https://www.polity.org.za
Deepening Democracy through Access to Information
Home / Legal Briefs / Bowmans RSS ← Back
Bowmans|Tanzania|Banking|Broadcasting|Civil Aviation|Corporate Governance|Critical Information Infrastructure|Cybersecurity|Data Centres|Data Localisation|Elections|Energy|Mining|Ports|Public Health|Railway|Services|Social Security|Telecommunications|Water Supply|Charles Mmasi|Flora Mukasa
||Services||
bowmans|tanzania|banking|broadcasting|civil-aviation|corporate-governance|critical-information-infrastructure|cybersecurity|data-centres|data-localisation|elections|energy|mining|ports|public-health|railway|services|social-security|telecommunications|water-supply|charles-mmasi|flora-mukasa
Close

Email this article

separate emails by commas, maximum limit of 4 addresses

Sponsored by

Close

Article Enquiry

Tanzania: Regulatory Update on Critical Information Infrastructure


Close

Tanzania: Regulatory Update on Critical Information Infrastructure

Should you have feedback on this article, please complete the fields below.

Please indicate if your feedback is in the form of a letter to the editor that you wish to have published. If so, please be aware that we require that you keep your feedback to below 300 words and we will consider its publication online or in Creamer Media’s print publications, at Creamer Media’s discretion.

We also welcome factual corrections and tip-offs and will protect the identity of our sources, please indicate if this is your wish in your feedback below.


Close

Embed Video

Tanzania: Regulatory Update on Critical Information Infrastructure

Bowmans

7th October 2026

ARTICLE ENQUIRY      SAVE THIS ARTICLE      EMAIL THIS ARTICLE

Font size: -+

On 19 June 2026, the Minister for Communication and Information Technology (Minister) issued the Cybercrimes (Protection of Critical Information Infrastructure) Order, 2026 (Order) as provided for under section 28 of the Cybercrimes Act, Cap. 443 R.E. 2023 (the Act).

The Order designates 25 categories of computer systems as critical information infrastructure (CII) and imposes registration, data localisation, risk management, disaster recovery and audit obligations on their owners and operators.

Advertisement

The Government has since announced a mandatory registration exercise. The registration window runs from 19 June 2026 to 19 December 2026, and registration is completed through the National Registry for Critical Information Infrastructure (NRCII) portal.

Key Definitions

Advertisement

The Order defines the following key terms:

  • Contact person: a designated officer responsible for regulatory liaison, incident reporting, compliance coordination and day-to-day communication with the Ministry for Information and Communication Technology (the Ministry) regarding CII.
  • Critical information infrastructure: an asset, device, computer system or network, whether physical or virtual, which is vital to Tanzania and whose incapacitation affects national security or the economy and social wellbeing of citizens.
  • Data: databases, system logs, transaction records, metadata, backups and any structured or unstructured information processed or generated by CII.
  • Operator: a person or entity that operates CII.
  • Owner: a person or entity that owns CII.

Designated CII

The Order designates 25 categories of CII across these sectors:

  • the national broadband backbone, submarine cable landing stations, internet exchange points and data centres;
  • telecommunications, postal and broadcasting systems;
  • banking, payment and government revenue systems;
  • energy, utilities, water and sewage, and public transport;
  • national ID, elections, social security and land management;
  • public health, education, mineral resources, food supply, and marine, harbour and port operations; and
  • civil aviation, railway, early warning, emergency services and national security systems.

Registration and self-assessment

Owners of designated CII must register with the Ministry by 19 December 2026 using the prescribed form provided under the Order. The NRCII register will record, among other things, critical services, data and dependencies, operators, the contact person, asset inventory, interconnected systems, hosting solutions, network architecture and internet links.

According to the Order, every government institution and private entity must, within the same period, assess its information systems under the prescribed form and submit a report to the Ministry. The Ministry will decide whether to designate each system and will prepare an initial designation list. The checklist covers organisational importance, public safety and security, technical resilience, operational continuity, operational performance, risk management, governance and compliance, communication and coordination, regulatory adherence, and resilience and redundancy.

Penalties

The Order sets no penalties. However, an offence under the Act or any other written law relating to CII carries one or both of the following on conviction:

  • a fine of at least TZS 100-million (about USD 37 000) or three times the loss caused; and
  • imprisonment of at least five years.

The Act does not say whether failing to register or comply with the Order is such an offence. Given the penalty, organisations should treat the deadline as binding.

Where a body corporate is convicted, each director, officer or manager may be deemed to have committed the offence. They escape liability only by proving that the offence occurred without their consent or that they exercised due diligence to prevent it.

Recommended actions

Before 19 December 2026, affected persons or entities should:

  • map their systems against the categories provided under the Order and file the self-assessment;
  • register designated CII on the NRCII portal;
  • appoint a contact person;
  • review offshore, cloud and backup hosting, and seek Ministerial approval where needed;
  • review disaster recovery, business continuity and audit frameworks against the Order; and
  • brief boards and management on personal exposure.

Written by Charles Mmasi, Partner, and Flora Mukasa, Associate, Bowmans Tanzania

EMAIL THIS ARTICLE      SAVE THIS ARTICLE      ARTICLE ENQUIRY      FEEDBACK

To subscribe email subscriptions@creamermedia.co.za or click here
To advertise email advertising@creamermedia.co.za or click here


About

Polity.org.za is a product of Creamer Media.
www.creamermedia.co.za

Other Creamer Media Products include:
Engineering News
Mining Weekly
Research Channel Africa

Read more

Subscriptions

We offer a variety of subscriptions to our Magazine, Website, PDF Reports and our photo library.

Subscriptions are available via the Creamer Media Store.

View store

Advertise

Advertising on Polity.org.za is an effective way to build and consolidate a company's profile among clients and prospective clients. Email advertising@creamermedia.co.za

View options

Email Registration Success

Thank you, you have successfully subscribed to one or more of Creamer Media’s email newsletters. You should start receiving the email newsletters in due course.

Our email newsletters may land in your junk or spam folder. To prevent this, kindly add newsletters@creamermedia.co.za to your address book or safe sender list. If you experience any issues with the receipt of our email newsletters, please email subscriptions@creamermedia.co.za