Kiribati enacted the Cybersecurity Act 2026 (Act No. 7 of 2026), passed by the Maneaba ni Maungatabu on 23 April 2026, alongside the Cybercrime Act 2021 (Act No. 10 of 2021) already documented under this jurisdiction's scraping-topic file for its unauthorised-access, interception, data- and system-interference offences and its investigatory production, preservation and interception-assistance duties on a person or service provider, all bound to a criminal investigation rather than to an operator's own security posture.
The Cybersecurity Act 2026 is the operator-facing instrument researched here.
It lets the Minister, on the advice of the Director of the Digital Transformation Office (DTO), designate a physical, electronic or virtual infrastructure asset, network or information system as critical infrastructure where it is essential for national security or for the population's economic and social well-being, on grounds naming electronic communications, banking and other financial services, electric power, water and wastewater, healthcare and public health, agriculture and food distribution, emergency services, fisheries, tourism and public transportation.
Once designated, the operator, defined broadly enough to reach an individual, a private entity, a public body, a state-owned enterprise or any other body, must register with the DTO, report a change of ownership or operator within 30 days, furnish information the DTO requires to assess the infrastructure's security, submit to cybersecurity standards, audits, inspections and penetration testing, conduct periodic assessments, appoint a Chief Information Security Officer, maintain and document risk-management and third-party and supply-chain risk policies, comply with a remedial-action order, and report a significant cybersecurity incident to the National CERT and any Sectoral CERT within 24 hours of detecting it.
This jurisdiction's Data Protection Act 2025 is a comprehensive data-protection statute whose own Part V (sections 18 to 20, headed Data Security and Personal Data Impact Assessments) carries the security-of-processing and breach-notification duties this topic's seam rule leaves with the privacy row, not restated here.
The Digital Government Act 2023 established an earlier National Computer Emergency Response Team confined to government systems and "public bodies", a government information-security programme of the kind this topic excludes; the Cybersecurity Act 2026 repeals its critical-digital-infrastructure and CERT provisions outright and supersedes them with the framework researched here.
No provision of the Foreign Investment Act 2018 is confirmed either way: no URL for the Act was located on the Ministry of Information, Communications and Transport's own site, and the Pacific Islands Legal Information Institute's Kiribati index answered every request with a Cloudflare CAPTCHA challenge, a stop rather than a wall to read past.
The Communications Act 2013, the sector's general telecommunications statute, part of which the Cybercrime Act 2021 already repeals (its own section 94 and Part XIV), is not read either: its PDF returns an HTTP 200 response that does not decode into text, so whether it separately obligates a licensed telecommunications operator to a network-security standard is not confirmed in the primary text.
No cybersecurity or IT-risk directive for a bank or other financial institution operating in Kiribati was located; Kiribati has no central bank of its own and its legal tender is the Australian dollar, and whether the Ministry of Finance and Economic Development or another body has issued such a directive is an open research gap rather than a confirmed absence.
The Cybersecurity Act 2026's own text carries two internal inconsistencies worth recording rather than silently resolving: its Explanatory Memorandum states penalty figures for the section 25 offence ($10,000 first offence, $20,000 subsequent, $100 per continuing day) ten times lower than the operative section itself ($100,000, $200,000, $200), and the Memorandum's own Part I summary calls the statute "the Cybersecurity Act 2025" once, against the Act's own title, arrangement of sections and Clerk's certification, which all read 2026 and carry Act No. 7 of 2026.