On 19 June 2026, the Minister for Communication and Information Technology (Minister) issued the Cybercrimes (Protection of Critical Information Infrastructure) Order, 2026 (Order) as provided for under section 28 of the Cybercrimes Act, Cap. 443 R.E. 2023 (the Act).
The Order designates 25 categories of computer systems as critical information infrastructure (CII) and imposes registration, data localisation, risk management, disaster recovery and audit obligations on their owners and operators.
The Government has since announced a mandatory registration exercise. The registration window runs from 19 June 2026 to 19 December 2026, and registration is completed through the National Registry for Critical Information Infrastructure (NRCII) portal.
Key Definitions
The Order defines the following key terms:
- Contact person: a designated officer responsible for regulatory liaison, incident reporting, compliance coordination and day-to-day communication with the Ministry for Information and Communication Technology (the Ministry) regarding CII.
- Critical information infrastructure: an asset, device, computer system or network, whether physical or virtual, which is vital to Tanzania and whose incapacitation affects national security or the economy and social wellbeing of citizens.
- Data: databases, system logs, transaction records, metadata, backups and any structured or unstructured information processed or generated by CII.
- Operator: a person or entity that operates CII.
- Owner: a person or entity that owns CII.
Designated CII
The Order designates 25 categories of CII across these sectors:
- the national broadband backbone, submarine cable landing stations, internet exchange points and data centres;
- telecommunications, postal and broadcasting systems;
- banking, payment and government revenue systems;
- energy, utilities, water and sewage, and public transport;
- national ID, elections, social security and land management;
- public health, education, mineral resources, food supply, and marine, harbour and port operations; and
- civil aviation, railway, early warning, emergency services and national security systems.
Registration and self-assessment
Owners of designated CII must register with the Ministry by 19 December 2026 using the prescribed form provided under the Order. The NRCII register will record, among other things, critical services, data and dependencies, operators, the contact person, asset inventory, interconnected systems, hosting solutions, network architecture and internet links.
According to the Order, every government institution and private entity must, within the same period, assess its information systems under the prescribed form and submit a report to the Ministry. The Ministry will decide whether to designate each system and will prepare an initial designation list. The checklist covers organisational importance, public safety and security, technical resilience, operational continuity, operational performance, risk management, governance and compliance, communication and coordination, regulatory adherence, and resilience and redundancy.
Penalties
The Order sets no penalties. However, an offence under the Act or any other written law relating to CII carries one or both of the following on conviction:
- a fine of at least TZS 100-million (about USD 37 000) or three times the loss caused; and
- imprisonment of at least five years.
The Act does not say whether failing to register or comply with the Order is such an offence. Given the penalty, organisations should treat the deadline as binding.
Where a body corporate is convicted, each director, officer or manager may be deemed to have committed the offence. They escape liability only by proving that the offence occurred without their consent or that they exercised due diligence to prevent it.
Recommended actions
Before 19 December 2026, affected persons or entities should:
- map their systems against the categories provided under the Order and file the self-assessment;
- register designated CII on the NRCII portal;
- appoint a contact person;
- review offshore, cloud and backup hosting, and seek Ministerial approval where needed;
- review disaster recovery, business continuity and audit frameworks against the Order; and
- brief boards and management on personal exposure.
Written by Charles Mmasi, Partner, and Flora Mukasa, Associate, Bowmans Tanzania
EMAIL THIS ARTICLE SAVE THIS ARTICLE ARTICLE ENQUIRY FEEDBACK
To subscribe email subscriptions@creamermedia.co.za or click here
To advertise email advertising@creamermedia.co.za or click here









