World Watch/Namibia/Cybersecurity

Cybersecurity · Namibia

Cybersecurity regulation in Namibia (2026)

ProposedCybercrime Bill, 2026 (pending Parliament); Electronic Transactions Act 4 of 2019 (in force); NAM-CSIRT under the Communications Regulatory Authority of Namibia (CRAN)Country index 61 · C+

Namibia shaded by its cybersecurity status

Namibia lacks a standalone, comprehensive cybersecurity law. The Electronic Transactions Act 4 of 2019 is in force but governs electronic commerce and evidence, not cybersecurity obligations broadly. A dedicated Cybercrime Bill (dated January 2026) is in the legislative pipeline — circulated for stakeholder validation in early 2026 — but had not been enacted as of May 2026. Operationally, NAM-CSIRT (hosted by CRAN) published non-binding National Cybersecurity Incident Management Guidelines in April 2026.

Key points

Cybercrime Bill 2026 (Proposed)

A Cybercrime Bill dated 30 January 2026 — covering unauthorised access, cyber fraud, identity theft, critical-infrastructure protection and establishment of a Cybercrime Directorate — was forwarded to Parliament but had not been passed or assented to as of May 2026. It aligns with the SADC Model Law on Cybercrime and the Budapest Convention.

Electronic Transactions Act 4 of 2019

The only in-force ICT statute; provides legal recognition of electronic transactions, admissibility of electronic evidence, consumer protection in e-commerce, and service-provider liability. It does not create general cybersecurity or breach-notification obligations.

NAM-CSIRT and CRAN oversight

The Namibia Cyber Security Incident Response Team (NAM-CSIRT), established under CRAN, serves as the national CSIRT for critical information infrastructure. It issues advisories, publishes quarterly threat reports, and coordinates incident response — but its mandate rests on regulatory authority rather than primary legislation.

National Cybersecurity Incident Management Guidelines 2026

Published by NAM-CSIRT in April 2026, these guidelines set out incident detection, reporting, analysis and response processes for CI/CII operators and public/private entities. They align with ISO/IEC 27001 and the NIST Cybersecurity Framework but are operational guidance, not legally binding obligations.

Breach notification — no formal legal duty yet

Namibia currently has no enacted law imposing mandatory breach-notification or incident-reporting duties on organisations. The 2026 Incident Management Guidelines encourage reporting to NAM-CSIRT, and a companion Data Protection Bill (draft) remains unenacted. High-profile breaches — Telecom Namibia, Namibia Airports Company, Paratus — have prompted ad hoc CRAN/NAM-CSIRT public advisories rather than statutory enforcement.

Harambee Prosperity Plan II commitment

The Cybercrime Bill is listed as a flagship deliverable under Namibia's Harambee Prosperity Plan II national development framework, signalling sustained executive commitment to enactment — though the bill has been in development since at least 2013.

Namibia - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →