ICT management in Zambia

Zambia's Cyber Security Act 2025 Explained

What Act No. 3 of 2025 changed, who it affects most, and the records controllers of critical information infrastructure need to keep.

Last reviewed · Sources

What does Zambia's Cyber Security Act 2025 require?

Zambia's Cyber Security Act No. 3 of 2025 establishes the Zambia Cyber Security Agency and lets it designate critical information and critical information infrastructure. Controllers of designated systems must register them within thirty days, host them in Zambia unless authorised otherwise, commission an annual cyber audit, and report incidents immediately with a preliminary report within twelve hours. Cyber security service providers must be licensed.

The Act was assented to on 8 April 2025 and came into operation on 12 May 2025 under Statutory Instrument No. 22 of 2025. Section 73 repealed the Cyber Security and Cyber Crimes Act, 2021. Criminal offences such as unauthorised access, system interference and cyber extortion moved to a companion statute, the Cyber Crimes Act No. 4 of 2025.

The heaviest duties attach to a controller of information or infrastructure that the Agency has designated as critical. The Act lists critical sectors — defence and security, the public sector, banking and finance, health, transport, pensions and insurance, information and communications technology, energy, education and mining (s.8) — but designation itself is made by notice in the Gazette (s.9). Organisations in these sectors should confirm with the Agency whether any of their systems are designated.

The Zambia Cyber Security Agency

Section 3 establishes the Agency in the Office of the President. Under the Act it designates and categorises critical information and critical information infrastructure (s.9–10), receives incident notifications and reports from controllers (s.17), and licenses providers of cyber security services (Part on licensing, including s.42).

Duties of controllers of critical information infrastructure

Once information or infrastructure is designated, its controller takes on a set of continuing duties:

  • Comply with the baseline security requirements prescribed for designated information or infrastructure (s.9(2)).
  • Register it with the Agency within thirty days of designation (s.11).
  • Host it within Zambia unless the Agency authorises hosting outside the Republic (s.12).
  • Notify the Agency of a change in its ownership within seven days (s.13).
  • Annually appoint an information technology auditor to perform a cyber audit, pay the audit fees, and submit the report of any audit the Agency directs by notice (s.14).
  • Report on cyber security situational awareness as the Agency determines (s.16) and submit the information the Agency requires each year (s.64).
  • Establish mechanisms and processes to detect cyber security threats, in line with standards the Agency publishes in the Gazette (s.17(5)).

Incident notification under section 17

A controller must immediately notify the Agency of a perceived or actual cyber security incident affecting critical information or critical information infrastructure, or a computer system connected to it. A preliminary incident report is due within twelve hours of that notification, status reports follow at intervals the Agency sets, and a detailed report is due once the incident is resolved.

Where personal data is affected, the Data Protection Act's separate duty to notify the Data Protection Commissioner within twenty-four hours (s.49) can apply to the same incident.

Licensing of cyber security services

Section 42 prohibits providing a cyber security service without a licence issued under the Act, and prohibits a controller — in this Act, a person responsible for registered critical information or critical information infrastructure (s.2) — from engaging an unlicensed provider. Section 41 lists the services covered: penetration testing, security operations centre services, information security risk assessment, vulnerability assessment, incident response, cyber audit and red teaming, plus any others prescribed. Before engaging an outside firm for any of these, check its licence status with the Agency.

Organisations that run security tools with their own staff should take advice on how the licensing provisions apply to their arrangements.

The Cyber Crimes Act 2025

The Cyber Crimes Act No. 4 of 2025, brought into force by SI No. 23 of 2025, creates offences including unauthorised access to and interference with computer systems and data, unauthorised disclosure or possession of data relating to critical information infrastructure, introducing malicious software, computer fraud, cyber extortion and identity-related crimes. For ICT teams it matters most when preserving evidence and deciding when to involve law enforcement.

Getting ready

  • Keep an accurate inventory of systems, owners and dependencies so you can answer quickly if the Agency designates any of them.
  • Record where critical systems are hosted and who can authorise changes.
  • Write an incident procedure with the immediate-notice and twelve-hour preliminary-report steps, and practise it.
  • Collect security logs and network-flow data so incidents can be detected and investigated.
  • Keep vulnerability findings, remediation records and reports in a form an auditor can review.
  • Check the licence status of any cyber security provider before engaging it.

Key obligations and how ICTM helps

A summary of provisions that affect how organisations manage ICT. It is not exhaustive — read the legislation for the full requirements.

