К содержанию

What the law requires from employers on cybersecurity

A calm explanation of what changed in Kazakhstan on 25 August 2026 and what you practically need to put in place in your company.

1.What changed on 25 August 2026

In Kazakhstan, from 25 August 2026, employers must inform their employees of the requirements set out in the company's own cybersecurity rules and run internal checks that those rules are followed.

This is a new duty for employers in the Labour Code of the Republic of Kazakhstan: art. 23(2)(25-1). At the same time employees were given a matching duty to follow the cybersecurity requirements at their workplace (art. 22(2)(3)).

The changes were introduced by Law of the Republic of Kazakhstan No. 326-VIII of 24 June 2026 and took effect 60 days after official publication, on 25 August 2026.

In practice this means three things: the company must have internal cybersecurity rules, the employees must be informed of them, and someone must check that they are followed.

Labour Code of the Republic of Kazakhstan, art. 23(2)(25-1) — adilet.zan.kz

2.What an «employer act on cybersecurity» is

An employer act is an internal company document approved by the head of the company. It sets out the rules employees have to follow: how to handle passwords and access rights, how to work with email and files, what to do in a suspicious situation, and who is responsible for what.

The law does not require one particular form. What matters is that the document is approved, that employees can understand it, and that it is genuinely applied.

The term «employer act» — art. 1 of the Labour Code of the Republic of Kazakhstan

3.What informing employees means

Informing employees means confirming that each of them has read the requirements and knows about them. Usually this is a signature in a register or on a sign-off sheet. New employees sign when they are hired; everyone else signs when the act is approved or changed.

  • A register of sign-offs with signatures and dates
  • Sign-off by new employees when they are hired
  • A fresh sign-off when the act is changed

4.What internal control means

Internal control means checking regularly that the requirements are being met: a responsible person has been named, the registers are being kept, staff have been trained, computers are protected, and incidents are recorded. The easiest way to do this is with a check-list on a clear schedule.

  • A named responsible employee
  • An internal check-list
  • An incident register
  • Clear reporting for the director

5.Which supporting documents it makes sense to keep

If questions come up, the company needs to show that the requirements were written down, passed on to employees and checked. For that it makes sense to keep:

  • The employer act on cybersecurity
  • The order approving the act
  • The order naming the responsible person
  • The register of employee sign-offs
  • The incident register
  • Completed internal check-lists
  • Proof that training was attended

6.Some organisations have extra requirements

Some organisations are subject to special requirements on top of the general ones: financial organisations, state bodies and owners of critically important information and communication infrastructure, for example. If your company is one of them, check the rules that apply to you separately.

7.Частые вопросы

Employer cybersecurity document kit

Act, orders, registers, checklist, instructions.

15 999 ₸

Staff training

Phishing, passwords, protecting data, what to do in suspicious situations.

6 000 ₸ / employee

Assistant for the responsible employee

We tell them what to do and help keep the documents and controls in order.

from 49 000 ₸ / month