top of page

Kiribati Cybersecurity Act 2026: Critical Infrastructure Law

18 hours ago
7 min read

Kiribati Cybersecurity Act 2026: MICT Publishes National Framework for Critical Infrastructure Protection and Incident Reporting


The Ministry of Information, Communications and Transport (MICT) of Kiribati has published the Cybersecurity Act 2026 (Act No. 7 of 2026) on its official website. The Bill was passed by the Maneaba ni Maungatabu, Kiribati's parliament, on 23 April 2026, and MICT released the enacted text on 4 August 2026.

The Act is Kiribati's first dedicated cybersecurity statute. It assigns national responsibility for cybersecurity to the Digital Transformation Office (DTO), creates a National Computer Emergency Response Team (CERT), and sets binding obligations for operators of designated critical infrastructure. It does not introduce a product certification scheme, but it does create supply chain duties that will reach equipment manufacturers and technology vendors through their customers.

The Act will come into force on a date appointed by the Minister by notice. The published copy does not state a commencement date.


Key Facts at a Glance


Item

Detail

Instrument

Cybersecurity Act 2026 (Act No. 7 of 2026)

Country

Republic of Kiribati

Publishing authority

Ministry of Information, Communications and Transport (MICT)

Lead agency

Digital Transformation Office (DTO)

Passed by parliament

23 April 2026

Published by MICT

4 August 2026

Commencement

Date to be appointed by ministerial notice

Who is regulated

Operators of designated critical infrastructure

Incident reporting deadline

24 hours from detection of a significant incident

Maximum fine for non-compliance

$100,000 (first offence), $200,000 (subsequent offence)

Official text


Regulatory Background


Until now, Kiribati's cyber legislation focused on criminal conduct and government digital services. The Cybercrime Act 2021 established computer-related offences, and the Digital Government Act 2023 created the DTO and contained early provisions on critical digital infrastructure and a national CERT. A Data Protection Act 2025 has also been published by MICT.

The Cybersecurity Act 2026 consolidates the cybersecurity elements into a standalone law. It repeals the definitions of "critical digital infrastructure" and "national computer emergency response team" in the Digital Government Act 2023, together with Division 4 of Part II and sections 22, 23 and 28 of that Act, and replaces them with a fuller regime.


What the Kiribati Cybersecurity Act 2026 Introduces


A national institutional framework


The DTO becomes the lead agency for national cybersecurity. Its functions include developing the national cybersecurity strategy, issuing cybersecurity standards for critical infrastructure, maintaining a register of that infrastructure, conducting audits, inspections and penetration testing, and supervising the CERTs.

Three bodies support the DTO:


  • National CERT. Operated by the DTO, with contact points available around the clock. It receives and assesses incident reports, provides incident response services, maintains an incident register and may classify incidents by severity.

  • Sectoral CERTs. The DTO may direct operators in a given sector to establish a sector-specific CERT. Unless decided otherwise, the operators in that sector bear the cost.

  • Kiribati Cybersecurity Working Group. A multi-stakeholder forum chaired by the DTO, with members drawn from ICT professionals, critical infrastructure operators, government, law enforcement, academia and civil society. It advises on standards, alerts and policy.


Designation of critical infrastructure


The Minister, acting on the advice of the Director of the DTO, may designate physical, electronic or virtual assets, networks and information systems as critical infrastructure where they are essential to national security or to the economic and social well-being of the population. Virtual assets expressly include software-based and remotely accessed infrastructure.

The sectors the Minister must consider are:


  • Electronic communications

  • Banking and financial services

  • Electric power

  • Water and wastewater

  • Healthcare and public health

  • Agriculture and food distribution

  • Emergency services

  • Fisheries

  • Tourism

  • Public transportation

  • The legislature, executive, judiciary, law enforcement and security agencies


The definition of "operator" is broad. It covers any person or entity that owns, operates, manages or controls critical infrastructure or the information systems supporting it. Where several entities perform those functions, each is treated as an operator.


Obligations of critical infrastructure operators


Obligation

Requirement

Section

Registration changes

Notify the DTO of any change of ownership or operator within 30 days

13

Information requests

Supply information requested by the DTO; report material changes to design, configuration or security within 30 days

14

Standards and audits

Comply with DTO cybersecurity standards; submit to audits and inspections

15

Periodic assessments

Conduct cybersecurity assessments and submit copies to the DTO

16

Governance

Appoint a senior manager as Chief Information Security Officer or equivalent

17

Policies and records

Maintain proportionate technical and organisational policies; keep compliance records

18

Risk management

Establish, maintain and regularly update a cybersecurity risk management framework

19

Supply chain

Manage risks from third-party suppliers, service providers and contractors through contractual, technical and organisational safeguards

20

Incident reporting

Report significant incidents to the National CERT and any Sectoral CERT within 24 hours of detection; allow CERT access to networks for analysis

21

Remedial orders

Comply with orders to take preventative, mitigating or remedial action

22


Operators that cannot comply for financial, legal or technical reasons must inform the DTO. The Director may grant exceptions or modify the prescribed standards.


National cybersecurity emergency


Where a serious threat affects national security or critical infrastructure, the Minister may declare a cybersecurity emergency and direct operators to implement specified measures. Directions must be proportionate and limited in duration.


Information sharing


The DTO, CERTs and operators may share information with each other and with foreign authorities for the purposes of the Act, national security or crime prevention. Entities that share incident or vulnerability information in good faith are protected from civil and criminal liability for the disclosure, and that information cannot be used against them in civil or administrative proceedings unless provided in bad faith.


