Critical Information Infrastructure Registration Tanzania: Register by 19 December 2026

Who must register critical information infrastructure in Tanzania, and by when? Owners and operators of systems designated as critical information infrastructure (CII) must register them on the Ministry's CII portal by 19 December 2026. The duty comes from Government Notice No. 147 of 19 June 2026, made under the Cybercrimes Act. Public and private bodies are covered, on the Mainland and in Zanzibar.
The Ministry also expects owners to report a security incident within 24 hours. Bowmans reports that the Order adds a self-assessment, a contact person and controls on data hosting; we could not see the Order, so those details are marked to confirm.
What changed: a six-month window to register critical ICT systems
On 19 August 2026 the Minister for Communication and Information Technology, Angellah Kairuki, announced in Dar es Salaam that registration of critical ICT infrastructure had begun. The Ministry's release of 20 August 2026 states that the exercise runs under the Cybercrimes Act No. 14 of 2015 and Government Notice No. 147 of 19 June 2026.
The window runs from 19 June to 19 December 2026, online through the National Registry for CII portal. The targets are assets, equipment, computer systems and networks whose failure would harm security, the economy or society.
The Respondents and Michuzi Blog reported the same GN number, window and deadline. On 7 October 2026, law firm Bowmans published a client update on the Order through Polity.
As at today, 73 days remain before the deadline.
What the law says about critical information infrastructure
The power to designate CII sits in section 28 of the Cybercrimes Act, 2015, now Cap. 443 in the Revised Edition. Section 28(1) lets the Minister, by order in the Gazette, designate a computer system as critical information infrastructure. Section 28(2) lets that order prescribe guidelines or procedures on eight matters.
Those matters are registration and management; access to, transfer and control of data; data integrity and storage; disaster recovery plans; audit and inspection; and any other matter relevant to protecting CII.
Section 28(3) defines CII to include assets, devices, computer systems or networks, physical or virtual, whose incapacitation would affect national security or the economy and social well-being of citizens.
The Ministry says the Order comes with five guidelines. The Respondents lists them as identification and management, audits, risk assessment, data integrity and authenticity, and disaster recovery planning. These match the headings in section 28(2).
Who is affected by CII registration?
The Ministry names finance and banking, health, water, energy, mining, transport, agriculture, industry, education and defence, "and others", in the public and private sectors. These should assume they are in scope until they have checked the Order's schedule.
- Banks, payment system operators and mobile money providers: core banking, card switches and payment rails.
- Telecom, internet and broadcasting licensees, including tower, cable landing and data centre operators.
- Energy, water and transport operators: control systems for power, pipelines, ports, rail and aviation.
- Mining companies running processing plants, mineral trading systems or site networks.
- Hospitals and health insurers holding patient records and clinical systems.
- Government agencies and public bodies, covered on the same footing.
- Cloud and managed service providers running any of the above for a client.
Ownership does not decide scope. The Act's test is the effect of losing the system, so a foreign-owned company is treated like a local one. Sector licensing remains in place, as our guides to Bank of Tanzania licensing and TCRA licensing explain.
How many sectors does the Order cover, 21 or 25?
Reports differ, and we could not resolve the point from the primary text. The figures come from different ways of counting.
| Source | What it says about scope | Status |
|---|---|---|
| Ministry release, 20 August 2026 | Lists ten sectors by name, then "and others". Gives no total. | Primary, incomplete |
| The Respondents, 19 August 2026 | Names about twenty sectors, from telecoms and banking to land, public safety and security. It gives no total; counts of 21 come from counting its list. | Independent report |
| Bowmans, 7 October 2026 | Says the Order designates 25 categories of CII, grouped into broader sectors such as digital infrastructure, financial systems, utilities and transport. | Independent law firm |
The likely reading is that the Order's schedule lists 25 categories, while the press listed sectors; transport alone can hold aviation, rail and ports. Until the schedule is checked, test your systems against both lists. If either names your activity, prepare to register.
What must an owner or operator do under the Order?
