The journal
Governance

Uganda's Computer Misuse Act and what 'authorized' really means

Governance 14 August 2026 1 min read

Uganda's Computer Misuse Act and what 'authorized' really means

A working reading of the 2011 Act, NITA-U guidance, and why a signed scope matters even for the most well-intentioned penetration test.

Legal & Compliance · BeeraSafe

The Act in one paragraph

Uganda's Computer Misuse Act (2011) criminalizes unauthorized access, intentional interference, and a range of computer-related offences. The key term for security work is unauthorized: the Act does not prohibit security testing, it prohibits access lacking authorization. Penetration testing requires proving authorization before testing begins.

What NITA-U guidance adds

NITA-U issues guidance and registers service providers in the sector. For a security firm, this means maintaining operator records, upholding evidence standards, and demonstrating an audit trail for all work performed. The guidance aligns with the Act’s principle: documented authorization and documented scope.

Why a signed scope is not a formality

A penetration test against a system you operate differs from one against a client’s system, which differs from a test against a third party. The scope document records who authorized what, when, and for how long. If a system falls outside the written scope, it is off-limits - even if the test “would have worked.”

For clients purchasing this work, the same document provides protection: it proves the test was scoped, operators adhered to boundaries, and findings resulted from documented authorization.

Bottom line

The Act does not stop security work - it demands it be authorized. A written, scoped, signed engagement serves as both the legal framework and the professional standard.

#uganda#regulation#authorization

Discussion(0)