Kenya Network Equipment Type Approval: Draft CA.TS.520:2026 Open for Comment
Kenya Opens Consultation on Network Equipment Technical Specifications (CA.TS.520:2026)
The Communications Authority of Kenya (CA) has launched a public consultation on the draft Technical Specifications for Network Equipment, 2026 (CA.TS.520:2026, Version 1.0). The document is intended to become the technical reference for type approval of IP network equipment that is marketed or used in Kenya.
Manufacturers, importers, licensees and other stakeholders may submit comments until September 30, 2026. This is a consultation deadline, not a compliance date: the draft lists its effective date as "TBD."
Regulatory Background
The CA regulates Kenya's ICT sector under the Kenya Information and Communications Act, 1998. As part of that mandate, it operates a mandatory type approval regime. Under this regime, telecommunications equipment is assessed against technical requirements before it can be marketed or connected to public networks.
Until now, Kenya has not had a dedicated, consolidated technical specification for IP network infrastructure equipment. CA.TS.520:2026 fills that gap. The draft states four objectives:
Improve interoperability across network platforms.
Strengthen security compliance.
Promote reliable network operations.
Support the implementation of the Authority's IPv4 to IPv6 Migration Strategy.
Scope: Which Equipment Falls Under Kenya Network Equipment Type Approval?
The draft covers network devices capable of connecting to public telecommunication networks. That includes the PSTN, public land mobile networks (PLMN), computer networks and broadcasting networks. The listed product categories are:
Switches
Routers
Firewalls
Gateways
Servers
Network interface cards (NICs)
Session border controllers (SBCs)
The specification also applies to devices that use management protocols (e.g. SNMP), security protocols (e.g. SSL/TLS) and communication protocols (e.g. HTTP). It further covers routed protocols (e.g. IP) and routing protocols (e.g. BGP, RIP).

Key Technical Requirements in CA.TS.520:2026
Clause | Area | Proposed Requirement | Reference Cited |
4.1 | Electrical power | 240 VAC ±10%, 50 Hz; PSU efficiency of at least platinum level | Kenya National Distribution Grid Code 2024; EU ESPR |
4.2 | Network protocols | Mandatory IPv6 and IPv6 Enhanced ("IPv6+") support; at least one management, security and communication protocol; at least one routing and routed protocol | IETF RFC 8200; CA IPv6 Migration Strategy |
4.3 | Interoperability | Compatibility with ASIC-, TCAM- and CAM-based switching; MPLS architecture support | RFC 5036, ITU-T G.8121, RFC 3031 |
4.4–4.5 | EMC | Radiated and conducted emission limits for industrial and residential environments (mains and telecom ports) | EN 55022:2006 |
4.6 | Security | ACLs, IPS/IDS, latest IPSec, TLS and SSH; secure update, access control, storage, communication and monitoring mechanisms | IETF RFC 4301, RFC 5246; ITU-T X.1034; EN 18031-1:2024 |
4.7 | Environmental | Operation from 5 °C to 45 °C, relative humidity up to 80% | ANSI/TIA-569-E-1 |
4.8 | Safety | Restricted access to energized parts; touch-temperature limits; IEC 60417-5041 marking where limits are exceeded | IEC 62368-1 |
4.9 | RoHS | No lead, mercury, cadmium or other hazardous substances | Directive 2011/65/EU |
4.10 | E-waste & DPP | At least 3 years remaining before end-of-life for imported equipment; mandatory Digital Product Passport | ETSI TS 103 199; EU ESPR 2024/1781 |
4.11 | Accessibility | Multi-modal operation, tactile markings, audible port-status tones and standardized connectors (end-user equipment) | Kenya Standard KS 2952 |
4.12 | Quality of Service | IPTD ≤100 ms voice / 400 ms data; IPDV ≤50 ms; IPLR 0.1%; IPER 0.01%; at least two QoS frameworks; MPLS DiffServ | ITU-T Y.1541; RFC 3270 |
4.13 | Artificial intelligence | AI-enabled equipment must safeguard safety, transparency, privacy and IP rights; human-machine interface for high-risk AI | EU AI Act, 2024 |
Digital Product Passport (DPP)
One of the most significant new elements is the requirement for every network equipment unit to be accompanied by a Digital Product Passport. The DPP must contain five categories of information:
Product identity: manufacturer details and model numbers.
Materials and components: raw materials, recycled content and hazardous substances.
Environmental footprint: recyclability, carbon footprint and energy efficiency.
Compliance and safety: certifications and the Declaration of Conformity (DoC).
Life-cycle data: disposal guidelines and repair instructions.
The DPP must be accessible through a QR code, RFID tag, NFC chip, barcode or online portal. This makes Kenya one of the first African markets to propose a DPP obligation modeled on the EU Ecodesign for Sustainable Products Regulation (ESPR).
What This Means for Manufacturers
CA.TS.520:2026 goes well beyond a conventional EMC-and-safety type approval scheme. If it is adopted as drafted, manufacturers and importers of network equipment should expect the following impacts.