The table separates what the Ministry said from what only Bowmans reports.
| Obligation | What is said | Source | Status |
|---|---|---|---|
| Register the CII on the portal | Owners and operators register online by 19 December 2026 | Ministry release; GN No. 147 of 2026 | Settled |
| Report security incidents | Report to the relevant authority within 24 hours of detecting a security problem | Ministry release | Settled as Ministry instruction |
| Follow five guidelines | Identification and management, audit, risk assessment, data integrity, recovery plans | Ministry release; The Respondents | Settled in outline |
| Submit a self-assessment | Assess information systems on a prescribed form and report to the Ministry within the same period | Bowmans | To confirm |
| Appoint a contact person | A designated officer for regulatory liaison, incident reporting and compliance | Bowmans | To confirm |
| Data hosting and localisation | Review offshore, cloud and backup hosting; seek Ministerial approval where needed | Bowmans | To confirm |
| Disaster recovery and audit | Risk management, disaster recovery and audit obligations | Bowmans; Act s.28(2) | Power settled; detail to confirm |
Bowmans reports that the self-assessment applies to "every government institution and private entity", not only to CII owners. If so, a business outside the designated categories may still have something to file.
The hosting point matters most for groups running core systems offshore or in a public cloud. A bank with a disaster recovery site abroad, or a mine using its parent's cloud, should read the Order's text on transfer and storage early.
Is failing to register a criminal offence?
The penalty in the news reports is real but easy to misread. Section 29 applies where a person "commits an offence under this Act or any written law in relation to critical information infrastructure".
| Provision | What it says | Applies to |
|---|---|---|
| Cybercrimes Act s.29 | Fine of not less than TZS 100,000,000 or three times the loss, or imprisonment of not less than 5 years, or both | An offence under the Act or any written law, committed in relation to CII |
| Cybercrimes Act s.49 | Directors, officers and managers deemed to commit the company's offence unless they prove lack of consent or due diligence | Any offence under the Act by a body corporate |
| Cybercrimes Act s.50 | The Director of Public Prosecutions may compound an offence before court proceedings, on a voluntary admission | Mainland Tanzania only, under s.2 |
Section 29 raises the penalty for an existing offence, such as unlawful access or damage, when the target is CII. On its face it does not make non-registration an offence, and the Ministry links the TZS 100 million figure to damage ("uharibifu").
Whether failing to register is itself an offence depends on the Order's text, which we have not seen, so it is unknown. A business that has not registered and then suffers an incident will face the regulator with no record of compliance. Bowmans puts TZS 100 million at about USD 37,000.
If an investigator calls, a system is seized, or a charge is threatened, instruct an advocate before you answer. Zatra has an advocate on the team for this, and prosecution, seizure and court matters always go to the advocate.
Can directors be personally liable?
Yes, for offences under the Act. Section 49 provides that where a company is convicted, every director or officer concerned with its management, or who knowingly authorised the act, is deemed to have committed the same offence. The defence is to prove that the offence happened without their consent, or that they exercised due diligence to prevent it.
Bowmans highlights this exposure. A board's best protection is evidence of due diligence: a board paper, a named accountable executive and minutes recording the registration decision. Our corporate governance advisory team drafts those papers.
Does the Order apply in Zanzibar?
Yes. Section 2 of the Cybercrimes Act states that, save for section 50, the Act applies to Mainland Tanzania as well as Tanzania Zanzibar. An order under section 28 therefore reaches CII in Zanzibar, and the Ministry's release names stakeholders from both sides.
| Point | Mainland Tanzania | Zanzibar |
|---|---|---|
| Cybercrimes Act and the CII Order | Applies | Applies, under s.2 |
| Where to register | Ministry CII portal | Same Union portal, on the Ministry's release |
| Compounding by the DPP under s.50 | Available | Excluded by s.2; confirm with the Zanzibar DPP |
| Personal Data Protection Act | Applies | Applies to Union matters only |
| Sector regulators | Bank of Tanzania, TCRA, EWURA and others | Union regulators for Union matters; Zanzibar bodies for non-Union matters |
A Zanzibar utility or port operator registers through the same portal. Where a Zanzibar regulator also sets rules for the same systems, check those with that regulator. Business registration with BPRA and investment approval with ZIPA are unaffected.
