Kenya has established a dedicated national agency for cybersecurity. The State Corporations (National Cybersecurity Agency) Order, 2026 creates the National Cybersecurity Agency as a body corporate under the State Corporations Act, with a mandate that reaches beyond government networks into the private sector. For businesses running digital infrastructure, particularly anything that could be designated critical information infrastructure, this new Agency is now the technical body to watch. This article covers what the Order actually establishes and what it means for private sector operators.
The New Law: The National Cybersecurity Agency Order, 2026
The State Corporations (National Cybersecurity Agency) Order, 2026 (Legal Notice 89 of 2026) was published in the Kenya Gazette and commenced on 15 May 2026. It is made under the State Corporations Act and establishes the National Cybersecurity Agency as the autonomous regulatory and technical body responsible for coordinating national cybersecurity matters, operating under the direction of the Cabinet Secretary responsible for internal security.
A New Body Corporate Headquartered in Nairobi
Paragraph 4 of the Order establishes the Agency as a body corporate with perpetual succession and a common seal, capable in its own name of suing and being sued, holding and disposing of property, borrowing and lending money, and entering into contracts. Its headquarters are in Nairobi City County, with the Agency empowered to establish satellite offices, units and specialised centres elsewhere as needed. This gives Kenya, for the first time, a single dedicated statutory body responsible for national cybersecurity coordination, rather than the function being spread informally across different government departments and agencies.
Functions That Reach Into the Private Sector
Paragraph 6 sets out the Agency’s functions in detail, and several of them extend well beyond coordinating government systems. The Agency is tasked with formulating and overseeing the implementation of national cybersecurity strategies for adoption across both the public and private sectors. It is also responsible for auditing and certifying the cybersecurity resilience of designated critical information infrastructure, to ensure continuous availability and system integrity, and for conducting periodic technical assessments and vulnerability exposure reviews of government and private sector digital networks to check adherence to established cybersecurity standards.
The Agency will also run the National Cybersecurity Operations Center and provide technical support to sector-specific Cybersecurity Operations Centers, deploy analytics and forensic tools to identify emerging vulnerabilities and issue technical advisories to affected stakeholders, and act as the lead technical liaison between government and industry consortia to harmonise cybersecurity practices within particular economic sectors. It is additionally mandated to establish a Cybersecurity Center of Excellence for local research and the development of indigenous cyber-defence tools, and to run professional certification and training programmes aimed at closing the national cybersecurity skills gap.
Governance: A Board Dominated by Security and Government Institutions
Paragraph 7 establishes a Board of Directors to manage the Agency, chaired by a non-executive Chairperson appointed by the President. The remaining membership is drawn overwhelmingly from state security and administrative institutions: the Principal Secretaries responsible for internal security, the National Treasury, and ICT, the Attorney-General, the Chief of the Kenya Defence Forces, the Inspector-General of the National Police Service, the Director-General of the National Intelligence Service, and the Director of Public Prosecutions, each represented directly or through a written designee, together with two appointed members. The composition signals that the Agency sits closer to national security architecture than to a conventional sectoral regulator, which is a useful context for understanding how its technical assessments and advisories are likely to be exercised in practice.
Why This Matters for Businesses
Nothing in the Order yet creates a licensing or permit requirement for private businesses, and no offence or penalty provision appears in the text. What it does create is a single, well-resourced state body with an explicit mandate to assess private sector digital networks, designate and audit critical information infrastructure, and issue binding technical advisories. Businesses operating in sectors likely to be treated as critical infrastructure, including banking and payments, telecommunications, energy, healthcare and large-scale data processing, should expect direct engagement from the Agency once its designation criteria and operational guidelines are published. This sits alongside, rather than replaces, Kenya’s existing data protection framework administered by the Office of the Data Protection Commissioner, and businesses already managing ODPC compliance should treat the two as complementary rather than overlapping obligations.
Businesses that have not previously had a single point of government contact on cybersecurity now have one. Engaging early, for example by understanding whether a business’s infrastructure is likely to be designated as critical, and by aligning internal cybersecurity practices with the national strategies the Agency is tasked with formulating, is a more sensible posture than waiting to be identified in an audit.
What to Watch For Next
The Order does not itself define the criteria for designating critical information infrastructure, nor does it set out the procedure the Agency will follow when auditing or certifying resilience. Businesses in infrastructure-heavy or data-intensive sectors should watch for the operational guidelines, designation criteria and any subsidiary regulations the Agency issues under its mandate, since these will determine the practical scope of the audit and certification function in paragraph 6.
How We Can Help
Clay & Associates Advocates advises technology, financial services, and infrastructure clients on regulatory compliance and engagement with Kenya’s data protection and cybersecurity authorities. See our related coverage of Kenya’s cross-border data transfer compliance regime and the expanded definition of sensitive personal data. Contact our Technology & Startups or Regulatory & Compliance practice to discuss how the new Agency’s mandate affects your business.
Sources: The State Corporations (National Cybersecurity Agency) Order, 2026 (Legal Notice 89 of 2026), paragraphs 3, 4, 5, 6 and 7.
Frequently asked questions
What is the National Cybersecurity Agency?
It is a body corporate established under the State Corporations Act by Legal Notice 89 of 2026, responsible for coordinating national cybersecurity matters, operating under the direction of the Cabinet Secretary responsible for internal security.
Does the Order create a licensing requirement for private businesses?
No. The Order establishes the Agency and its functions, including auditing and certifying critical information infrastructure and assessing private sector networks, but it does not itself create a permit or licensing regime or set out penalties.
Which businesses are most likely to be affected?
Businesses operating what may be designated as critical information infrastructure, such as banking and payments, telecommunications, energy, healthcare and large-scale data processing operations, are most likely to see direct engagement from the Agency once designation criteria are published.
How does this relate to Kenya’s data protection law?
The Agency’s cybersecurity mandate is separate from and complementary to the data protection framework administered by the Office of the Data Protection Commissioner. Businesses should treat compliance with each as a distinct requirement.



