Kiribati Cybersecurity Act 2026: Critical Infrastructure Law
Kiribati Cybersecurity Act 2026: MICT Publishes National Framework for Critical Infrastructure Protection and Incident Reporting
The Ministry of Information, Communications and Transport (MICT) of Kiribati has published the Cybersecurity Act 2026 (Act No. 7 of 2026) on its official website. The Bill was passed by the Maneaba ni Maungatabu, Kiribati's parliament, on 23 April 2026, and MICT released the enacted text on 4 August 2026.
The Act is Kiribati's first dedicated cybersecurity statute. It assigns national responsibility for cybersecurity to the Digital Transformation Office (DTO), creates a National Computer Emergency Response Team (CERT), and sets binding obligations for operators of designated critical infrastructure. It does not introduce a product certification scheme, but it does create supply chain duties that will reach equipment manufacturers and technology vendors through their customers.
The Act will come into force on a date appointed by the Minister by notice. The published copy does not state a commencement date.
Key Facts at a Glance
Item | Detail |
Instrument | Cybersecurity Act 2026 (Act No. 7 of 2026) |
Country | Republic of Kiribati |
Publishing authority | Ministry of Information, Communications and Transport (MICT) |
Lead agency | Digital Transformation Office (DTO) |
Passed by parliament | 23 April 2026 |
Published by MICT | 4 August 2026 |
Commencement | Date to be appointed by ministerial notice |
Who is regulated | Operators of designated critical infrastructure |
Incident reporting deadline | 24 hours from detection of a significant incident |
Maximum fine for non-compliance | $100,000 (first offence), $200,000 (subsequent offence) |
Official text |
Regulatory Background
Until now, Kiribati's cyber legislation focused on criminal conduct and government digital services. The Cybercrime Act 2021 established computer-related offences, and the Digital Government Act 2023 created the DTO and contained early provisions on critical digital infrastructure and a national CERT. A Data Protection Act 2025 has also been published by MICT.
The Cybersecurity Act 2026 consolidates the cybersecurity elements into a standalone law. It repeals the definitions of "critical digital infrastructure" and "national computer emergency response team" in the Digital Government Act 2023, together with Division 4 of Part II and sections 22, 23 and 28 of that Act, and replaces them with a fuller regime.
What the Kiribati Cybersecurity Act 2026 Introduces
A national institutional framework
The DTO becomes the lead agency for national cybersecurity. Its functions include developing the national cybersecurity strategy, issuing cybersecurity standards for critical infrastructure, maintaining a register of that infrastructure, conducting audits, inspections and penetration testing, and supervising the CERTs.
Three bodies support the DTO:
National CERT. Operated by the DTO, with contact points available around the clock. It receives and assesses incident reports, provides incident response services, maintains an incident register and may classify incidents by severity.
Sectoral CERTs. The DTO may direct operators in a given sector to establish a sector-specific CERT. Unless decided otherwise, the operators in that sector bear the cost.
Kiribati Cybersecurity Working Group. A multi-stakeholder forum chaired by the DTO, with members drawn from ICT professionals, critical infrastructure operators, government, law enforcement, academia and civil society. It advises on standards, alerts and policy.
Designation of critical infrastructure
The Minister, acting on the advice of the Director of the DTO, may designate physical, electronic or virtual assets, networks and information systems as critical infrastructure where they are essential to national security or to the economic and social well-being of the population. Virtual assets expressly include software-based and remotely accessed infrastructure.
The sectors the Minister must consider are:
Electronic communications
Banking and financial services
Electric power
Water and wastewater
Healthcare and public health
Agriculture and food distribution
Emergency services
Fisheries
Tourism
Public transportation
The legislature, executive, judiciary, law enforcement and security agencies
The definition of "operator" is broad. It covers any person or entity that owns, operates, manages or controls critical infrastructure or the information systems supporting it. Where several entities perform those functions, each is treated as an operator.
Obligations of critical infrastructure operators
Obligation | Requirement | Section |
Registration changes | Notify the DTO of any change of ownership or operator within 30 days | 13 |
Information requests | Supply information requested by the DTO; report material changes to design, configuration or security within 30 days | 14 |
Standards and audits | Comply with DTO cybersecurity standards; submit to audits and inspections | 15 |
Periodic assessments | Conduct cybersecurity assessments and submit copies to the DTO | 16 |
Governance | Appoint a senior manager as Chief Information Security Officer or equivalent | 17 |
Policies and records | Maintain proportionate technical and organisational policies; keep compliance records | 18 |
Risk management | Establish, maintain and regularly update a cybersecurity risk management framework | 19 |
Supply chain | Manage risks from third-party suppliers, service providers and contractors through contractual, technical and organisational safeguards | 20 |
Incident reporting | Report significant incidents to the National CERT and any Sectoral CERT within 24 hours of detection; allow CERT access to networks for analysis | 21 |
Remedial orders | Comply with orders to take preventative, mitigating or remedial action | 22 |
Operators that cannot comply for financial, legal or technical reasons must inform the DTO. The Director may grant exceptions or modify the prescribed standards.
National cybersecurity emergency
Where a serious threat affects national security or critical infrastructure, the Minister may declare a cybersecurity emergency and direct operators to implement specified measures. Directions must be proportionate and limited in duration.
Information sharing
The DTO, CERTs and operators may share information with each other and with foreign authorities for the purposes of the Act, national security or crime prevention. Entities that share incident or vulnerability information in good faith are protected from civil and criminal liability for the disclosure, and that information cannot be used against them in civil or administrative proceedings unless provided in bad faith.
