Critical infrastructure: what the 2026 Regulations require

In June 2026 Mauritius put in place a framework for designating critical information infrastructure. Five sectors are covered, a national committee decides, and designated organisations inherit enforceable obligations. The timetable allows until 1 June 2027 to comply — a shorter runway than it looks.
What the text actually says
The Cybersecurity and Cybercrime (Critical Information Infrastructure Designation) Regulations 2026, issued as Government Notice No. 113 of 2026, were made by the Minister on 29 May 2026 under section 51 of the Cybersecurity and Cybercrime Act 2021. They appeared in Government Gazette No. 45 of 20 June 2026 and came into operation on 1 June 2026.
The Regulations cover five sectors, listed unambiguously: financial services, banking and non-banking; the public service; information and communication technology and broadcasting; energy and water supply; and the transport industry. The explicit mention of non-banking widens the perimeter considerably against a casual reading: management companies, insurers and global business financial services providers fall within scope.
The text is short — ten regulations — but its architecture is clear. The National Cybersecurity Committee, in consultation with the regulator, designates systems against the criteria in section 33(2) of the Act, by public notice in the Gazette. The owner of a designated system must comply with the regulator's directions under section 34. Access to the system's architecture and its vulnerabilities is restricted to persons authorised in writing. Each designation is reviewed every three years.
A deadline of 1 June 2027
Regulation 9 allows twelve months from commencement, which sets the deadline at 1 June 2027. Eleven months remain as these lines are written, and that is less comfortable than it sounds for an organisation with no inventory of its critical systems, no documented access management and no tested recovery plan.
On penalties, a clarification is needed because incorrect figures have circulated. Regulation 8 provides for a fine not exceeding 100,000 rupees and imprisonment for a term not exceeding five years. The far heavier numbers sometimes quoted — around two million rupees and twenty-five years — sit elsewhere in the 2021 Act and target those who attack a critical infrastructure, not the operator who falls short on compliance. The confusion is common; it is also avoidable.
What designation means in practice
The Regulations do not prescribe detailed technical measures: they install a designation mechanism and defer to the regulator's directions. That is precisely what should hold a board's attention. An obligation to comply with future instructions, without knowing which or when, cannot be handled in a rush: it assumes a baseline is already in place.
Three requirements read between the lines. Control of access to architecture and vulnerabilities first, which means knowing who holds the diagrams, the audit results and the administrative credentials — and being able to prove it in writing. The ability to answer the regulator next, which assumes documented audits rather than convictions. And continuity last: a critical system is by definition one whose failure creates a collective problem, which makes a tested recovery plan hard to avoid.
Not designated? It still concerns you
Designation targets systems, so a limited number of organisations. But the cascade effect is predictable, and it is the most interesting mechanism here, commercially and operationally. A designated entity that must comply with the regulator's directions will pass those requirements down to its suppliers: hosting provider, managed service provider, software vendor, integrator, backup provider.
If you supply a bank, an insurer, a telecoms operator, a government body, an electricity or water utility, or a transport operator, new questionnaires and contract clauses are coming. The pattern matches DORA requirements for Mauritian providers: regulation hits the client, the contract hits the supplier. Better to prepare the answers before the tender than during it.
What to have ready
- Check your sector: banking and non-banking financial services, public service, ICT and broadcasting, energy and water, transport.
- Inventory the systems whose failure would have consequences beyond your own company.
- Document access to architecture, audit results and vulnerabilities — with named written authorisation.
- Review administrative privileges and remove shared accounts.
- Put monitoring in place capable of detecting and time-stamping an incident.
- Test the recovery plan and record the times actually achieved.
- Assemble the evidence file: policies, logs, audit reports, exercise records.
- Anticipate the contractual cascade if you serve a client in one of the five sectors.
- Set an internal deadline well before 1 June 2027, and have the gap assessed if the subject is new to you.
How SOVALYX can help
SOVALYX prepares organisations likely to be designated: an inventory of genuinely critical systems, documented control of access to architecture and vulnerabilities, continuous monitoring, and a recovery plan that has been tested and timed. We then run that baseline under SLA, with the written evidence a designation makes necessary — so you can answer a regulator's direction without starting from scratch.
Talk compliance with an engineer🧰 The companion tool: Are you ready for the AI Act? — free · 2 minutes.
Reviewed and optimised by AI.