber Security Centre, Rwanda’s National Cyber Security Authority, and Kenya’s move follows the same design logic: one accountable authority, sectoral SOCs beneath it, and a national CERT function integrated rather than free-standing.

Alignment operates at several levels. At the standards level, the NCSA’s audit and certification mandate creates a natural anchor for frameworks already embedded in Kenyan supervision i.e the NIST Cybersecurity Framework (whose 2024 update added the Govern function, mirroring Kenya’s emphasis on board accountability), ISO/IEC 27001 for management systems, and CIS Controls for technical baselines. At the treaty level, a competent national authority strengthens Kenya’s position in consultations on the AU Malabo Convention and in international cooperation on cybercrime. At the market level, credible national certification can serve as a trust mark that eases cross-border licensing, correspondent relationships and investment due diligence.

For regulated institutions, the practical takeaway is reassuring: if your control environment is genuinely mapped to NIST CSF 2.0 or ISO 27001, you are already building toward whatever certification baseline the NCSA adopts. The institutions at risk are those whose compliance exists on paper but not in evidence.

Impact on Financial Institutions and the Industries We Serve

The NCSA’s arrival lands differently across the financial sector. Here is what each class of institution should anticipate:

Banks

High exposure

Banks are the most likely candidates for CII designation and already operate under the CBK’s cybersecurity guidance and BS-SOC reporting expectations. The NCSA adds a national certification layer on top.

  • Expect harmonised incident reporting flowing to both the BS-SOC and the national NCOC — reporting pathways and timelines must be reconciled now
  • CII audit and certification cycles will demand a defensible evidence trail: vulnerability management records, penetration test reports, board minutes on cyber risk
  • Threat intelligence consumption becomes a supervisory expectation, not a maturity aspiration — banks must show they operationalise national and sectoral feeds
  • Group structures with regional subsidiaries should anticipate NCSA engagement on cross-border infrastructure dependencies

SACCOs

Rising exposure

Kenya’s deposit-taking SACCOs already face SASRA’s tightened ICT and IT audit requirements. While most individual SACCOs are unlikely to be designated CII, the shared platforms many depend on such as core banking hosts, payment integrations, mobile channels may well be designated CII.

  • Expect CII obligations to flow down through vendor contracts: SACCOs must be able to demonstrate due diligence over critical service providers
  • SASRA’s supervisory posture will likely absorb NCSA expectations over time i.e boards should get ahead of that convergence
  • Resource-constrained SACCOs should evaluate co-sourced IT audit and managed security arrangements as proportionate compliance pathways
  • Incident response plans must now contemplate national-level reporting, not only SASRA notification

MicroFinance Institutions (MFI)

Baseline building

MFIs often operate core systems with limited monitoring and no dedicated security staff. The direction of travel is unambiguous: minimum cybersecurity controls regardless of institution size.

  • Expect proportionate but non-negotiable baselines such as access control, patching discipline, monitored backups, incident reporting capability etc.
  • The skills gap is the binding constraint; shared services, MSSPs and co-sourced assurance are the realistic route to compliance
  • Boards should commission an independent gap assessment before a regulator or the NCSA forces them to do it.

Payment Service Providers(PSP)

Highest exposure

PSPs and mobile money operators sit at the centre of the CII conversation i.e their rails are the definition of infrastructure whose disruption would have national economic impact. Kenyan fintech operators now face a regulator with explicit authority to audit their digital infrastructure and certify their cybersecurity resilience.

  • Expect direct NCSA engagement: designation, resilience audits, and certification requirements layered onto CBK’s PSP cybersecurity guidelines.
  • Certification cuts both ways i.e compliance overhead, but also a credible trust signal for cross-border licensing and partnerships.
  • API ecosystems and third-party integrations will come under scrutiny as systemic dependencies.
  • Resilience engineering i.e redundancy, failover, tested recovery will be examined, not just documented.

Insurance Companies

Dual role

Insurers face the NCSA twice: as regulated entities holding sensitive personal and financial data, and as underwriters of cyber risk whose portfolios depend on the control maturity of insured entities.

  • Expect IRA supervisory expectations to progressively reference national standards and NCSA advisories.
  • Core insurance platforms, bancassurance integrations and health data systems raise both cyber and KDPA exposure simultaneously.
  • Cyber underwriting gains a reference point: NCSA certification status may become a rating factor for corporate insured entities.
  • Third-party administrators and intermediaries must be brought inside the control perimeter.

Beyond financial services, Ministries, Counties, Departments and Agencies (MCDAs) should note that government systems sit squarely within the NCSA’s vulnerability assessment mandate, reinforcing the ICT Authority’s Government Enterprise Architecture standards with an operational audit authority behind them.

What Changes Organisations Should Expect

Synthesising the Order’s mandate and the trajectory of Kenyan cyber regulation, institutions should plan for the following changes over the next 12–24 months:

1
CII designation and scoping exercisesFormal identification of designated systems and operators, with obligations attaching on designation.
2
A national audit and certification cyclePeriodic resilience audits of designated infrastructure, requiring evidence-based demonstration of control effectiveness.
3
Harmonised incident reportingConvergence of reporting obligations across the NCSA/NCOC, sectoral SOCs, sector regulators and the ODPC’s 72-hour breach regime.
4
Mandatory threat intelligence integrationExpectations that institutions consume and act on national and sectoral advisories, with evidence of operationalisation.
5
Deeper third-party scrutinyVendor and cloud dependencies of designated systems examined as part of the national resilience picture.
6
Professionalisation of the cyber workforceNational certification curricula that will, over time, shape hiring expectations and competence standards for security and audit roles.