Enforcement and penalties
Offence | Penalty |
Operator fails to carry out its obligations without an exemption (s. 25) | Fine up to $100,000 for a first offence; up to $200,000 for a subsequent offence; up to $200 per day for a continuing offence |
Removing, destroying, altering or damaging critical infrastructure without lawful authority (s. 26) | Fine up to $200,000, imprisonment up to 7 years, or both |
Offences by companies and other legal persons (s. 27) | Liability attaches to the entity; individuals in leading positions may be charged jointly unless they show due diligence |
Amounts are expressed in dollars; Kiribati uses the Australian dollar. The explanatory memorandum annexed to the published copy quotes lower figures that appear to reflect an earlier draft. Stakeholders should rely on the operative sections and confirm with the DTO where exposure is material.

What This Means for Manufacturers
The Act regulates operators, not products. A manufacturer exporting equipment to Kiribati has no new filing, test or approval to complete because of this law. The commercial impact arrives indirectly, through customers that are designated as critical infrastructure operators.
Supply chain scrutiny will increase. Section 20 requires operators to apply contractual, technical and organisational safeguards to suppliers, service providers and contractors. Manufacturers selling to telecom operators, banks, utilities, hospitals, ports or government bodies in Kiribati should expect security questionnaires, contractual security clauses, and requests for evidence of secure development and vulnerability handling.
Technical standards may follow. The DTO can issue cybersecurity standards for critical infrastructure generally or for specific infrastructure. Once published, these could set baseline security requirements for equipment deployed in designated networks.
Incident support obligations shorten. Operators have 24 hours to report significant incidents. Vendors whose products or services sit inside critical infrastructure will need to supply incident information and remediation support on a matching timescale.
Service providers may be operators themselves. Because an operator includes any entity that manages or controls critical infrastructure or its supporting information systems, vendors providing managed services, hosting, cloud platforms or remote network operation could fall directly within the regime once a designation is made.
Products may be tested in situ. The DTO may audit, inspect and penetration test critical infrastructure. Equipment vulnerabilities identified during those exercises can lead to remedial orders against the operator, and to commercial pressure on the supplier.
Further rules are possible. The Minister may make regulations on supply chain risk management. These are the most likely route for any future vendor-facing requirements.
Certification Impact Summary
Area | Impact of the Act | Status |
Type approval for telecom and radio equipment | No change. Remains with the Communications Commission of Kiribati (CCK) under its Type Approval Rules | Unchanged |
Accepted technical standards (ACMA, CE, FCC, ITU) | No change | Unchanged |
Product cybersecurity certification | None introduced | Not applicable |
Cybersecurity labelling or marking | None introduced | Not applicable |
Import or customs requirements | No change | Unchanged |
Cybersecurity standards for critical infrastructure | New DTO power to issue standards (s. 15) | Pending issuance |
Supply chain risk regulations | New ministerial power (s. 20) | Pending issuance |
Audits and penetration testing | Applies to designated infrastructure; may cover deployed vendor equipment | Effective on commencement and designation |
Supplier contractual requirements | Operators must impose safeguards on third parties | Effective on commencement and designation |
In short, existing type approval certificates and applications are unaffected. The compliance work created by the Act sits in procurement, contracts and post-sale security support rather than in pre-market certification.
Timeline and Required Actions
Timeline
Date | Milestone |
2021 | Cybercrime Act 2021 enacted |
2023 | Digital Government Act 2023 establishes the DTO |
23 April 2026 | Cybersecurity Bill passed by the Maneaba ni Maungatabu |
2026 | Assented to as Act No. 7 of 2026 |
4 August 2026 | Act published on the MICT website |
To be announced | Commencement date appointed by ministerial notice |
After commencement | Ministerial designation of critical infrastructure; DTO notifies operators and opens the register |
After commencement | DTO standards, assessment formats and implementing regulations |
Ongoing once designated | 24-hour incident reporting; 30-day change notifications; periodic assessments |
Required actions
Stakeholder | Action | When |
Entities in the listed sectors | Assess whether assets, networks or systems are likely to be designated | Now |
Likely operators | Identify a senior manager to act as CISO or equivalent | Before commencement |
Likely operators | Build or update a risk management framework, security policies and compliance records | Before commencement |
Likely operators | Establish an incident response process capable of reporting to the National CERT within 24 hours | Before commencement |
Likely operators | Review supplier contracts and add security, notification and audit clauses | Before commencement |
Designated operators | Notify the DTO of ownership, operator or material system changes | Within 30 days of the change |
Manufacturers and vendors | Map which Kiribati customers fall within the listed sectors | Now |
Manufacturers and vendors | Prepare security documentation: vulnerability disclosure policy, patch and support commitments, secure development evidence | Now |
Manufacturers and vendors | Align incident notification and support terms with the 24-hour reporting window | Before commencement |
Managed service and hosting providers | Assess whether services amount to managing or controlling critical infrastructure | Now |
All stakeholders | Monitor MICT and the DTO for the commencement notice, designations, standards and regulations | Ongoing |
Importers and manufacturers | Continue to obtain CCK type approval for in-scope equipment | No change |
Conclusion
The Kiribati Cybersecurity Act 2026 gives the country a statutory cybersecurity framework built around the DTO, a National CERT and enforceable obligations for critical infrastructure operators. For manufacturers, market access procedures are unchanged, but customer expectations are not. Vendors that can demonstrate secure products, clear vulnerability handling and rapid incident support will be better placed when operators begin applying the Act's supply chain requirements.
The full text of the Act is available from MICT at https://www.mict.gov.ki/node/128.

