Law / Kiribati

Cybersecurity Act 2026, Critical Infrastructure Operator Obligations

Cybersecurity Act 2026 (Act No. 7 of 2026), ss. 12-20, 22-23 (Parts V-VI)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Commencement not set.

A sector security regimes rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This duty does not yet bind: the Cybersecurity Act 2026 commences only on a date the Minister may by notice appoint under section 2, and no commencement date has been identified.
  • It reaches you only once the Minister, on the Director's advice, has designated your physical, electronic or virtual infrastructure asset, network or information system as critical infrastructure under section 12, on grounds including electronic communications, banking or other financial services, electric power, water and wastewater, healthcare and public health, agriculture and food distribution, emergency services, fisheries, tourism, or public transportation; the definition of an "operator" reaches an individual, a private entity, a public body, a state-owned enterprise or any other body, not only a company.
  • Once designated, register with the DTO and notify it of any change in ownership of the infrastructure or in the person or entity operating it within 30 days; furnish the DTO whatever information it requires by written notice to assess the infrastructure's security and cybersecurity measures; and report a material change to the infrastructure's design, configuration, security or operation to the DTO within 30 days of the change.
  • Comply with cybersecurity standards the DTO issues, submit to its periodic or ad hoc audits, inspections and penetration testing, and conduct and submit periodic cybersecurity assessments of the infrastructure's risk, vulnerability and preparedness.
  • Appoint a member of senior management as Chief Information Security Officer, and develop, implement, communicate to staff and keep records of technical and organisational policies, practices and processes to manage risk to your network and information infrastructure and to prevent, mitigate and remedy a cybersecurity incident.
  • Establish, implement and maintain a cybersecurity risk-management framework, and take reasonable contractual, technical and organisational measures to manage cybersecurity risk arising from your third-party suppliers, service providers and contractors.
  • Comply with any order the DTO, a Sectoral CERT, the Minister or your sector's regulatory authority makes to take preventative, mitigating or remedial action, and tell the DTO where you cannot meet an obligation under this framework for financial, legal or technical reasons, which lets the Director grant an exception or modify a prescribed standard.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Section 25(1) makes it an offence for an operator of critical infrastructure to fail to carry out its obligations under Parts IV or V without a granted exemption or modification from the DTO under section 23. Section 25(2) sets the operative penalty: a fine not exceeding $100,000 for a first offence or $200,000 for a subsequent offence, and a further fine not exceeding $200 for each day a continuing offence persists. The Act's own Explanatory Memorandum states a lower penalty for the identical offence ($10,000, $20,000 and $100 respectively), a discrepancy between the enacted section and its own memorandum that is not resolved here. Section 27 extends liability to an individual with a leading position in a person that is not an individual.

Penalty structure

Section 25(2)'s own operative text sets a graduated fixed structure: a fine not exceeding $100,000 for a first offence, not exceeding $200,000 for a subsequent offence (recorded here as fixed_cap), and a further fine not exceeding $200 for each day a continuing offence persists. The Act does not define the currency the bare "$" denotes; Kiribati's legal tender is the Australian dollar (ISO 4217: AUD). The Act's own Explanatory Memorandum states a different, lower set of figures for the same offence: $10,000, $20,000 and $100 per continuing day, exactly one-tenth the operative section's figures; both are recorded here, and which one governs is not resolved.

Rule
Fixed only
As of
19 September 2026
Currency
AUD
Fixed cap
200,000

Who enforces it

Enforcement body

The Digital Transformation Office (DTO), which registers critical infrastructure, requires information, issues cybersecurity standards, and conducts audits, inspections and penetration testing under Parts V and VI, and to which the DTO, a Sectoral CERT, the Minister or a sector regulator may direct a remedial-action order under section 22; a failure to carry out an obligation under the framework, absent a granted exemption under section 23, is prosecuted as a criminal offence under section 25, whose own text names a failure of obligations under "Parts IV or V" rather than the Part VI operator obligations it appears intended to enforce.

