Company Setup

Critical Information Infrastructure Registration Tanzania: Register by 19 December 2026

Cover: critical information infrastructure registration in Tanzania, GN No. 147 of 2026, deadline 19 December 2026
Registration of critical ICT systems under the Cybercrimes Act, for banks, telecoms, utilities, mines and other operators. As at 7 October 2026.
Direct answer

Who must register critical information infrastructure in Tanzania, and by when? Owners and operators of systems designated as critical information infrastructure (CII) must register them on the Ministry's CII portal by 19 December 2026. The duty comes from Government Notice No. 147 of 19 June 2026, made under the Cybercrimes Act. Public and private bodies are covered, on the Mainland and in Zanzibar.

The Ministry also expects owners to report a security incident within 24 hours. Bowmans reports that the Order adds a self-assessment, a contact person and controls on data hosting; we could not see the Order, so those details are marked to confirm.

What changed: a six-month window to register critical ICT systems

On 19 August 2026 the Minister for Communication and Information Technology, Angellah Kairuki, announced in Dar es Salaam that registration of critical ICT infrastructure had begun. The Ministry's release of 20 August 2026 states that the exercise runs under the Cybercrimes Act No. 14 of 2015 and Government Notice No. 147 of 19 June 2026.

The window runs from 19 June to 19 December 2026, online through the National Registry for CII portal. The targets are assets, equipment, computer systems and networks whose failure would harm security, the economy or society.

The Respondents and Michuzi Blog reported the same GN number, window and deadline. On 7 October 2026, law firm Bowmans published a client update on the Order through Polity.

As at today, 73 days remain before the deadline.

What the law says about critical information infrastructure

The power to designate CII sits in section 28 of the Cybercrimes Act, 2015, now Cap. 443 in the Revised Edition. Section 28(1) lets the Minister, by order in the Gazette, designate a computer system as critical information infrastructure. Section 28(2) lets that order prescribe guidelines or procedures on eight matters.

Those matters are registration and management; access to, transfer and control of data; data integrity and storage; disaster recovery plans; audit and inspection; and any other matter relevant to protecting CII.

Section 28(3) defines CII to include assets, devices, computer systems or networks, physical or virtual, whose incapacitation would affect national security or the economy and social well-being of citizens.

The Ministry says the Order comes with five guidelines. The Respondents lists them as identification and management, audits, risk assessment, data integrity and authenticity, and disaster recovery planning. These match the headings in section 28(2).

Who is affected by CII registration?

The Ministry names finance and banking, health, water, energy, mining, transport, agriculture, industry, education and defence, "and others", in the public and private sectors. These should assume they are in scope until they have checked the Order's schedule.

Ownership does not decide scope. The Act's test is the effect of losing the system, so a foreign-owned company is treated like a local one. Sector licensing remains in place, as our guides to Bank of Tanzania licensing and TCRA licensing explain.

How many sectors does the Order cover, 21 or 25?

Reports differ, and we could not resolve the point from the primary text. The figures come from different ways of counting.

SourceWhat it says about scopeStatus
Ministry release, 20 August 2026Lists ten sectors by name, then "and others". Gives no total.Primary, incomplete
The Respondents, 19 August 2026Names about twenty sectors, from telecoms and banking to land, public safety and security. It gives no total; counts of 21 come from counting its list.Independent report
Bowmans, 7 October 2026Says the Order designates 25 categories of CII, grouped into broader sectors such as digital infrastructure, financial systems, utilities and transport.Independent law firm

The likely reading is that the Order's schedule lists 25 categories, while the press listed sectors; transport alone can hold aviation, rail and ports. Until the schedule is checked, test your systems against both lists. If either names your activity, prepare to register.

What must an owner or operator do under the Order?

The table separates what the Ministry said from what only Bowmans reports.

ObligationWhat is saidSourceStatus
Register the CII on the portalOwners and operators register online by 19 December 2026Ministry release; GN No. 147 of 2026Settled
Report security incidentsReport to the relevant authority within 24 hours of detecting a security problemMinistry releaseSettled as Ministry instruction
Follow five guidelinesIdentification and management, audit, risk assessment, data integrity, recovery plansMinistry release; The RespondentsSettled in outline
Submit a self-assessmentAssess information systems on a prescribed form and report to the Ministry within the same periodBowmansTo confirm
Appoint a contact personA designated officer for regulatory liaison, incident reporting and complianceBowmansTo confirm
Data hosting and localisationReview offshore, cloud and backup hosting; seek Ministerial approval where neededBowmansTo confirm
Disaster recovery and auditRisk management, disaster recovery and audit obligationsBowmans; Act s.28(2)Power settled; detail to confirm

Bowmans reports that the self-assessment applies to "every government institution and private entity", not only to CII owners. If so, a business outside the designated categories may still have something to file.

The hosting point matters most for groups running core systems offshore or in a public cloud. A bank with a disaster recovery site abroad, or a mine using its parent's cloud, should read the Order's text on transfer and storage early.

Is failing to register a criminal offence?