How does CII registration fit with PDPC registration?
They are separate duties under separate laws, and one does not discharge the other. The Personal Data Protection Act, 2022 requires data controllers and processors to register with the Personal Data Protection Commission (PDPC). FB Attorneys note that the Act applies to the Mainland and to Zanzibar, except for non-Union matters in Zanzibar.
| Point | CII registration | PDPC registration |
|---|---|---|
| Law | Cybercrimes Act s.28; GN No. 147 of 2026 | Personal Data Protection Act, 2022 |
| What is registered | Systems and networks designated as CII | The organisation as data controller or processor |
| Authority | Ministry of Communication and Information Technology | Personal Data Protection Commission |
| Incident reporting | Within 24 hours, per the Ministry | Breach notice to the Commission and data subjects |
A bank or hospital will usually need both, and one incident can trigger two reports. Clyde & Co describe the PDPA duty to notify the Commission and affected data subjects of a breach. Build one incident playbook covering both. Our guides on PDPC registration and the consequences of not registering with the PDPC cover the data protection side.
Worked example: a mid-size bank preparing its registration
A commercial bank in Dar es Salaam (a hypothetical case) runs a core banking system, an internet and mobile banking channel and a card switch. Its primary data centre is in Dar es Salaam and its disaster recovery site is hosted by a regional provider outside Tanzania. It starts work on 12 October 2026, with 68 days to the deadline.
Timeline. The bank sets an internal target of 28 November 2026, three weeks before the legal deadline.
- 12 to 23 October: obtain the Order and map systems against both lists.
- 26 October to 6 November: name the contact person and brief the board.
- 9 to 20 November: complete the self-assessment and review offshore hosting.
- 23 to 28 November: open the portal account and submit.
- December: answer queries and file the acknowledgement.
Budget. The figures below are internal costs built on assumed rates. Replace them with your own.
| Item | Basis (assumed) | Cost |
|---|---|---|
| Security lead | 15 days at TZS 450,000 a day | TZS 6,750,000 |
| Two IT engineers | 25 days each at TZS 450,000 a day | TZS 22,500,000 |
| Compliance officer and in-house counsel | 15 days at TZS 450,000 a day | TZS 6,750,000 |
| Disaster recovery test, overtime and travel | Lump sum | TZS 4,000,000 |
| Government registration fee | None stated in the Ministry release; Order text unseen | Unknown, budget TZS 0 and confirm |
| Total internal budget | TZS 40,000,000 |
The board will compare this with the section 29 floor of TZS 100,000,000 for an offence in relation to CII. The bigger risk is the offshore recovery site: if the Order requires Ministerial approval for it, approval may outlast the window.
A mining company follows the same plan, starting with its plant control network and mineral sales records. Our mining licence guide covers the licence side.
What to do now
- Get the Order. Obtain GN No. 147 of 2026 and its schedule from the Government Printer or the Ministry, and read the categories, forms and hosting rules.
- Map your systems. List every system whose loss would stop a public service, and test it against both the sector and category lists.
- Name a contact person. Appoint one accountable officer and a deputy, with authority to report incidents within 24 hours.
- Brief the board. Record the decision, the owner and the target date in minutes, as evidence of due diligence under section 49.
- Review hosting. Check where primary, backup and disaster recovery data sit, and whether any approval is needed.
- Complete the self-assessment. Use the prescribed form and keep the working papers.
- Register on the portal. Submit on cii.mawasiliano.go.tz well before 19 December 2026 and keep the acknowledgement.
- Align the PDPC file. Confirm PDPC registration and merge breach and CII incident steps into one playbook.
