KAZAKHSTAN
N/A
Pillar Cross-border data policies |
Indicator Participation in trade agreements committing to open cross-border data flows
Lack of participation in agreements with binding commitments on data flows
Kazakhstan has not joined any agreement with binding commitments to open transfers of data across borders.
Coverage Horizontal
KAZAKHSTAN
Since May 2013, last amended in December 2025
Since July 2020
Since July 2020
Pillar Domestic data policies |
Indicator Framework for data protection
Law of the Republic of Kazakhstan of 21 May 2013 No. 94-V on Personal Data and Its Protection (Қазақстан Республикасының 2013 жылғы 21 мамырдағы № 94-V Заңы Дербес деректер және оларды қорғау туралы)
Law on Amendments and Additions to Some Legislative Acts of the Republic of Kazakhstan on the Regulation of Digital Technologies (Қазақстан Республикасының Заңы 2020 жылғы 25 маусымдағы № 347-VI ҚРЗ Қазақстан Республикасының кейбір заңнамалық актілеріне цифрлық технологияларды реттеу мәселелері бойынша өзгерістер мен толықтырулар енгізу туралы)
Law on Amendments and Additions to Some Legislative Acts of the Republic of Kazakhstan on the Regulation of Digital Technologies (Қазақстан Республикасының Заңы 2020 жылғы 25 маусымдағы № 347-VI ҚРЗ Қазақстан Республикасының кейбір заңнамалық актілеріне цифрлық технологияларды реттеу мәселелері бойынша өзгерістер мен толықтырулар енгізу туралы)
Law No. No. 94-V provides a comprehensive regime of data protection in Kazakhstan. The Personal Data Law provides general regulations on the collection and processing of personal data and notably includes broad requirements for data localisation. In addition, Law No. 347-VI of 25 June 2020 on "Amendments and Additions to Some Legislative Acts on the Regulation of Digital Technologies" was introduced in July 2020, significantly extending data protection obligations for organisations. Law No. 347-VI introduces, among other things, further requirements for data collection and processing, obligations for data operators (similar to data processors), and redefines key concepts. Law No. 347-VI further establishes the competency of the data protection authority, including its powers and role.
Coverage Horizontal
KAZAKHSTAN
Since July 2004, last amended in November 2025
Since June 2023
Since June 2023
Pillar Domestic data policies |
Indicator Minimum period for data retention
Law of the Republic of Kazakhstan of 5 July 2004 No. 567-II "On Communications" (Қазақстан Республикасының 2004 жылғы 5 шілдедегі N 567 Заңы Байланыс туралы)
Order No. 220/НҚ of 30 June 2023 "On approval of the Rules for the implementation by communications operators of the collection and storage of official information about subscribers and (or) users of communications services" (Байланыс операторларының абоненттері және (немесе) байланыс қызметтерінің пайдаланушылары туралы қызметтік ақпаратты жинауды және сақтауды жүзеге асыру қағидаларын бекіту туралы)
Order No. 220/НҚ of 30 June 2023 "On approval of the Rules for the implementation by communications operators of the collection and storage of official information about subscribers and (or) users of communications services" (Байланыс операторларының абоненттері және (немесе) байланыс қызметтерінің пайдаланушылары туралы қызметтік ақпаратты жинауды және сақтауды жүзеге асыру қағидаларын бекіту туралы)
Under Art. 15(1)(2) of Law No. 567-II “On Communications” of 5 July 2004, telecommunications operators and/or owners of communications networks are required to collect and retain service information relating to subscribers and/or users of communications services. This obligation is implemented through Order No. 220/НҚ of 30 June 2023, which approved the Rules for the Collection and Storage by Telecom Operators of Service Information on Subscribers and/or Users of Communication Services.
The Rules require telecommunications operators to retain the relevant service information for a period of two years, after which it must be destroyed. The information subject to retention includes subscriber numbers, IIN/BIN identifiers, device identification codes, billing information, the location of subscriber devices, data-network addresses, addresses and identifiers of internet resources accessed, and data-transmission protocols.
The Rules require telecommunications operators to retain the relevant service information for a period of two years, after which it must be destroyed. The information subject to retention includes subscriber numbers, IIN/BIN identifiers, device identification codes, billing information, the location of subscriber devices, data-network addresses, addresses and identifiers of internet resources accessed, and data-transmission protocols.
