Uganda's Computer Misuse Act and what 'authorized' really means
Uganda's Computer Misuse Act and what 'authorized' really means
A working reading of the 2011 Act, NITA-U guidance, and why a signed scope matters even for the most well-intentioned penetration test.
The Act in one paragraph
Uganda's Computer Misuse Act (2011) criminalizes unauthorized access, intentional interference, and a range of computer-related offences. The key term for security work is unauthorized: the Act does not prohibit security testing, it prohibits access lacking authorization. Penetration testing requires proving authorization before testing begins.
What NITA-U guidance adds
NITA-U issues guidance and registers service providers in the sector. For a security firm, this means maintaining operator records, upholding evidence standards, and demonstrating an audit trail for all work performed. The guidance aligns with the Act’s principle: documented authorization and documented scope.
Why a signed scope is not a formality
A penetration test against a system you operate differs from one against a client’s system, which differs from a test against a third party. The scope document records who authorized what, when, and for how long. If a system falls outside the written scope, it is off-limits - even if the test “would have worked.”
For clients purchasing this work, the same document provides protection: it proves the test was scoped, operators adhered to boundaries, and findings resulted from documented authorization.
Bottom line
The Act does not stop security work - it demands it be authorized. A written, scoped, signed engagement serves as both the legal framework and the professional standard.

