The journal
Governance

Uganda's Computer Misuse Act and what 'authorized' really means

Governance 14 August 2026 1 min read

Uganda's Computer Misuse Act and what 'authorized' really means

A working reading of the 2011 Act, NITA-U guidance, and why a signed scope matters even for the most well-intentioned penetration test.

Legal & Compliance · BeeraSafe

The Act in one paragraph

Uganda's Computer Misuse Act (2011) criminalizes unauthorized access, intentional interference, and a range of computer-related offences. The word that matters for security work is unauthorized: the Act does not ban security testing, it bans access that lacks authorization. The discipline of pen testing is proving that an activity was authorized before it ran.

What NITA-U guidance adds

NITA-U issues guidance and registers service providers in the sector. For a security firm, that means keeping an operator record, maintaining evidence standards, and being able to show an audit trail for work performed. The guidance leans into the same principle as the Act: documented authorization, documented scope.

Why a signed scope is not a formality

A penetration test against a system you operate is different from a penetration test against a client's system, which is different from a test against a third party. The scope document records who authorized what, when, and for how long. If a system is outside the written scope, it is off-limits — even if the test 'would have worked'.

For clients buying this work, the same document is their protection: it proves the test was scoped, the operators were held to a boundary, and the findings were produced under a documented authorization.

Bottom line

The Act does not stop security work — it demands it be authorized. A written, scoped, signed engagement is both the legal frame and the professional standard.

#uganda#regulation#authorization