Coverage Telecommunications sector
KAZAKHSTAN
Since May 2013, as amended in December 2021, last amended in December 2025
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Law of the Republic of Kazakhstan of 21 May 2013 No. 94-V on Personal Data and Its Protection (Қазақстан Республикасының 2013 жылғы 21 мамырдағы № 94-V Заңы Дербес деректер және оларды қорғау туралы)
According to Art. 25.2(10) of Law No. 94-V, an owner and/or operator of a personal data database, which is a legal entity, should appoint a person responsible for organising the processing of personal data (this requirement does not apply to the activities of courts). According to Art. 25.3, such a person is entrusted with the following duties:
- Exercise internal control over observance by the owner and/or operator of a personal data database and its employees of Kazakh law requirements in relation to personal data and its protection;
- Inform the employees of an owner and/or operator of the provisions of Kazakh law with respect to processing and protection of personal data;
- Exercise control over receipt and processing of applications from personal data subjects or their legal representatives.
- Exercise internal control over observance by the owner and/or operator of a personal data database and its employees of Kazakh law requirements in relation to personal data and its protection;
- Inform the employees of an owner and/or operator of the provisions of Kazakh law with respect to processing and protection of personal data;
- Exercise control over receipt and processing of applications from personal data subjects or their legal representatives.
Coverage Horizontal
KAZAKHSTAN
Since July 2004, as amended in July 2019, last amended in November 2025
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Law of the Republic of Kazakhstan of July 5, 2004 No. 567-II "On Communications" (Қазақстан Республикасының 2004 жылғы 5 шілдедегі N 567 Заңы Байланыс туралы)
In July 2019, the government introduced the Qaznet Trust Certificate under the Law on Communications, a machine-in-the-middle (MITM) technology that enables it to monitor users’ online activities. The certificate requires every internet user in the country to install a backdoor, allowing the government to conduct surveillance. This allows the government to conduct a so-called “man-in-the-middle” attack, which allows the government to intercept every secure connection in the country and see web browsing history, usernames and passwords, and even secure and HTTPS-encrypted traffic.
KazakhTelecom, the country’s largest telecommunications company, has said that citizens are “obliged” to install a “national security certificate” on every device, including desktops and mobile devices.
It is reported that the commentators and experts inside the country and abroad almost unanimously consider the certificate a government-initiated technology for the interception of encrypted user traffic via MITM attacks. Some of the 37 websites that University of Michigan researchers identified as targets of the certificate included Facebook, Gmail, Instagram, Mail.ru, OK, Twitter, VK, and YouTube, suggesting that its purpose was to “surveil users on social networking and communication sites.”
On 21 August 2019, Mozilla and Google simultaneously announced that their Firefox and Chrome web browsers would not accept the government-issued certificate, even if installed manually by users. Later, Apple announced that it would make similar changes to its Safari browser and that the certificate would not be installed. After this, the requirement for the installation of the certificate was postponed.
While required, the certificate appeared to affect a fraction of connections passing through the country’s largest ISP, Kazakhtelecom. This means that some, but not all, of the Kazakh Internet population was affected.
In December 2020, Kazakhstan once again tried to enforce the installation of the certificate. However, the enforcement once again halted after the protest of the major internet browsers. Although not enforced, the provisions for mandatory installation of the certificate remain in Kazakhstan's regulations.
KazakhTelecom, the country’s largest telecommunications company, has said that citizens are “obliged” to install a “national security certificate” on every device, including desktops and mobile devices.
It is reported that the commentators and experts inside the country and abroad almost unanimously consider the certificate a government-initiated technology for the interception of encrypted user traffic via MITM attacks. Some of the 37 websites that University of Michigan researchers identified as targets of the certificate included Facebook, Gmail, Instagram, Mail.ru, OK, Twitter, VK, and YouTube, suggesting that its purpose was to “surveil users on social networking and communication sites.”
On 21 August 2019, Mozilla and Google simultaneously announced that their Firefox and Chrome web browsers would not accept the government-issued certificate, even if installed manually by users. Later, Apple announced that it would make similar changes to its Safari browser and that the certificate would not be installed. After this, the requirement for the installation of the certificate was postponed.
While required, the certificate appeared to affect a fraction of connections passing through the country’s largest ISP, Kazakhtelecom. This means that some, but not all, of the Kazakh Internet population was affected.
