BlackTree Security · Infrastructure · Automation · AI

Zambia Split Cybersecurity Regulation From Cybercrime. The Obligations Got Sharper.

Zambia replaced its combined 2021 cyber law with two statutes in 2025. The split separates cybersecurity regulation from criminal offences, while making critical-infrastructure reporting, audits, local hosting and provider licensing much more explicit.

The Cyber Security Act No. 3 of 2025 and Cyber Crimes Act No. 4 of 2025 commenced on 12 May 2025. Together they establish a new regulatory agency, organise national and sectoral incident response, protect critical information infrastructure and define computer-related offences and investigation powers.

The separation is sensible on paper. Operators, security providers and legal teams still need to read the laws together because a single incident can trigger regulatory reporting, evidence obligations and criminal investigation.

Critical infrastructure now has a control cycle

Controllers of designated critical information or critical information infrastructure must register and protect it, submit situational-awareness reporting and comply with binding agency guidelines. The Act requires an annual cyber audit by an information technology auditor and allows the agency to order additional audits.

This creates a recurring assurance cycle: identify, assess, report, remediate and demonstrate. A one-time certification or generic security policy will not satisfy a regime built around continuing evidence.

Incident reporting starts immediately

A controller must immediately notify the agency of a perceived or actual incident affecting critical information or infrastructure, including an interconnected system. A preliminary report follows within 12 hours, with status reporting and a detailed report after resolution.

The word perceived is important. Reporting cannot wait for forensic certainty. Organisations need thresholds, authority, contact details and a staged reporting template before an incident occurs.

Local hosting is the default for critical information

The Act requires critical information and critical information infrastructure to be hosted in Zambia unless the agency authorises hosting outside the country. The agency considers the data category, operational justification, resilience, foreign legal framework, public-sector status, national security and data-protection requirements.

Cloud strategy therefore needs a decision record. Architecture teams should know which workloads are designated, where backups and management planes sit, and which external dependencies could make the local-hosting claim incomplete.

Cybersecurity services become licensed work

Penetration testing, SOC services, risk assessment, vulnerability assessment, incident response, cyber audit and red teaming fall within the Act’s cybersecurity-service categories. Providers need a licence, and controllers may not engage an unlicensed provider.

This changes procurement. Buyers need to check licensing, and providers need to understand the conditions, renewal, reporting and possible suspension attached to market access.

The criminal law still needs safeguards

The Cyber Crimes Act modernises offences involving unauthorised access, illegal devices, fraud, identity and child online protection. The wider framework has also attracted concern about surveillance, speech and oversight. Those concerns should be treated as a governance issue, not dismissed as separate from cybersecurity.

What organisations should do now

  1. Determine whether systems or data are designated as critical.
  2. Validate Zambian hosting and any overseas authorisation.
  3. Prepare immediate notification and a 12-hour preliminary report.
  4. Schedule annual cyber audits and remediation tracking.
  5. Verify licensing of security providers before procurement.
  6. Align incident response with evidence preservation and lawful process.

The sharper obligation is speed

Zambia’s new framework makes several controls measurable: 12-hour preliminary reporting, annual audits, local hosting and provider licensing. Organisations will succeed or fail on operational readiness, not on whether a policy mentions cybersecurity.

Official sources

This article provides general information and is not legal advice.

Continue the series: Africa Cyber & Digital Law Series index

Leave a Reply

Your email address will not be published. Required fields are marked *