ObligationSourceWhat it requiresHow ICTM helps
Meet baseline security requirements Cyber Security Act No. 3 of 2025, s.9(2) A controller of designated critical information or infrastructure must comply with the baseline security requirements that are prescribed. Control sets for ISO/IEC 27001:2022, NIST CSF 2.0 and CIS Controls v8, agentless device compliance checks and firewall configuration audits help measure systems against a baseline.
Register designated infrastructure Cyber Security Act No. 3 of 2025, s.11 Register designated critical information or infrastructure with the Agency within thirty days of designation, in the prescribed manner and form. The asset register and dependency mapping document each system, its owner and what depends on it.
Host in Zambia Cyber Security Act No. 3 of 2025, s.12 Host critical information or infrastructure within the Republic unless the Agency authorises otherwise. —
Commission an annual cyber audit Cyber Security Act No. 3 of 2025, s.14 Annually appoint an information technology auditor to perform a cyber audit on critical information or infrastructure, and pay the audit fees. Audit-readiness scores, vulnerability and penetration-test findings with remediation deadlines by severity, and CSV, PDF and SARIF exports give the auditor organised evidence.
Notify and report incidents Cyber Security Act No. 3 of 2025, s.17(1)–(4) Immediately notify the Agency of a perceived or actual incident, submit a preliminary report within twelve hours of notifying, status reports as required and a detailed report once resolved. Incident records with severity, status and PDF/CSV export; security events can be escalated into incidents and root-cause analyses recorded.
Detect cyber security threats Cyber Security Act No. 3 of 2025, s.17(5) Establish mechanisms and processes to detect threats to critical information or infrastructure, following standards the Agency publishes. Network detection and response analyses NetFlow, IPFIX and sFlow data for port scans, beaconing, lateral movement, DNS tunnelling and exfiltration; syslog, Windows event logs and Linux authentication logs feed threshold-based rules; CVE and CISA KEV matching flags known exploited vulnerabilities.
Use licensed cyber security service providers Cyber Security Act No. 3 of 2025, s.42 A person may not provide a cyber security service without a licence, and a controller of registered critical information or infrastructure (s.2) may not engage an unlicensed provider. —

Frequently asked questions

Which laws repealed and replaced the Cyber Security and Cyber Crimes Act 2021?

Two Acts assented to on 8 April 2025. The Cyber Security Act No. 3 of 2025 repealed the 2021 Act (s.73) and covers the Zambia Cyber Security Agency, critical information infrastructure and licensing of cyber security services. The Cyber Crimes Act No. 4 of 2025 covers computer-related offences. Both came into operation on 12 May 2025, under SI No. 22 and SI No. 23 of 2025 respectively.

What is critical information infrastructure under the Act?

It is information or information infrastructure in a critical sector that the Zambia Cyber Security Agency designates as critical by notice in the Gazette (s.9). The critical sectors listed in section 8 include defence and security, the public sector, banking and finance, health, transport, pensions and insurance, ICT, energy, education and mining. Designation brings duties to register, host locally, audit annually and report incidents.

How quickly must a cyber incident be reported to the Agency?

Section 17 requires a controller to notify the Zambia Cyber Security Agency immediately of a perceived or actual incident affecting critical information or critical information infrastructure, or a connected system. A preliminary incident report must follow within twelve hours of that notification, with status reports as the Agency requires and a detailed report once the incident is resolved.

Does the Act matter if none of our systems are designated?

Yes, in part. The critical-infrastructure duties apply only to controllers of designated, registered systems, but anyone providing a cyber security service listed in s.41 needs a licence (s.42(1)), and the companion Cyber Crimes Act applies to everyone. Organisations in the listed critical sectors should also be ready for designation by keeping good inventories and incident procedures.

Do penetration testers need a licence in Zambia?

Section 42 of the Cyber Security Act 2025 prohibits providing a cyber security service without a licence and prohibits controllers from engaging unlicensed providers. The licensable services are listed in section 41 and include penetration testing and vulnerability assessment. Ask any provider for evidence of its licence before engaging it.

How does ICTM help with Cyber Security Act obligations?

ICTM is software your own team runs. It keeps an asset register with dependencies for scoping critical systems, records incidents and root-cause analyses, collects security logs and network-flow data for detection, runs vulnerability scans with remediation deadlines, and exports findings and reports for auditors. It does not file reports with the Agency for you or replace the independent cyber audit.

Sources

  1. Cyber Security Act No. 3 of 2025 (National Assembly of Zambia)
  2. Cyber Security Act (Commencement) — SI No. 22 of 2025 (ZambiaLII)
  3. Cyber Crimes Act No. 4 of 2025 (National Assembly of Zambia)
  4. Cyber Crimes Act (Commencement) — SI No. 23 of 2025 (ZambiaLII)

This page is general information about Zambian law as reviewed on 13 September 2026. It is not legal advice. Laws and regulator guidance change — check the current legislation or consult a qualified legal adviser before relying on it. Ontech ICTM helps you organise records and evidence; it does not by itself make an organisation compliant.

Organise your ICT obligations in one place

Ontech ICTM keeps your registers, assessments, incidents and evidence together. Book a walkthrough with the Ontech team in Lusaka.