In December 2020, Kazakhstan once again tried to enforce the installation of the certificate. However, the enforcement once again halted after the protest of the major internet browsers. Although not enforced, the provisions for mandatory installation of the certificate remain in Kazakhstan's regulations.
Coverage Telecommunications sector
Sources
- https://web.archive.org/web/20230307044623/https://adilet.zan.kz/eng/docs/Z040000567_
- https://www.gp-digital.org/world-map-of-encryption/
- https://web.archive.org/web/20230215091055/https://freedomhouse.org/country/kazakhstan/freedom-net/2020
- https://web.archive.org/web/20230923120905/https://www.engadget.com/tech-giants-browsers-block-kazakhstan-web-surveillance-080031499.html
- https://web.archive.org/web/20220320025856/https://www.reuters.com/article/us-kazakhstan-internet-surveillance-idUSKCN1UX0VD
- https://web.archive.org/web/20220328030754/https://venturebeat.com/2019/08/21/google-and-mozilla-block-kazakhstan-root-ca-certificate-from-chrome-and-firefox/
- https://web.archive.org/web/20230329115524/https://censoredplanet.org/kazakhstan
- Show more...
KAZAKHSTAN
N/A
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for copyright infringement
Lack of intermediary liability framework in place for copyright infringements
A basic legal framework on intermediary liability for copyright infringement is absent in Kazakhstan's law and jurisprudence. However, the Agreement on Enhanced Partnership between the EU and the Republic of Kazakhstan, signed in March 2016, provides a safe harbour to European companies under several conditions. According to the agreement, an information intermediary is not liable, for example, if it does not initiate the transfer, if the end-user always takes the initiative, if it does not choose the recipient of the transfer if it does not choose or change the information contained in the transfer if it complies with the conditions of access to information, observes rules for updating information, does not interfere with the lawful use of generally recognised technologies, immediately deletes information or stops access to it, after receiving a notice.
Coverage Internet intermediaries
KAZAKHSTAN
N/A
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for any activity other than copyright infringement
Lack of intermediary liability framework in place beyond copyright infringement
A basic legal framework on intermediary liability beyond copyright infringement is absent in Kazakhstan's law and jurisprudence. However, the Agreement on Enhanced Partnership between the EU and the Republic of Kazakhstan, signed in March 2016, provides a safe harbour to European companies under several conditions. According to the agreement, an information intermediary is not liable, for example, if it does not initiate the transfer, if the end-user always takes the initiative, if it does not choose the recipient of the transfer, if it does not choose or change the information contained in the transfer if it complies with the conditions of access to information, observes rules for updating information, does not interfere with the lawful use of generally recognised technologies, immediately deletes information or stops access to it, after receiving a notice.
Coverage Internet intermediaries
KAZAKHSTAN
Since December 2017, entry into force in April 2018
Pillar Intermediary liability |
Indicator User identity requirement
Law on Amendments and Additions to Certain Legislative Acts of the Republic of Kazakhstan on Information and Communications (Закон Республики Казахстан от 28 декабря 2017 года № 128-VI «О внесении изменений и дополнений в некоторые законодательные акты Республики Казахстан по вопросам информации и коммуникаций» (с изменениями от 24.05.2018 г.))
As per the requirements of the Law on Amendments and Additions to Certain Legislative Acts of the Republic of Kazakhstan on Information and Communications (2017), users have been required to identify themselves using government-issued digital signature technology or SMS verification in order to comment on domestic websites. Failure to enforce the rule after April 2018 can lead to fines. The law requires website operators to make it mandatory for users to enter into a formal agreement before they are permitted to post comments on local websites. The information provided in the agreement needs to be retained by the website and handed over to the authorities whenever asked.
Coverage Domestic websites
Sources
- https://web.archive.org/web/20231210002921/https://eurasianet.org/kazakhstan-online-anonymity-ban-in-force-from-april
- https://web.archive.org/web/20230202023623/https://freedomhouse.org/country/kazakhstan/freedom-net/2020
- https://web.archive.org/web/20220928063642/https://online.zakon.kz/document/?doc_id=34205812&show_di=1#pos=1;-16
- Show more...