The penalty in the news reports is real but easy to misread. Section 29 applies where a person "commits an offence under this Act or any written law in relation to critical information infrastructure".

ProvisionWhat it saysApplies to
Cybercrimes Act s.29Fine of not less than TZS 100,000,000 or three times the loss, or imprisonment of not less than 5 years, or bothAn offence under the Act or any written law, committed in relation to CII
Cybercrimes Act s.49Directors, officers and managers deemed to commit the company's offence unless they prove lack of consent or due diligenceAny offence under the Act by a body corporate
Cybercrimes Act s.50The Director of Public Prosecutions may compound an offence before court proceedings, on a voluntary admissionMainland Tanzania only, under s.2

Section 29 raises the penalty for an existing offence, such as unlawful access or damage, when the target is CII. On its face it does not make non-registration an offence, and the Ministry links the TZS 100 million figure to damage ("uharibifu").

Whether failing to register is itself an offence depends on the Order's text, which we have not seen, so it is unknown. A business that has not registered and then suffers an incident will face the regulator with no record of compliance. Bowmans puts TZS 100 million at about USD 37,000.

If an investigator calls, a system is seized, or a charge is threatened, instruct an advocate before you answer. Zatra has an advocate on the team for this, and prosecution, seizure and court matters always go to the advocate.

Can directors be personally liable?

Yes, for offences under the Act. Section 49 provides that where a company is convicted, every director or officer concerned with its management, or who knowingly authorised the act, is deemed to have committed the same offence. The defence is to prove that the offence happened without their consent, or that they exercised due diligence to prevent it.

Bowmans highlights this exposure. A board's best protection is evidence of due diligence: a board paper, a named accountable executive and minutes recording the registration decision. Our corporate governance advisory team drafts those papers.

Does the Order apply in Zanzibar?

Yes. Section 2 of the Cybercrimes Act states that, save for section 50, the Act applies to Mainland Tanzania as well as Tanzania Zanzibar. An order under section 28 therefore reaches CII in Zanzibar, and the Ministry's release names stakeholders from both sides.

PointMainland TanzaniaZanzibar
Cybercrimes Act and the CII OrderAppliesApplies, under s.2
Where to registerMinistry CII portalSame Union portal, on the Ministry's release
Compounding by the DPP under s.50AvailableExcluded by s.2; confirm with the Zanzibar DPP
Personal Data Protection ActAppliesApplies to Union matters only
Sector regulatorsBank of Tanzania, TCRA, EWURA and othersUnion regulators for Union matters; Zanzibar bodies for non-Union matters

A Zanzibar utility or port operator registers through the same portal. Where a Zanzibar regulator also sets rules for the same systems, check those with that regulator. Business registration with BPRA and investment approval with ZIPA are unaffected.

How does CII registration fit with PDPC registration?

They are separate duties under separate laws, and one does not discharge the other. The Personal Data Protection Act, 2022 requires data controllers and processors to register with the Personal Data Protection Commission (PDPC). FB Attorneys note that the Act applies to the Mainland and to Zanzibar, except for non-Union matters in Zanzibar.

PointCII registrationPDPC registration
LawCybercrimes Act s.28; GN No. 147 of 2026Personal Data Protection Act, 2022
What is registeredSystems and networks designated as CIIThe organisation as data controller or processor
AuthorityMinistry of Communication and Information TechnologyPersonal Data Protection Commission
Incident reportingWithin 24 hours, per the MinistryBreach notice to the Commission and data subjects

A bank or hospital will usually need both, and one incident can trigger two reports. Clyde & Co describe the PDPA duty to notify the Commission and affected data subjects of a breach. Build one incident playbook covering both. Our guides on PDPC registration and the consequences of not registering with the PDPC cover the data protection side.

Worked example: a mid-size bank preparing its registration

A commercial bank in Dar es Salaam (a hypothetical case) runs a core banking system, an internet and mobile banking channel and a card switch. Its primary data centre is in Dar es Salaam and its disaster recovery site is hosted by a regional provider outside Tanzania. It starts work on 12 October 2026, with 68 days to the deadline.

Timeline. The bank sets an internal target of 28 November 2026, three weeks before the legal deadline.

Budget. The figures below are internal costs built on assumed rates. Replace them with your own.

ItemBasis (assumed)Cost
Security lead15 days at TZS 450,000 a dayTZS 6,750,000
Two IT engineers25 days each at TZS 450,000 a dayTZS 22,500,000
Compliance officer and in-house counsel15 days at TZS 450,000 a dayTZS 6,750,000
Disaster recovery test, overtime and travelLump sumTZS 4,000,000
Government registration feeNone stated in the Ministry release; Order text unseenUnknown, budget TZS 0 and confirm
Total internal budgetTZS 40,000,000

The board will compare this with the section 29 floor of TZS 100,000,000 for an offence in relation to CII. The bigger risk is the offshore recovery site: if the Order requires Ministerial approval for it, approval may outlast the window.

A mining company follows the same plan, starting with its plant control network and mineral sales records. Our mining licence guide covers the licence side.

