About
Corporate & Business Law
Real Estate & Conveyancing
Technology, Fintech & Digital Assets
Private Client & Estate Planning
Insights Legal Templates Capabilities & Approach Our People Contact Book a Consultation
Fintech, Crypto & Technology Law

Cybersecurity, Technology Controls & Systems Audits for Kenyan VASPs

Virtual asset businesses are technology businesses first. Regulators assess technology governance as closely as financial governance, because a systems failure is a customer-harm event.

Njau & Associates Advocates/Published 2026-08-17/Reviewed 2026-08-17/8 min read

Because virtual assets are bearer instruments at the protocol level, a security failure, a compromised key, an exploited smart contract, a breached admin account, can be irreversible in a way traditional banking incidents often are not. This is why cybersecurity and technology governance sit prominently in the VASP Regulations rather than as an afterthought.

Technology governance

Regulators are likely to expect clear board and senior management accountability for technology risk, not delegation to a technical team without oversight. A documented ICT governance framework should set out who is accountable for systems decisions, security posture and incident response authority.

Core cybersecurity controls

  • Access control. Role-based access, multi-factor authentication, and strict controls over privileged and administrative access to systems handling customer assets or data.
  • Key management. Documented procedures for generating, storing and using private keys, including multi-signature or hardware security module arrangements for high-value holdings.
  • Logging and monitoring. Comprehensive, tamper-resistant logging of system access and transactions, with active monitoring for anomalous activity.
  • Vulnerability management. A documented process for identifying, prioritising and remediating vulnerabilities across infrastructure and applications.

Testing and audit

Applicants and licensees should expect to demonstrate periodic security testing, including penetration testing of externally facing systems, and, where the business relies on smart contracts, independent smart-contract audits before deployment and after material changes. The frequency and scope of testing that regulators expect should be confirmed against the current Regulations and any supplementary guidance for your licence category.

Statutory requirement vs good implementation practice

Not every specific control described in this article is necessarily a rigid mandatory minimum spelled out for every licence category; some reflect the standard of implementation that a well-run compliance and technology function should meet under the Regulations' more general risk-based cybersecurity expectations. Confirm the specific mandatory requirements applicable to your licence category directly against the current Regulations.

Outsourcing and vendor risk

Where infrastructure, cloud hosting, or key technology functions are outsourced, licensees remain accountable for the security of those functions. Vendor risk assessments, contractual security obligations, and the right to audit critical vendors should be built into outsourcing arrangements from the start.

Business continuity and disaster recovery

Licensees should maintain documented business continuity and disaster recovery plans covering system outages, data loss and cyber incidents, tested periodically rather than left as an unexercised document.

Incident response and notification

A documented incident response plan should address containment, customer communication, and any regulatory notification obligations that arise from a security incident. Where regulatory notification is required, timelines and thresholds should be confirmed against the current Regulations, since prompt, transparent handling of incidents is generally viewed far more favourably by regulators than delayed disclosure.

Evidence to prepare for an application

  • ICT governance and cybersecurity policy documentation
  • Key management procedures and access control architecture
  • Evidence of recent penetration testing or security audits
  • Business continuity and disaster recovery plans, including test records
  • Incident response plan and any vendor/outsourcing risk assessments

Mid-article CTA

Preparing your technology and cybersecurity documentation for a licence application? We help structure and review the technology-control evidence regulators expect to see.

Discuss your systems readiness

Frequently asked questions

Is penetration testing mandatory for every VASP in Kenya?

Testing expectations should be confirmed against the current Regulations for your specific licence category; as a matter of good practice, periodic testing of externally facing systems is expected across custodial and exchange-type businesses regardless of the precise statutory minimum.

Are smart contract audits a regulatory requirement?

Where a business relies on smart contracts for customer-facing functions, independent audit before deployment is a strong risk-management practice and is likely to be expected as part of a credible technology governance framework, even where not spelled out as a specific numbered requirement for every category.

What should happen if a VASP suffers a security breach?

A licensee should follow its documented incident response plan, covering containment, customer communication and any applicable regulatory notification. Prompt, transparent handling is generally viewed far more favourably by regulators than delayed disclosure.

Key legal sources

  • Kenya Law — Virtual Asset Service Providers Act, 2025 (Act No. 20 of 2025)
  • Kenya Law — Virtual Asset Service Providers Regulations, 2026 (Legal Notice No. 134 of 2026)
  • Central Bank of Kenya and Capital Markets Authority public guidance on VASP licensing

Related insights

The information on this website is general in nature, is not legal advice, and does not create an advocate-client relationship. Figures, fees, capital thresholds and procedural requirements under the Virtual Asset Service Providers Act, 2025 and the Virtual Asset Service Providers Regulations, 2026 should be confirmed against the current Gazette text and regulator guidance before action is taken. Regulatory requirements may also be supplemented by subsequent guidance, notices or licensing requirements issued by the CBK or CMA. Please contact Njau & Associates Advocates for advice on your specific circumstances.