Regulatory Update

Uganda’s communications sector is entering a more demanding phase of cybersecurity regulation

The Uganda Communications Commission (UCC) has issued the Minimum Cybersecurity Guidelines for the Licensed Operators in Uganda, June 2025, establishing minimum and harmonised cybersecurity controls for licensed operators in Uganda. The Guidelines are intended to strengthen the protection of critical communication and information infrastructure and ensure the continued provision of secure and reliable communications services.

The Guidelines apply to UCC-licensed operators, including telecommunications companies, Internet Service Providers (ISPs), broadcasting and radio communications operators, satellite providers and courier companies.

For regulated entities, cybersecurity is no longer simply an IT function. The Guidelines place responsibility at governance and management level and require licensed operators to establish and maintain a cybersecurity governance framework with clearly defined roles and responsibilities. Boards or equivalent governing bodies are expected to be accountable for cybersecurity management, while operators are required to allocate appropriate resources, periodically review their cybersecurity strategies and programmes, establish appropriate cybersecurity oversight structures and maintain an independent cybersecurity function where appropriate. Operators are also expected to establish and maintain cybersecurity and information-security policies and submit the relevant policy to UCC.

Licensed operators are further expected to maintain a systematic cybersecurity risk-management process aligned with their enterprise risk-management framework. This includes identifying information and technological assets, conducting periodic cybersecurity risk assessments, assessing critical environments and applications, implementing measures to treat identified risks and monitoring the effectiveness of those measures. The Guidelines also expressly address third-party and supply-chain risks, requiring operators to consider cybersecurity risks arising from suppliers and other external parties.

The compliance expectation extends beyond having policies and procedures in place. The Guidelines require cybersecurity assessment and auditing covering networks, information systems, facilities and security controls, including penetration testing. These assessments are intended to establish whether controls have been properly designed and implemented, whether their effectiveness is being monitored and whether vulnerabilities or weaknesses exist within the operator’s systems and security arrangements.

Incident management is also a significant regulatory requirement. Licensed operators are required to notify the Commission of significant information or computer-security threats or incidents that come to their attention and to provide UCC with quarterly cybersecurity incident reports, information technology and risk-assessment reports and other information requested by the Commission. The Guidelines also provide for access to records and premises during investigations of communications emergencies or alleged cybercrime.

Operators are therefore expected to have an effective incident-response framework capable of identifying, escalating, managing and reporting cybersecurity incidents. The Guidelines require appropriate incident-response plans, defined roles and responsibilities, communication and escalation channels and regular cyber incident-response drills to test organisational readiness.

Business continuity and disaster recovery are equally important. Licensed operators are expected to establish and maintain disaster-recovery plans for critical ICT systems and documented, tested and maintained business-continuity plans. Appropriate capabilities should be available to restore network and communication services following disasters or other significant disruptions.

Internet Service Providers face additional technical and operational requirements under the Guidelines. These include security controls for network infrastructure, vulnerability management, secure software development, threat intelligence, real-time security monitoring and alerting, secure disposal of information assets, traffic protection, log retention, incident response and disaster recovery. Where an ISP provides Digital Financial Services, the Guidelines require adoption of the ITU Digital Financial Services Security Assurance Framework and periodic security testing of the DFS ecosystem.

ISPs are also required to report cybersecurity incidents to the Uganda Computer Emergency Response Team (UG-CERT). The Guidelines specifically identify incidents such as network intrusions, breaches of customer data, denial-of-service and distributed denial-of-service attacks, malware outbreaks, spam-related incidents, phishing and other spoofing-related attacks and web defacement.

The cybersecurity requirements must also be considered alongside Uganda’s wider legal framework. The Guidelines expressly identify the Data Protection and Privacy Act, 2019, the Computer Misuse Act, 2011, the National Payments Systems Act, 2020, the Electronic Transactions Act, 2011, the Electronic Signatures Act, 2011 and the Uganda Communications (Computer Emergency Response Team) Regulations, 2019, among other instruments, as part of the legal and regulatory framework applicable to their implementation.

This is particularly important where a cybersecurity incident involves personal data. For a regulated operator, a single cyber incident may raise UCC regulatory requirements alongside obligations arising under data protection and other applicable laws. Cybersecurity compliance should therefore be integrated into the organisation’s wider regulatory, privacy, risk-management and corporate-governance frameworks.

The Guidelines also contain an express enforcement provision. Where a licensed operator fails to comply with applicable provisions or conditions, including failure to submit required information, the applicable sanctions under the Uganda Communications (Computer Emergency Response Team) Regulations, 2019 will apply.

UCC-licensed operators should therefore be undertaking a comprehensive review of their current cybersecurity arrangements against the June 2025 Guidelines. The review should determine whether the organisation has appropriate governance and board oversight, a current cybersecurity policy, documented risk assessments, effective technical and organisational controls, third-party risk-management processes, audit and testing arrangements, incident-response procedures, regulatory reporting mechanisms, business-continuity arrangements and tested disaster-recovery capabilities.

Most importantly, regulated entities should ensure that compliance can be demonstrated with evidence. Policies should be supported by implementation records, risk assessments, audit reports, testing results, training records, incident reports, governance records and evidence of remediation where weaknesses have been identified.

The UCC Minimum Cybersecurity Guidelines therefore place a clear responsibility on licensed operators to move beyond cybersecurity as a purely technical function and establish cybersecurity as an organisation-wide regulatory and governance responsibility. For UCC-regulated entities, the critical question is no longer simply whether cybersecurity measures exist, but whether the organisation has an effective, documented and demonstrable framework capable of preventing, detecting, responding to and recovering from cybersecurity threats.

 

This Legal Alert is issued for general regulatory awareness and does not constitute legal advice. Regulated entities should assess the application of the Guidelines to their specific licence, operations, systems and applicable legal obligations.

Source: Uganda Communications Commission, Minimum Cybersecurity Guidelines for the Licensed Operators in Uganda, June 2025. View the UCC Guidelines