What to do now

  1. Get the Order. Obtain GN No. 147 of 2026 and its schedule from the Government Printer or the Ministry, and read the categories, forms and hosting rules.
  2. Map your systems. List every system whose loss would stop a public service, and test it against both the sector and category lists.
  3. Name a contact person. Appoint one accountable officer and a deputy, with authority to report incidents within 24 hours.
  4. Brief the board. Record the decision, the owner and the target date in minutes, as evidence of due diligence under section 49.
  5. Review hosting. Check where primary, backup and disaster recovery data sit, and whether any approval is needed.
  6. Complete the self-assessment. Use the prescribed form and keep the working papers.
  7. Register on the portal. Submit on cii.mawasiliano.go.tz well before 19 December 2026 and keep the acknowledgement.
  8. Align the PDPC file. Confirm PDPC registration and merge breach and CII incident steps into one playbook.

Key dates and deadlines

DateEventSource
19 June 2026GN No. 147 of 2026 issued; registration window opensMinistry release
19 August 2026Minister announces registration at a press conferenceMinistry release; The Respondents
28 November 2026Suggested internal submission targetZatra planning date
19 December 2026Registration deadlineMinistry release
Within 24 hours of detectionReport a security incidentMinistry release

How Zatra helps

Our internal controls and risk advisory team maps systems against the Order, drafts the board paper and tracks the self-assessment. Our digital transformation team helps your IT staff build the system inventory. Security testing stays with your IT team or a qualified security firm.

For a quick scope check, book a Senior Advisory Session at USD 49. Ongoing deadlines, including PDPC, fit our Compliance Renewal package at USD 900 to 1,200 a year. Prices are on our pricing page.

Any government fee is paid by the client to the authority at the official rate against its own control number. It is separate from Zatra's professional fee and never marked up. No CII fee appears in our government fees handbook. Prosecution, seizure, disputes, court or tribunal work and legal opinions go to our advocate. Zatra prepares and coordinates the file; it does not decide or guarantee any authority's outcome.

Sources and status

Accurate as at 7 October 2026.

Figures to confirm before you act

This article is general information based on official sources available at the date of publication. It is not legal, tax or financial advice. Laws and notices change. Verify with the issuing authority or consult Zatra before acting.

Frequently asked questions

Is there a fee to register on the CII portal?

The Ministry's release mentions no registration fee, and we have not seen the Order's text. Budget for internal staff time, and confirm on the portal whether any charge applies. If one does, pay it only against an official control number.

Does a small company with one office server need to register?

Probably not, unless the system supports a service in a designated category, such as payments or health records. Check the Order's schedule and keep a short note of the reasoning.

Who registers when a cloud provider hosts the system?

The Ministry refers to owners and operators, which can mean both client and provider. Until the Order settles it, agree in writing who files, and name both parties and the hosting location.

What happens after 19 December 2026 if we have not registered?

Register as soon as possible and keep evidence of the steps taken. The Order's text will show whether late registration carries a sanction. If the Ministry or an investigator contacts you, take advice from an advocate before replying.

Can a foreign parent company register on behalf of its Tanzanian subsidiary?

The duty falls on the owner or operator of the system in Tanzania. A parent can prepare the information, but the local entity should file in its own name and appoint a contact person who can act within 24 hours.

Does the 24-hour incident report replace reporting to the Bank of Tanzania or TCRA?

Nothing in the Ministry's release says so. A licensed bank or telecom should assume it reports to its sector regulator, the CII authority and, for personal data, the PDPC.

Do Zanzibar businesses use a separate registry?

No separate Zanzibar registry has been announced. The Cybercrimes Act is a Union law that applies in Zanzibar, and the Ministry's portal serves both sides. Zanzibar sector regulators may add their own rules.

Will the Ministry audit registered systems?

Section 28(2)(g) lets the Order set the manner and procedure for audit and inspection of CII, and Bowmans reports audit obligations in the Order. How often audits happen, and who carries them out, is not stated in the sources we could read.

Sources & regulators

Verify before filing: Rates, forms and thresholds move by Finance Act, Government Notice and portal revision. Confirm the live schedule on the mandate-holder portal before you budget or submit. Law-firm alerts and Big Four notes are discovery only.

Brief the desk

This Insights page is orientation. Internal controls and risk advisory is the commercial desk for the same facts. Zatra’s fee stays on its own line, separate from government, bank and regulator charges. Approvals are not guaranteed.

Book a 20-minute file check PDPC registration and compliance in Tanzania

+255 788 466 212 · [email protected] · WhatsApp +255 747 912 965

Disclaimer

This article is informational orientation. It is not legal, tax or investment advice and not a government decision. Tanzanian instruments move by Act, Government Notice, Finance Act and portal revision. If a sentence here disagrees with the live mandate-holder, the mandate-holder wins. Zatra Consultants Limited does not issue licences, permits, tax clearances or approvals, and gives no assurance of any regulatory or banking outcome. Professional fees are published only on /pricing/.

Office Line +255 788 466 212
Ask Senior Desk on WhatsApp