1. IPv6 becomes a gating requirement. Equipment without IPv6 support, and without some support for IPv6+ capabilities, may not qualify for type approval. Legacy or IPv4-only product lines could be excluded from the Kenyan market.
2. Cybersecurity evidence will be required. The reference to EN 18031-1:2024 aligns Kenya with the EU Radio Equipment Directive cybersecurity framework. Test reports or technical documentation showing secure update, access control, secure storage and secure communication mechanisms are likely to become part of the application file.
3. New documentation beyond test reports. The DPP, platinum-level PSU efficiency evidence, RoHS declarations and end-of-life data require input from sustainability, supply-chain and product lifecycle teams, not only certification engineers.
4. Portfolio and lifecycle restrictions. Imported equipment must have at least three years remaining before end-of-life. This could affect sales of mature or discontinued models and the shipment of refurbished equipment.
5. AI-enabled features come under scrutiny. Products that include AI-driven functions, such as AI-based traffic management or threat detection, may need to show how they address transparency, privacy and human oversight.
6. There is a window to shape the final text. Several provisions could benefit from clarification during the consultation, for example:
Emissions standard: the EMC clauses reference EN 55022:2006, which has since been superseded by EN 55032.
TLS version: the TLS clause cites RFC 5246 (TLS 1.2) while requiring the "latest version."
Touch-temperature limits: the limits include body-worn contact categories that are uncommon for network infrastructure equipment.
DPP and AI implementation: the DPP format and the definition of "high-risk" AI in network equipment are not yet specified.
Stakeholders are encouraged to raise these points through the CA's comments template.
Certification Impact Summary
Impact Area | Current Situation | Proposed under CA.TS.520:2026 | Impact Level |
Type approval scope | Network equipment approved under general CA type approval requirements | Dedicated specification for switches, routers, firewalls, gateways, servers, NICs and SBCs | High |
Test reports | EMC, safety (and RF where applicable) | EMC, IEC 62368-1 safety, plus evidence of protocol, security and QoS capability | High |
IPv6 | Encouraged under the national migration strategy | Mandatory IPv6 and IPv6+ support | High |
Cybersecurity | Not specifically required for network equipment | ACLs, IPS/IDS, IPSec, TLS, SSH, EN 18031-1 mechanisms | High |
Energy efficiency | No specific PSU requirement | Minimum platinum-level PSU efficiency | Medium |
Environmental / RoHS | General requirements | RoHS compliance, 3-year minimum remaining life, Digital Product Passport | High |
Accessibility | Not specified for network equipment | KS 2952-based accessibility features | Medium |
AI-enabled equipment | Not addressed | Safety, transparency, privacy and human-oversight safeguards | Medium |
Compliance date | N/A | Effective date TBD (not yet mandatory) | — |
Timeline and Required Actions
Date / Phase | Milestone | Required Action for Manufacturers and Importers |
September 2026 | CA publishes draft CA.TS.520:2026 (Version 1.0) and opens public consultation | Download the draft and comments template; identify affected product lines |
Now – September 30, 2026 | Consultation period open | Perform a gap analysis against clauses 4.1–4.13; prepare technical comments on unclear or problematic provisions |
September 30, 2026 | Deadline for stakeholder comments | Submit comments using the CA template to specifications@ca.go.ke |
Q4 2026 onward (expected) | CA reviews submissions; a stakeholder validation exercise may follow, as the CA has held for other 2026 drafts | Monitor CA notices; take part in any validation forum |
TBD | Final specification published with an effective date | Update test plans, DPP documentation and type approval files; confirm any transition period for existing approvals |
After the effective date | New requirements apply to type approval applications | Apply for, or renew, type approval under CA.TS.520:2026 |
Recommended Action Checklist
Map your portfolio of switches, routers, firewalls, gateways, servers, NICs and SBCs intended for Kenya.
Confirm IPv6/IPv6+, MPLS and QoS capabilities for each model.
Check whether current EMC reports (EN 55032 / CISPR 32) and IEC 62368-1 reports meet the proposed clauses.
Assess cybersecurity documentation against EN 18031-1 and the required security protocols.
Verify PSU efficiency ratings and RoHS declarations.
Review end-of-life dates for models planned for import into Kenya.
Start preparing Digital Product Passport data and choose an access method (QR code, NFC, RFID, barcode or portal).
Identify any AI-enabled features and document their safeguards.
Submit consultation comments by September 30, 2026.
Conclusion
CA.TS.520:2026 is a major step in modernizing Kenya network equipment type approval. It moves the framework beyond basic EMC and safety testing to cover IPv6 readiness, cybersecurity, sustainability, accessibility and AI governance. The requirements are not yet mandatory, but the draft signals clearly where Kenya's certification regime is heading.
Manufacturers and importers who review the draft now, submit targeted comments before September 30, 2026, and begin gap analyses early will be best placed to maintain uninterrupted market access once the final specification takes effect.