KAZAKHSTAN
Since July 2004, as amended in 2016, last amended in November 2025
Since July 2014, last amended in November 2022
Since July 2014, last amended in November 2022
Pillar Intermediary liability |
Indicator Monitoring requirement
Law of the Republic of Kazakhstan of July 5, 2004 No. 567-II "On Communications" (Қазақстан Республикасының 2004 жылғы 5 шілдедегі N 567 Заңы Байланыс туралы)
The Code of the Republic of Kazakhstan «On Administrative Infractions» (Қазақстан Республикасының Кодексі 2014 жылғы 5 шілдедегі № 235-V ҚРЗ Әкімшілік құқық бұзушылық туралы)
The Code of the Republic of Kazakhstan «On Administrative Infractions» (Қазақстан Республикасының Кодексі 2014 жылғы 5 шілдедегі № 235-V ҚРЗ Әкімшілік құқық бұзушылық туралы)
Under Art. 41-1(1-1), (2) and (3)(1) of Law No. 567-II on Communications, telecommunications operators must restrict access to information prohibited by law or by a final court decision when instructed by the competent authority. Operators must implement such instructions within no more than two hours. Art. 637(1)(9-5) of the Code of Administrative Offences imposes fines where a communications operator provides access to prohibited information. It is reported that this framework also requires ISPs to monitor content passing through their networks and determine whether problematic material should be restricted, although the legislation does not specify how such monitoring is to be carried out.
Coverage Internet service
KAZAKHSTAN
Reported in 2017, last reported in 2025
Pillar Content access |
Indicator Blocking or filtering of commercial web content
Blocking of websites
It is reported that the government routinely blocks or filters online content and may compel ISPs to restrict access to material considered unlawful; if providers do not comply promptly, the State Technical Service may implement the block directly. Website blocking reportedly continued during the June 2024–May 2025 coverage period. At least 17 media websites, several human-rights and petition websites, and 73 circumvention-tool websites, including commercial VPN services such as NordVPN, ExpressVPN, ProtonVPN, TunnelBear and Surfshark, were reportedly subject to coordinated blocking across Kazakhstani networks, mainly through TLS interference.
Coverage Horizontal
KAZAKHSTAN
Reported in 2026
Pillar Content access |
Indicator Presence of Internet shutdowns
Presence of Internet shutdowns
The indicator "7.2.4 - Government Internet shut down in practice" of the V-Dem Dataset, which measures whether the government has the technical capacity to actively make internet service cease, thus interrupting domestic access to the internet or whether the government has decided to do so, has a score of 2 in Kazakhstan for the year 2025. This corresponds to "The government shut down domestic access to the Internet several times this year."
Coverage Horizontal
KAZAKHSTAN
N/A
Pillar Telecom infrastructure & competition |
Indicator Presence of an independent telecom authority
Lack of an independent telecom authority
Kazakhstan has a telecommunications authority: The Telecommunications Committee of the Ministry of Digital Development, Innovations and Aerospace Industry of the Republic of Kazakhstan. However, it is reported that this entity's decision-making process is not fully independent of the government.
Coverage Telecommunications sector
KAZAKHSTAN
Since April 2015, last amended in August 2025
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Other import restrictions, including non-transparent/discriminatory import procedures
Decision No. 30 of the Eurasian Economic Commission Board "On Measures of Non-tariff regulation" (Решение Коллегии Евразийской экономической комиссии от 21 апреля 2015 г. N 30 "О мерах нетарифного регулирования")
Appendix No. 2 to the Decision of the Board of the Eurasian Economic Commission No. 30 of 21 April 2015 (“On Measures of Non-Tariff Regulation”) sets out the Union-wide list of goods restricted for import into the customs territory of the Eurasian Economic Union (EAEU), including Kazakhstan. The list includes, among others, (i) radio-electronic and high-frequency equipment for civilian use—devices for transmitting or receiving voice, images, or data (e.g., headings in HS 8471, 8517–8519, 8521, 8525–8528, 8531, and certain Chapter 90 items); (ii) systems and receivers for technical radio monitoring and for detecting sources of electromagnetic emissions (e.g., HS 8526–8527); and (iii) encryption (cryptographic) means, including computing machines and parts with cryptographic functions, computer devices incorporating encryption, and standalone cryptographic software (selected subheadings of HS 8471/8473 and 8523).
