The Communications Authority of Kenya (CA) wants your input on new technical rules for network equipment sold and used in the country.
The regulator has published a draft document called Technical Specifications for Network Equipment, 2026, and is accepting comments from the public and ICT industry until September 30, 2026.
Beyond telecommunications, broadcasting, e-commerce, cybersecurity, and postal and courier services, part of CA’s job is running a Type Approval process, which is basically a certification system that checks equipment before it can be sold or connected to networks in the country.
The new specifications will serve as the technical rulebook for that process going forward.
The rules cover a wide range of equipment, including switches, routers, firewalls, gateways, servers, network interface cards, and session border controllers.
Essentially, any device that connects to public telecom networks, mobile networks, computer networks, or broadcasting networks falls under its scope.
What the New Rules Require
The draft spec is detailed and touches on several areas.
- Power and Efficiency
Equipment must run on Kenya’s standard 240V, 50Hz power supply. It also has to meet a “platinum” level of power efficiency, a fairly high bar borrowed from EU sustainability rules.
- Internet Protocols
Devices need to support IPv6, the newer internet addressing system, in line with the CA’s ongoing push to migrate the country from IPv4.
Equipment must also handle at least one protocol each for network management, security, and communication, plus support for common routing protocols like BGP and RIP.
READ: CA Introduces Distributor License for Importing ICT Equipment
- Interoperability
Equipment needs to work with modern switching technologies (ASIC, TCAM, CAM-based systems) and support MPLS, a networking technique used to keep core networks running efficiently.
- Emissions Limits
The draft sets specific limits on radiated and conducted emissions, meaning how much electromagnetic interference a device can put out, with slightly different thresholds depending on whether it’s used in an industrial or residential setting.
- Security
This is a major focus. Devices must support firewalls-style access controls, intrusion detection and prevention systems, and current versions of encryption protocols like IPSec and TLS.
Secure remote access tools like SSH are also required, along with secure mechanisms for software updates, storage, and monitoring.
- Environmental and Safety Limits
Equipment must operate reliably between 5°C and 45°C with humidity up to 80%, which fits typical conditions in Kenyan telecom equipment rooms.
READ: CA Releases New Environmental Rules for Kenya’s ICT Sector
There are also detailed surface temperature limits to prevent burns, with different thresholds depending on how long a person might touch the device and what material it’s made of.
- Hazardous Materials and e-Waste
Devices can’t contain lead, mercury, cadmium, or other hazardous substances. Equipment imported for sale must also have at least three years of usable life left before reaching end-of-life.
Interestingly, the draft also wants imported gear to come with a “Digital Product Passport,” a record showing what the device is made of, its environmental footprint, and disposal instructions, accessible via a QR code, RFID tag, NFC chip, or online portal.
- Accessibility
Devices meant for end users need to support people with disabilities. This includes having more than one way to interact with the device (not just physical buttons), tactile markings for identifying parts, audio cues for port connections, and standard connectors that work with assistive devices.
READ: CA Delays ICT Regulations After Controversial USB-C Requirement for Phones
- Quality of Service
The specs set numeric targets for network performance, such as keeping voice call delay under 100 milliseconds and data delay under 400 milliseconds, along with limits on packet loss and errors.
- Artificial Intelligence
Perhaps the most forward-looking section: any network equipment that uses AI must be built to protect user safety, privacy, transparency, and intellectual property rights.
If the AI system is classified as “high risk,” the equipment must include human-machine interfaces designed to prevent harm to health, safety, or fundamental rights.
Submit Comments
The specifications aren’t final yet. The CA is treating this as a draft and wants feedback from telecom companies, equipment manufacturers, consumer groups, and the general public before locking anything in.
Once finalized, the rules will shape which network devices are allowed onto the Kenyan market and how they’re expected to perform, from the amount of radiation they emit to how well they protect against cyberattacks.
If you work in telecom, manufacture networking gear, or just care about how connected devices are regulated in Kenya, the comment window closes September 30, 2026. Anyone interested can send feedback to [email protected].



