Enforcement and penalties


Offence

Penalty

Operator fails to carry out its obligations without an exemption (s. 25)

Fine up to $100,000 for a first offence; up to $200,000 for a subsequent offence; up to $200 per day for a continuing offence

Removing, destroying, altering or damaging critical infrastructure without lawful authority (s. 26)

Fine up to $200,000, imprisonment up to 7 years, or both

Offences by companies and other legal persons (s. 27)

Liability attaches to the entity; individuals in leading positions may be charged jointly unless they show due diligence

Amounts are expressed in dollars; Kiribati uses the Australian dollar. The explanatory memorandum annexed to the published copy quotes lower figures that appear to reflect an earlier draft. Stakeholders should rely on the operative sections and confirm with the DTO where exposure is material.


An infographic summarizing the Kiribati Cybersecurity Act 2026, outlining its institutional framework, regulated critical infrastructure sectors, operator obligations, 24-hour incident reporting rules, potential fines, and indirect impacts on technology manufacturers.

What This Means for Manufacturers


The Act regulates operators, not products. A manufacturer exporting equipment to Kiribati has no new filing, test or approval to complete because of this law. The commercial impact arrives indirectly, through customers that are designated as critical infrastructure operators.


Supply chain scrutiny will increase. Section 20 requires operators to apply contractual, technical and organisational safeguards to suppliers, service providers and contractors. Manufacturers selling to telecom operators, banks, utilities, hospitals, ports or government bodies in Kiribati should expect security questionnaires, contractual security clauses, and requests for evidence of secure development and vulnerability handling.


Technical standards may follow. The DTO can issue cybersecurity standards for critical infrastructure generally or for specific infrastructure. Once published, these could set baseline security requirements for equipment deployed in designated networks.


Incident support obligations shorten. Operators have 24 hours to report significant incidents. Vendors whose products or services sit inside critical infrastructure will need to supply incident information and remediation support on a matching timescale.


Service providers may be operators themselves. Because an operator includes any entity that manages or controls critical infrastructure or its supporting information systems, vendors providing managed services, hosting, cloud platforms or remote network operation could fall directly within the regime once a designation is made.


Products may be tested in situ. The DTO may audit, inspect and penetration test critical infrastructure. Equipment vulnerabilities identified during those exercises can lead to remedial orders against the operator, and to commercial pressure on the supplier.


Further rules are possible. The Minister may make regulations on supply chain risk management. These are the most likely route for any future vendor-facing requirements.


Certification Impact Summary


Area

Impact of the Act

Status

Type approval for telecom and radio equipment

No change. Remains with the Communications Commission of Kiribati (CCK) under its Type Approval Rules

Unchanged

Accepted technical standards (ACMA, CE, FCC, ITU)

No change

Unchanged

Product cybersecurity certification

None introduced

Not applicable

Cybersecurity labelling or marking

None introduced

Not applicable

Import or customs requirements

No change

Unchanged

Cybersecurity standards for critical infrastructure

New DTO power to issue standards (s. 15)

Pending issuance

Supply chain risk regulations

New ministerial power (s. 20)

Pending issuance

Audits and penetration testing

Applies to designated infrastructure; may cover deployed vendor equipment

Effective on commencement and designation

Supplier contractual requirements

Operators must impose safeguards on third parties

Effective on commencement and designation


In short, existing type approval certificates and applications are unaffected. The compliance work created by the Act sits in procurement, contracts and post-sale security support rather than in pre-market certification.


Timeline and Required Actions


Timeline


Date

Milestone

2021

Cybercrime Act 2021 enacted

2023

Digital Government Act 2023 establishes the DTO

23 April 2026

Cybersecurity Bill passed by the Maneaba ni Maungatabu

2026

Assented to as Act No. 7 of 2026

4 August 2026

Act published on the MICT website

To be announced

Commencement date appointed by ministerial notice

After commencement

Ministerial designation of critical infrastructure; DTO notifies operators and opens the register

After commencement

DTO standards, assessment formats and implementing regulations

Ongoing once designated

24-hour incident reporting; 30-day change notifications; periodic assessments


Required actions


Stakeholder

Action

When

Entities in the listed sectors

Assess whether assets, networks or systems are likely to be designated

Now

Likely operators

Identify a senior manager to act as CISO or equivalent

Before commencement

Likely operators

Build or update a risk management framework, security policies and compliance records

Before commencement

Likely operators

Establish an incident response process capable of reporting to the National CERT within 24 hours

Before commencement

Likely operators

Review supplier contracts and add security, notification and audit clauses

Before commencement

Designated operators

Notify the DTO of ownership, operator or material system changes

Within 30 days of the change

Manufacturers and vendors

Map which Kiribati customers fall within the listed sectors

Now

Manufacturers and vendors

Prepare security documentation: vulnerability disclosure policy, patch and support commitments, secure development evidence

Now

Manufacturers and vendors

Align incident notification and support terms with the 24-hour reporting window

Before commencement

Managed service and hosting providers

Assess whether services amount to managing or controlling critical infrastructure

Now

All stakeholders

Monitor MICT and the DTO for the commencement notice, designations, standards and regulations

Ongoing

Importers and manufacturers

Continue to obtain CCK type approval for in-scope equipment

No change


Conclusion


The Kiribati Cybersecurity Act 2026 gives the country a statutory cybersecurity framework built around the DTO, a National CERT and enforceable obligations for critical infrastructure operators. For manufacturers, market access procedures are unchanged, but customer expectations are not. Vendors that can demonstrate secure products, clear vulnerability handling and rapid incident support will be better placed when operators begin applying the Act's supply chain requirements.

The full text of the Act is available from MICT at https://www.mict.gov.ki/node/128.


bottom of page