Coverage Telecom and cryptographic equipment
KAZAKHSTAN
Since May 2013, as amended in November 2015, last amended in December 2025
Since November 2015, as amended in January 2021
Since June 2023, last amended in 2024
Since November 2015, as amended in January 2021
Since June 2023, last amended in 2024
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Law of the Republic of Kazakhstan of 21 May 2013 No. 94-V on Personal Data and Its Protection (Қазақстан Республикасының 2013 жылғы 21 мамырдағы № 94-V Заңы Дербес деректер және оларды қорғау туралы)
Law No. 418-V ZRK of the Republic of Kazakhstan on Informatization (Қазақстан Республикасының Ақпараттандыру туралы Заңы 2015 жылғы 24 қарашадағы № 418-V ҚРЗ)
Order of the Minister of Digital Development, Innovation and Aerospace Industry of the Republic of Kazakhstan, No. 179/NK, on Approval of the Rules for the Implementation by the Owner and (or) the Operator, as well as by a Third Party, of Measures to Protect Personal Data (Қазақстан Республикасының Цифрлық даму, инновациялар және аэроғарыш өнеркәсібі министрінің 2023 жылғы 12 маусымдағы № 179/НҚ бұйрығы Меншік иесінің және (немесе) оператордың, сондай-ақ үшінші тұлғаның дербес деректерді қорғау жөніндегі шараларды жүзеге асыру қағидаларын бекіту туралы)
Law No. 418-V ZRK of the Republic of Kazakhstan on Informatization (Қазақстан Республикасының Ақпараттандыру туралы Заңы 2015 жылғы 24 қарашадағы № 418-V ҚРЗ)
Order of the Minister of Digital Development, Innovation and Aerospace Industry of the Republic of Kazakhstan, No. 179/NK, on Approval of the Rules for the Implementation by the Owner and (or) the Operator, as well as by a Third Party, of Measures to Protect Personal Data (Қазақстан Республикасының Цифрлық даму, инновациялар және аэроғарыш өнеркәсібі министрінің 2023 жылғы 12 маусымдағы № 179/НҚ бұйрығы Меншік иесінің және (немесе) оператордың, сондай-ақ үшінші тұлғаның дербес деректерді қорғау жөніндегі шараларды жүзеге асыру қағидаларын бекіту туралы)
Under Art. 12(2) of Law No. 94-V on Personal Data and Its Protection, personal data must be stored by the owner and/or operator, as well as by third parties, in a database located within the territory of Kazakhstan.
This localisation framework was further reinforced in 2021, when Art. 36(8) was added to the Law on Informatization. Under this provision, personal data contained in electronic information resources must be stored by the owner and/or operator, as well as by third parties, in an electronic database located within Kazakhstan. As of 2025, the provision specifies that such a database must be located in a server room or data processing centre situated within the territory of the Republic of Kazakhstan. It also requires the adoption of appropriate measures to protect personal data in accordance with the procedure established by the competent authority. Under the Law, “electronic information resources” are defined as data in electronic-digital form contained on electronic media and in information objects.
Further technical requirements are set out in the Rules for the Implementation of Measures to Protect Personal Data by Owners, Operators and Third Parties, adopted pursuant to Art. 27-1 of Law No. 94-V. Under Paragraph 8 of the Rules, the collection and processing of personal data with restricted access must be carried out through information facilities located within Kazakhstan. The storage and transfer of such data must also be protected using cryptographic information-protection tools meeting at least the third level of security established under the applicable Kazakhstan standard.
A similar provision had previously been contained in Paragraph 10 of the predecessor Rules adopted in 2021. Those Rules were repealed in 2023 upon the entry into force of the current Rules, thereby maintaining continuity in the applicable data-localisation and data-protection framework.
This localisation framework was further reinforced in 2021, when Art. 36(8) was added to the Law on Informatization. Under this provision, personal data contained in electronic information resources must be stored by the owner and/or operator, as well as by third parties, in an electronic database located within Kazakhstan. As of 2025, the provision specifies that such a database must be located in a server room or data processing centre situated within the territory of the Republic of Kazakhstan. It also requires the adoption of appropriate measures to protect personal data in accordance with the procedure established by the competent authority. Under the Law, “electronic information resources” are defined as data in electronic-digital form contained on electronic media and in information objects.
Further technical requirements are set out in the Rules for the Implementation of Measures to Protect Personal Data by Owners, Operators and Third Parties, adopted pursuant to Art. 27-1 of Law No. 94-V. Under Paragraph 8 of the Rules, the collection and processing of personal data with restricted access must be carried out through information facilities located within Kazakhstan. The storage and transfer of such data must also be protected using cryptographic information-protection tools meeting at least the third level of security established under the applicable Kazakhstan standard.
