Kenya's Critical Information Infrastructure (CII) Regulations are in force.
The compliance deadlines have passed. Most designated infrastructure operators haven't met them. We help close the gap.
We work with Kenya's designated CII operators on the operational technology layer that IT security firms don't cover. SCADA systems, energy management systems, industrial control systems. Every engagement is built around the mandatory compliance obligations: annual risk assessment, CISO designation, and NC4 audit readiness.
Policy deadline (Aug 2024) passed. Annual risk assessment (Feb 2025) overdue. Most designated CII owners are already behind.
Annual mandatory cybersecurity risk assessment with risk register. Overdue for most designated operators. We deliver a structured assessment that satisfies the Regulation 17 compliance requirement and gives your Chief Information Security Officer (CISO) a defensible risk posture.
Learn More →Regulation 71(3) permits CII owners to adopt global best practices on their own initiative. IEC 62443 is the only international standard purpose-built for industrial control systems. We hold all four certificates.
View Credentials →Every designated CII owner must appoint a CISO. The qualification requirements are specific. Most organisations don't have a person who meets them. We help with CISO function design, policy development, and ongoing advisory support.
Learn More →CII owners must report all cybersecurity incidents to the relevant Sectoral Cybersecurity Operations Centre within 24 hours. Without an IR plan and tested procedures, most organisations cannot meet this obligation. We build and exercise the capability.
Learn More →Legal Notice 44 of 2024
Annual risk assessments. Mandatory CISO. 24-hour incident reporting. Data must stay in Kenya. Annual internal audits. Formal compliance audits by the enforcement authority. Understand the full obligation stack before a directive lands.
Designated CII sectors under the Second Schedule of the Regulations.
Energy
Electricity generation, transmission/distribution, petroleum, natural gas
Water
Drinking water storage, distribution, quality assurance, wastewater treatment
Transport
Aviation, rail, road, maritime and port operations
Financial Services
Banking, payment systems, stock exchange
16 sectors are formally designated under the Second Schedule. See the full list →