Key dates and deadlines
| Date | Event | Source |
|---|---|---|
| 19 June 2026 | GN No. 147 of 2026 issued; registration window opens | Ministry release |
| 19 August 2026 | Minister announces registration at a press conference | Ministry release; The Respondents |
| 28 November 2026 | Suggested internal submission target | Zatra planning date |
| 19 December 2026 | Registration deadline | Ministry release |
| Within 24 hours of detection | Report a security incident | Ministry release |
How Zatra helps
Our internal controls and risk advisory team maps systems against the Order, drafts the board paper and tracks the self-assessment. Our digital transformation team helps your IT staff build the system inventory. Security testing stays with your IT team or a qualified security firm.
For a quick scope check, book a Senior Advisory Session at USD 49. Ongoing deadlines, including PDPC, fit our Compliance Renewal package at USD 900 to 1,200 a year. Prices are on our pricing page.
Any government fee is paid by the client to the authority at the official rate against its own control number. It is separate from Zatra's professional fee and never marked up. No CII fee appears in our government fees handbook. Prosecution, seizure, disputes, court or tribunal work and legal opinions go to our advocate. Zatra prepares and coordinates the file; it does not decide or guarantee any authority's outcome.
Sources and status
Accurate as at 7 October 2026.
- Usajili wa Miundombinu Muhimu ya TEHAMA kuimarisha ulinzi na usalama wa huduma za kidijitali: Ministry of Communication and Information Technology, 20 Aug 2026. Accessed 7 Oct 2026.
- National Registry for Critical Information Infrastructure portal: Ministry of Communication and Information Technology, live 2026; the page did not load from our location. Accessed 7 Oct 2026.
- Cybercrimes Act, 2015 (Act No. 14 of 2015), ss.2, 28, 29, 49 and 50: TanzLII, as commenced 1 Sep 2015, an 11 Oct 2024 amendment not yet applied. Accessed 7 Oct 2026.
- Cybercrimes Act, Chapter 443, PDF: TanzLII, text as at 2015. Accessed 7 Oct 2026.
- Personal Data Protection Act, 2022 (Act No. 11 of 2022): TanzLII, 2 Dec 2022. Accessed 7 Oct 2026.
- Tanzania: Regulatory Update on Critical Information Infrastructure: Bowmans (Charles Mmasi and Flora Mukasa), via Polity, 7 Oct 2026. Accessed 7 Oct 2026.
- Tanzania gives six months to register critical ICT infrastructure: The Respondents, 19 Aug 2026. Accessed 7 Oct 2026.
- Serikali yatoa miezi sita kukamilisha usajili wa miundombinu muhimu ya TEHAMA: Michuzi Blog, 19 Aug 2026. Accessed 7 Oct 2026.
- Serikali yaweka adhabu kali kwa wanaoharibu miundombinu muhimu ya TEHAMA: Msumba News Blog, Aug 2026. Accessed 7 Oct 2026.
- Scope of the Personal Data Protection Act: FB Attorneys, 6 May 2024. Accessed 7 Oct 2026.
- Key obligations for data controllers and data processors under Tanzania's Personal Data Protection Act: Clyde & Co, 13 Feb 2025. Accessed 7 Oct 2026.
Figures to confirm before you act
- GN No. 147 of 19 June 2026: from the Ministry release; the gazetted Order text was not available to us
- 25 categories against about 20 or 21 sectors: unresolved; check the Order's schedule
- Self-assessment, contact person and offshore hosting approval: reported by Bowmans only; confirm in the Order
- Whether non-registration is itself an offence: unknown; s.29 applies to offences in relation to CII
- Section numbers in Cap. 443 R.E. 2023: taken from the 2015 Act on TanzLII; an 11 Oct 2024 amendment is not yet consolidated there
- Registration fee: none stated by the Ministry; confirm on the portal
- Worked example budget of TZS 40,000,000: internal costs on assumed rates, not government charges
This article is general information based on official sources available at the date of publication. It is not legal, tax or financial advice. Laws and notices change. Verify with the issuing authority or consult Zatra before acting.
Frequently asked questions
Is there a fee to register on the CII portal?
The Ministry's release mentions no registration fee, and we have not seen the Order's text. Budget for internal staff time, and confirm on the portal whether any charge applies. If one does, pay it only against an official control number.
Does a small company with one office server need to register?
