Telecoms licensing Kenya is administered by the Communications Authority, which issues licences for network facilities, service provision and spectrum access. The Communications Authority of Kenya (CA) is the statutory regulator for the information and communications sector under the Kenya Information and Communications Act (KICA) 1998 (Cap 411A). Any person seeking to provide public telecommunications services, operate an internet service provider (ISP), provide broadcasting services, or provide postal services in Kenya must hold the appropriate CA licence. The CA’s licensing framework has been significantly modernised through the Kenya Information and Communications (Amendment) Act 2013 and the Communications (Licensing and Quality of Service) Regulations 2010.
The Kenya Information and Communications Act Framework
KICA establishes the CA and grants it powers to issue, renew, modify, and revoke communications licences; set quality of service standards; regulate tariffs; manage spectrum; and protect consumers. Kenya’s communications sector has undergone dramatic liberalisation since the late 1990s, transitioning from a state monopoly to a competitive market with multiple licensed operators. The CA’s licensing framework reflects this competitive market structure.
Telecommunications Licences
Network Facility Provider Licence
A Network Facility Provider (NFP) licence is required by any person who owns or operates public communications infrastructure, including mobile network towers, fibre optic cables, satellite ground stations, and other physical communications assets. NFP licensees may provide network capacity to service providers but may not offer services directly to end users without holding a corresponding service provider licence.
Network Service Provider Licence
A Network Service Provider (NSP) licence is required by any person providing telecommunications services over communications infrastructure, including mobile network operators, fixed-line operators, and MVNO operators. The four major mobile network operators (Safaricom, Airtel, Telkom, and Equitel) each hold NSP licences. New entrants into mobile or fixed telecommunications services require NSP licences.
Application Service Provider Licence
An Application Service Provider (ASP) licence is required by persons providing value-added services over communications networks, including internet access services, VoIP services, managed data services, cloud computing services, and enterprise ICT managed services. The ASP licence category is the most relevant for technology businesses and internet-based service providers.
Internet Service Provider (ISP) Licensing
ISPs providing internet access services to the public must hold an Application Service Provider licence from the CA. The ISP licence application requires a company incorporated in Kenya, evidence of technical capacity, cybersecurity compliance plan, and payment of prescribed licence fees. ISPs must also comply with the CA’s Quality of Service Regulations including minimum connectivity speed standards and service availability requirements.
Broadcasting Licences
Broadcasting services in Kenya are regulated by the CA under KICA and the Kenya Broadcasting Corporation Act. Licences are required for free-to-air television, pay TV, radio broadcasting, and community broadcasting. Broadcasting licence applications require content compliance plans aligned with the CA’s content regulations, technical frequency plans, and compliance with the Code on News and Current Affairs. The CA coordinates with the Kenya Film Classification Board (KFCB) on content standards.
Type Approval for Communications Equipment
All communications equipment offered for sale or use in Kenya must be type-approved by the CA. This includes mobile phones, routers, modems, satellite equipment, and other devices that use licensed radio frequencies. Equipment importers and distributors must obtain CA type approval before commercialising communications equipment. Type approval applications are submitted to the CA with technical specifications and test reports.
Cybersecurity and Data Protection Obligations
CA licensees have specific cybersecurity obligations under the Computer Misuse and Cybercrimes Act 2018 and the CA’s Cybersecurity Regulations. Significant security incidents must be reported to the CA’s National KE-CIRT within prescribed timeframes. Licensees must implement minimum cybersecurity controls and cooperate with CA cybersecurity inspections.
For legal advice on CA licensing, telecommunications law, and regulatory compliance, our regulatory compliance practice advises telecoms operators, ISPs, technology companies, and broadcasters. More information is available at the Communications Authority website. Technology businesses should also consult our technology and startups practice on the full range of regulatory requirements for digital businesses in Kenya.
Data Localisation Requirements for Digital Service Providers
The Data Protection Act 2019 and the Communications Authority’s Data Protection Framework impose data localisation considerations on telecommunications and internet service providers operating in Kenya. While Kenya does not impose an absolute requirement to store all data locally, the DPA restricts cross-border transfers of personal data to countries without adequate data protection frameworks. ISPs and cloud service providers processing Kenyan personal data must assess whether cross-border data transfers to their hosting infrastructure comply with DPA transfer restrictions and must implement appropriate safeguards such as standard contractual clauses or binding corporate rules where transfers are necessary.
Cybersecurity Obligations for CA Licensees
The Computer Misuse and Cybercrimes Act 2018 and the CA’s National Cybersecurity Framework impose specific obligations on licensed telecoms operators and ISPs. Critical information infrastructure operators, which include major telecoms providers, must register with the National KE-CIRT (Computer Incident Response Team) and report significant cybersecurity incidents within prescribed timelines. CA licensees must implement minimum cybersecurity controls including access control, intrusion detection, encryption of sensitive data, and regular security assessments. The CA has powers to inspect licensees’ cybersecurity measures and may suspend licences of operators found to have inadequate security controls that put consumers at risk.
5G and Spectrum Allocation in Kenya
Kenya is among the early movers on 5G deployment in Sub-Saharan Africa, with the Communications Authority issuing spectrum allocations in the 700MHz, 2600MHz, and 3500MHz frequency bands to support 5G network deployments. New 5G network infrastructure requires CA approval for spectrum use, network equipment type approval, and compliance with the CA’s Quality of Service Regulations for 5G services. For technology companies developing IoT applications, smart city solutions, or industrial automation products that rely on 5G connectivity, understanding the CA licensing requirements for spectrum-dependent services is critical. See our broader technology regulatory advisory through our technology and startups practice.
Universal Service and Access Obligations
The Communications Authority administers the Universal Service Fund (USF) under KICA, which is funded by a 0.5% levy on licensed operators’ turnover and is used to finance telecommunications infrastructure rollout in underserved areas. CA-licensed operators are subject to both the USF levy and potential obligations to participate in USF-funded projects if designated as access providers. Understanding the CA’s universal service framework is important for new licensees calculating their total regulatory cost. The CA’s guidance on USF obligations and levy calculation is available through the Communications Authority website.
Regulatory Compliance for Mobile Financial Services
Mobile money services and mobile financial services in Kenya are regulated by the CBK under the National Payment System Act, with the Communications Authority having oversight of the mobile network infrastructure through which these services are delivered. The intersection of CBK and CA regulation is particularly important for mobile money operators and for fintech companies delivering financial services through mobile platforms. A fintech company launching a mobile lending or payments application in Kenya must navigate both CBK licensing (or CBK’s Payment Service Provider framework) and ensure that any use of licensed mobile network operator infrastructure complies with the CA’s Application Service Provider rules. For comprehensive regulatory mapping of mobile financial services businesses, our regulatory sandbox and compliance advisory teams work together to identify all applicable licensing requirements.
CA Type Approval for IoT Devices
The growing Internet of Things (IoT) market in Kenya creates specific type approval requirements. IoT devices that communicate wirelessly in licensed frequency bands must obtain CA type approval before being imported, sold, or deployed in Kenya. This requirement applies to smart meters, connected vehicles, industrial IoT sensors, and consumer smart home devices. Importers and distributors of IoT devices should verify CA type approval status before committing to commercial volumes. The CA type approval register is available on the Communications Authority website.
For tailored legal advice on Communications Authority licensing, consult our regulatory compliance practice team. The broader media regulatory landscape is covered in our guide to media and broadcasting law in Kenya, and technology-sector considerations in the startup legal checklist.






