One set of standards for a trustworthy digital government

Discover the standards every public ICT system must meet, and how to get your company or team accredited.

Why standards matter

One set of rules, so every government system can talk to each other

The ICT Authority sets and enforces the technical, security and procurement standards that every public ICT system in Kenya must meet. Standards protect citizen data, keep public money out of substandard equipment, and make sure a system built in one county can connect cleanly to a system built in another.

Mandatory compliance
All national and county government ICT projects must comply before rollout.
Reviewed regularly
Standards are revised as technology, threats and regulation evolve.
Supplier accreditation
ICT vendors and professionals are accredited against these standards.
Independently audited
Compliance is verified through audits, site visits and certification renewal.
Data centre standards compliance
4 standards categories
Covering infrastructure, data, software and telecoms
GEA framework

The 9 Government ICT Standards

The Government Enterprise Architecture (GEA) Framework defines the minimum components of every public-service ICT plan. Nine standards across six domains are mandatory for Ministries, Counties and Agencies.

ICTA 1:001
GEA General Guiding Principles
The foundation standard that defines architecture principles, governance roles and how MCAs should align their ICT plans.
ICTA 5:002
IT Governance Standard
Decision-rights, oversight structures and risk-management practices required across every public-service ICT investment.
ICTA 2:001
Network Standard
Design, sizing, monitoring and security requirements for every LAN, WAN and metro network deployed in government.
ICTA 2:002
Data Centre Standard
Tier classification, environmental controls, redundancy and physical-security baselines for government data centres.
ICTA 2:003
Cloud Computing Standard
Adoption framework for IaaS, PaaS and SaaS in the public service, including data sovereignty and exit clauses.
ICTA 2:004
End-User Computing Devices Standard
Minimum specifications and lifecycle management for laptops, desktops, tablets and peripherals across government.
ICTA 6:001
Systems & Applications Standard
Development, integration, interoperability and website-management standards for every government-facing application.
ICTA 3:001
Information Security Standard
Risk management, access control, encryption and incident-response controls protecting public data and systems.
ICTA 4:001
Electronic Records Management
Capture, retention and disposal rules for every electronic record produced or held by a public-service body.
Supplier & professional accreditation

How to get accredited

Four steps to becoming a recognised ICT supplier or professional within the Kenyan government ecosystem.

1
Register on the portal
Create an account on the Accreditation Portal and select your category — supplier, contractor or professional.
2
Submit documentation
Upload company registration, tax compliance, technical capability and staff qualification documents.
3
Assessment & verification
Our standards team reviews your submission and may schedule a technical or site verification visit.
4
Certificate issued
Approved applicants receive an accreditation certificate, valid for renewal review every two years.
Documents

Download standards documents

All standards documents
GEA General Guiding Principles (ICTA 1:001)
PDF · 3.1 MB · Updated Mar 2026
IT Governance Standard (ICTA 5:002)
PDF · 2.4 MB · Updated 2019
Information Security Standard (ICTA 3:001)
PDF · 2.6 MB · Updated Jan 2026
Systems & Applications Standard (ICTA 6:001)
PDF · 2.8 MB · Updated 2016
Accreditation Application Form
DOCX · 175 KB

Ready to apply for accreditation?

Register on the Accreditation Portal or speak to our standards team about your specific category.