Settledness

As of
19 September 2026
Open questions
  • Has the Minister issued the section 2 commencement notice bringing the Cybersecurity Act 2026 into force, and if so, on what date?
  • Which infrastructure assets, networks or information systems, if any, has the Minister designated as critical infrastructure under section 12, since every duty in this instrument binds only an operator so designated?
  • Does section 25(1)'s reference to a failure of obligations under "Parts IV or V" mean Part VI, where the operator's obligations under this framework and section 23's own cross-reference to "this Part or Part IV" actually sit, given Part V (Critical Infrastructure) itself carries no operator-facing obligation of its own?
  • Which of the two conflicting fine schedules for the section 25 offence, the operative section's figures or the Explanatory Memorandum's tenfold-lower figures, governs a prosecution under this section?
  • Does the Explanatory Memorandum calling this statute "the Cybersecurity Act 2025" once in its Part I summary, against the Act's own title, arrangement of sections and Clerk's certification, which all read "Cybersecurity Act 2026" and Act No. 7 of 2026, reflect anything beyond an uncorrected drafting leftover from an earlier version?

What it reaches

Obligation class

Governance, Security

Applicability criteria

The Act itself is not yet in force: section 2 makes commencement conditional on a date the Minister proclaims by notice, so this criterion cannot yet be satisfied by anyone.

As of
19 September 2026
Combinator
All of
Criteria
The Minister, on the advice of the Director of the Digital Transformation Office, has designated your physical, electronic or virtual infrastructure asset, network or information system as critical infrastructure under section 12 of the Cybersecurity Act 2026.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Sections 12 to 15 of the Cybersecurity Act 2026 let the Minister, acting on the advice of the Director of the Digital Transformation Office (DTO), designate a physical, electronic or virtual infrastructure asset, network or information system as critical infrastructure where it is essential for national security or for the economic and social well-being of the population, on grounds naming electronic communications, banking and other financial services, electric power, water and wastewater, healthcare and public health, agriculture and food distribution, emergency services, fisheries, tourism and public transportation.

A designated operator, defined to include an individual, a private entity, a public body, a state-owned enterprise, or any other body that owns, operates, manages or controls the infrastructure or the information systems supporting it, must register with the DTO and notify it of any change of ownership or of the operating person or entity within 30 days.

The DTO may by written notice require the operator to furnish information it needs to assess the infrastructure's security and cybersecurity measures, and the operator must report a material change to the infrastructure's design, configuration, security or operation within 30 days of implementing it.

The DTO may issue cybersecurity standards for critical infrastructure and conduct or require periodic or ad hoc audits, inspections and penetration testing of it, and the operator must conduct and submit periodic cybersecurity assessments of the infrastructure's risk, vulnerability and preparedness to the DTO.

The operator must appoint a member of senior management as Chief Information Security Officer responsible for the operator's cybersecurity preparedness, monitoring, reporting and coordination with the DTO, and must develop, implement, communicate to staff and document technical and organisational policies, practices and processes to manage risk to its network and information infrastructure and to prevent, mitigate and remedy a cybersecurity incident.

The operator must also establish, implement and maintain a cybersecurity risk-management framework and take reasonable contractual, technical and organisational measures to manage cybersecurity risk arising from its third-party suppliers, service providers and contractors.

The operator must comply with an order the DTO, a Sectoral CERT, the Minister or a sector's regulatory authority makes to take preventative, mitigating or remedial action, and must tell the DTO where it cannot meet an obligation under this framework for financial, legal or technical reasons, which lets the Director grant an exception or modify a prescribed standard.

A failure to carry out an obligation under Parts IV or V, absent a granted exemption, is an offence under section 25, punishable on summary conviction by a fine of up to $100,000 for a first offence, up to $200,000 for a subsequent offence, and up to $200 for each day a continuing offence persists.

The Act's own Explanatory Memorandum states a materially lower set of figures for the identical offence, a fine of up to $10,000 for a first offence, up to $20,000 for a subsequent offence, and up to $100 for each day continuing, a discrepancy between the operative text and its own memorandum that is not resolved here.

When LexLint raises it

  • operates_essential_service
  • provides_financial_services
  • provides_telecom_services
  • handles_health_records

Read the law

Official Act text (Cybersecurity Act 2026, Act No. 7 of 2026)
published by the Ministry of Information, Communications and Transport (mict.gov.ki)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app