Probably not, unless the system supports a service in a designated category, such as payments or health records. Check the Order's schedule and keep a short note of the reasoning.
Who registers when a cloud provider hosts the system?
The Ministry refers to owners and operators, which can mean both client and provider. Until the Order settles it, agree in writing who files, and name both parties and the hosting location.
What happens after 19 December 2026 if we have not registered?
Register as soon as possible and keep evidence of the steps taken. The Order's text will show whether late registration carries a sanction. If the Ministry or an investigator contacts you, take advice from an advocate before replying.
Can a foreign parent company register on behalf of its Tanzanian subsidiary?
The duty falls on the owner or operator of the system in Tanzania. A parent can prepare the information, but the local entity should file in its own name and appoint a contact person who can act within 24 hours.
Does the 24-hour incident report replace reporting to the Bank of Tanzania or TCRA?
Nothing in the Ministry's release says so. A licensed bank or telecom should assume it reports to its sector regulator, the CII authority and, for personal data, the PDPC.
Do Zanzibar businesses use a separate registry?
No separate Zanzibar registry has been announced. The Cybercrimes Act is a Union law that applies in Zanzibar, and the Ministry's portal serves both sides. Zanzibar sector regulators may add their own rules.
Will the Ministry audit registered systems?
Section 28(2)(g) lets the Order set the manner and procedure for audit and inspection of CII, and Bowmans reports audit obligations in the Order. How often audits happen, and who carries them out, is not stated in the sources we could read.
Sources & regulators
Verify before filing: Rates, forms and thresholds move by Finance Act, Government Notice and portal revision. Confirm the live schedule on the mandate-holder portal before you budget or submit. Law-firm alerts and Big Four notes are discovery only.
- Ministry of Communication and Information Technology: Usajili wa Miundombinu Muhimu ya TEHAMA: Ministry of Communication and Information Technology, published 20 Aug 2026; primary source for GN No. 147, deadline, 24-hour reporting, read 7 Oct 2026. Accessed 2026-10-07.
- National Registry for Critical Information Infrastructure portal: Ministry of Communication and Information Technology, live 2026; primary source, did not load from our location on 7 Oct 2026. Accessed 2026-10-07.
- Cybercrimes Act, 2015 (Act No. 14 of 2015): TanzLII, commenced 1 Sep 2015, 2024 amendment not yet applied; primary source for ss.2, 28, 29, 49, 50, read 7 Oct 2026. Accessed 2026-10-07.
- Cybercrimes Act, Chapter 443 (PDF): TanzLII, text as at 2015; primary source, read 7 Oct 2026. Accessed 2026-10-07.
- Personal Data Protection Act, 2022: TanzLII, version 2 Dec 2022; primary source, read 7 Oct 2026. Accessed 2026-10-07.
- Bowmans: Tanzania: Regulatory Update on Critical Information Infrastructure: independent law firm update via Polity, published 7 Oct 2026. Accessed 2026-10-07.
- The Respondents: Tanzania gives six months to register critical ICT infrastructure: independent news report, published 19 Aug 2026. Accessed 2026-10-07.
- Michuzi Blog: Serikali yatoa miezi sita kukamilisha usajili: independent Swahili news report, published 19 Aug 2026. Accessed 2026-10-07.
- Msumba News: Serikali yaweka adhabu kali: independent Swahili news report, published Aug 2026. Accessed 2026-10-07.
- FB Attorneys: Scope of the Personal Data Protection Act: independent law firm note, published 6 May 2024. Accessed 2026-10-07.
- Clyde & Co: Key obligations for data controllers and data processors under Tanzania's PDPA: independent law firm note, published 13 Feb 2025. Accessed 2026-10-07.
Disclaimer
This article is informational orientation. It is not legal, tax or investment advice and not a government decision. Tanzanian instruments move by Act, Government Notice, Finance Act and portal revision. If a sentence here disagrees with the live mandate-holder, the mandate-holder wins. Zatra Consultants Limited does not issue licences, permits, tax clearances or approvals, and gives no assurance of any regulatory or banking outcome. Professional fees are published only on /pricing/.