A similar provision had previously been contained in Paragraph 10 of the predecessor Rules adopted in 2021. Those Rules were repealed in 2023 upon the entry into force of the current Rules, thereby maintaining continuity in the applicable data-localisation and data-protection framework.
Coverage Horizontal
Sources
- https://web.archive.org/web/20231206150241/https://adilet.zan.kz/kaz/docs/Z1300000094
- https://prg.kz/m/amp/document/34689052/6/
- https://www.morganlewis.com/-/media/files/publication/outside-publication/article/2024/data-localization-laws-overview-kazakhstan.pdf
- https://web.archive.org/web/20240522042804/https://adilet.zan.kz/kaz/docs/V2300032810
- https://www.dataguidance.com/notes/kazakhstan-data-transfers
- Show more...
KAZAKHSTAN
Since November 2015, as amended in December 2017
Since April 2018, as amended in October 2022, May 2023, December 2024 and November 2025
Since April 2018, as amended in October 2022, May 2023, December 2024 and November 2025
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Local content requirements (LCRs) on ICT goods for the commercial market
Law No. 418-V ZRK of the Republic of Kazakhstan on Informatization (Қазақстан Республикасының Ақпараттандыру туралы Заңы 2015 жылғы 24 қарашадағы № 418-V ҚРЗ)
Order No. 53/НҚ of the Minister of Defence and Aerospace Industry of the Republic of Kazakhstan on the Approval of the Rules for the Formation and Maintenance of a Register of Trusted Software and Electronics Industry Products, as well as Criteria for Including Software and Electronics Industry Products in the Register of Trusted Software and Electronics Industry Products (Приказ Министра оборонной и аэрокосмической промышленности Республики Казахстан от 28 марта 2018 года № 53/НҚ Об утверждении Правил формирования и ведения реестра доверенного программного обеспечения и продукции электронной промышленности, а также критериев по включению программного обеспечения и продукции электронной промышленности в реестр доверенного программного обеспечения и продукции электронной промышленности)
Order No. 53/НҚ of the Minister of Defence and Aerospace Industry of the Republic of Kazakhstan on the Approval of the Rules for the Formation and Maintenance of a Register of Trusted Software and Electronics Industry Products, as well as Criteria for Including Software and Electronics Industry Products in the Register of Trusted Software and Electronics Industry Products (Приказ Министра оборонной и аэрокосмической промышленности Республики Казахстан от 28 марта 2018 года № 53/НҚ Об утверждении Правил формирования и ведения реестра доверенного программного обеспечения и продукции электронной промышленности, а также критериев по включению программного обеспечения и продукции электронной промышленности в реестр доверенного программного обеспечения и продукции электронной промышленности)
According to Art. 7.6 of the Informatisation Law, the central executive body carrying out state regulation in the field of the electronic industry is tasked with establishing a unified register of trusted software and electronic products. According to Art. 54.3.1, for the purposes of state security, only approved software may be used for public procurement and for critical information and communication infrastructure, whether state-owned or private, including telecommunication infrastructure.
The "Rules for the Formation and Maintenance of a Register of Trusted Software and Electronics Industry Products, as well as Criteria for Including Software and Electronics Industry Products in the Register of Trusted Software and Electronics Industry Products" previously required software to meet a minimum in-country value share of 70%, including under para. 10(3) of the version restated by Order No. 354/НҚ, published in October 2022. Order No. 829/НҚ, published in December 2024, subsequently reintroduced the localisation requirement, increasing the minimum share to 80% and requiring compliance to be evidenced through an industrial certificate in 2025. Order No. 567/НҚ, published in November 2025, maintained the 80% threshold but abolished the industrial-certificate requirement with effect from January 2026.
The "Rules for the Formation and Maintenance of a Register of Trusted Software and Electronics Industry Products, as well as Criteria for Including Software and Electronics Industry Products in the Register of Trusted Software and Electronics Industry Products" previously required software to meet a minimum in-country value share of 70%, including under para. 10(3) of the version restated by Order No. 354/НҚ, published in October 2022. Order No. 829/НҚ, published in December 2024, subsequently reintroduced the localisation requirement, increasing the minimum share to 80% and requiring compliance to be evidenced through an industrial certificate in 2025. Order No. 567/НҚ, published in November 2025, maintained the 80% threshold but abolished the industrial-certificate requirement with effect from January 2026.
Coverage Software