How to Prepare: A 90-Day Readiness Roadmap

Institutions do not need to wait for the NCSA’s first circular to act. The preparation that serves you under the new regime is the same preparation that serves you under the CBK, SASRA, IRA and ODPC today — done properly and evidenced.

Days 1–30
Establish your positionConduct a CII self-assessment: could your systems, or systems you critically depend on, plausibly be designated? Map your current obligations across CBK/SASRA/IRA, the CMCA Regulations 2024 and the KDPA, and identify where NCSA requirements will layer on top. Brief the board.
Days 31–60
Baseline and gap-assessMap your control environment to NIST CSF 2.0 (including the Govern function) or ISO 27001. Commission an independent gap assessment against the framework and your sector’s requirements. Inventory third-party and cloud dependencies supporting critical services, and test your incident reporting pathways end-to-end.
Days 61–90
Close gaps and build the evidence fileRemediate priority findings such as access control, vulnerability management, backup integrity, logging and monitoring. Assemble a certification-ready evidence file: policies, test results, board minutes, training records, vendor assessments. Schedule an independent IT audit to validate readiness before any regulator arrives.

Questions Every Board Should Be Asking Now

  • Could any of our systems or systems we critically depend on be designated as Critical Information Infrastructure?
  • Can we evidence our cybersecurity controls to certification standard, or does our compliance exist only in policy documents?
  • How do our incident reporting obligations reconcile across the NCSA, our sector regulator, and the ODPC’s 72-hour breach notification requirement?
  • When did we last commission an independent IT audit of our cybersecurity control environment and were the findings remediated?
  • Do our critical vendor contracts allow us to demonstrate due diligence if their systems are designated CII?
  • Who in management owns NCSA readiness, and when will they next report to this board?

Challenges the NCSA Will Face

Balanced analysis requires acknowledging that the NCSA’s success is not guaranteed. Institutions should track how the Agency navigates seven structural challenges because each affects how, and how fast, obligations will land:

Skills shortages

Kenya’s cybersecurity talent gap is acute, and the NCSA will compete with banks, telcos and global firms for the same scarce professionals. The Centre of Excellence and certification programmes are the long-term answer; the short-term reality is constrained capacity.

Funding constraints

A mandate this broad i.e national SOC operations, audits, research, certification is expensive. Sustained Treasury commitment will determine whether the Agency regulates actively or nominally.

Coordination across agencies

The NCSA must harmonise with the CA, NC4, ODPC, CBK, SASRA, IRA and law enforcement without triggering turf conflict or duplicating reporting burdens on regulated entities. Institutional cooperation is the Agency’s hardest deliverable.

Rapidly evolving cyber threats

Threat actors iterate in weeks; regulatory institutions in years. The NCSA must build adaptive, intelligence-led processes rather than static checklists that age badly.

AI-driven cyber attacks

Adversaries are already using AI for convincing phishing, deepfake-enabled fraud and automated vulnerability discovery. The Agency’s tooling, and its guidance to industry, must contend with attacks that scale faster than human-speed defence.

Public awareness gaps

Most successful attacks against Kenyan businesses and citizens still begin with social engineering. National resilience requires citizen-level awareness at a scale no agency has yet achieved.

Balancing regulation with innovation

Kenya’s fintech dynamism is a national asset. Certification regimes that are too heavy will push innovation offshore; too light, and they protect nothing. Calibration i.e proportionate, risk-based requirements will define whether the NCSA enables or encumbers the digital economy.

The Bottom Line

The National Cybersecurity Agency Order, 2026 is the most significant restructuring of Kenya’s cybersecurity governance since the Computer Misuse and Cybercrimes Act. For regulated institutions, the message is not to panic but rather to be prepared. The NCSA will take time to become fully operational, issue its first designations and run its first certification cycles. That interval is a gift: the institutions that use it to baseline their controls, close their gaps and build a defensible evidence file will experience the new regime as validation. Those that wait will experience it as enforcement.

Independent assurance is the bridge between the two outcomes. A rigorous, framework-aligned IT audit conducted now before the Agency arrives tells your board exactly where you stand, and gives your institution the one thing no regulator can fault: evidence.

Frequently Asked Questions

Is my SACCO or MFI “critical information infrastructure”?

Most individual SACCOs and MFIs are unlikely to be designated directly. However, the shared core banking platforms, payment integrations and mobile channels they depend on may be and obligations flow down through those dependencies. A CII exposure assessment answers the question for your specific architecture.

Does NCSA certification replace CBK, SASRA or IRA requirements?

No. Sector prudential supervision continues unchanged. The NCSA adds a national layer i.e strategy, CII audit and certification, and coordinated incident response on top of existing sectoral regimes. Institutions must design one control environment that satisfies both.

When does the NCSA become operational?

Parliament approved the Order in June 2026 and the Agency’s establishment is underway, with headquarters in Nairobi and powers to establish satellite units. Operationalisation such as board appointments, staffing, first circulars will unfold over the coming months. The preparation window is now.

How does the NCSA relate to the ODPC?

They are complementary. The ODPC enforces personal data protection under the Data Protection Act, 2019; the NCSA governs cybersecurity resilience. A single cyber incident involving personal data will typically trigger both regimes including the ODPC’s 72-hour breach notification requirement.

What should we do first?

Start with a CII exposure self-assessment and an independent gap analysis against NIST CSF 2.0 or ISO 27001. These two exercises tell your board where you stand, what designation would mean, and what it will cost to close the gap before any regulator asks.