New rules governing how telecom operators respond to cybersecurity incidents will take effect in Kazakhstan on October 11, 2026. In certain cases, subscribers will first receive an SMS demanding that they eliminate the threat, and if the problem is not resolved within 48 hours, the operator will be able to restrict the device's internet access, the website infohub.kz reports.
The specific grounds and procedure are set out in a new regulatory document. The detailed requirements were published in Order No. 569/НҚ of the Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan, dated September 24, 2026. The new procedure takes effect on October 11, 2026.
According to the document, the basis for considering the suspension of communication services will be information about an incident that disrupts the operation of communication networks or poses a threat to cybersecurity.
Such information may come from a cybersecurity assurance center or the National Coordination Center for Cybersecurity (NCCCS).
Cybersecurity assurance centers must conduct round-the-clock monitoring of networks. If an incident is detected, the NCCCS sends the relevant information to the telecom operator and the cybersecurity assurance center within 24 hours.
Restricting internet access also involves a specific procedure for interacting with the subscriber.
The operator is obliged to restrict the subscriber device's internet access in two prescribed cases:
First, if the subscriber has not eliminated incidents identified by the operator that could serve as grounds for suspending services.
Second, if the operator has received information from the NCCCS or response services about incidents that pose a threat to critically important digital facilities.
Before restricting access, the subscriber must be sent an SMS message demanding that they eliminate the identified incident. After the message is sent, the user will have 48 hours to resolve the problem.
If the incident is not eliminated after this period, the operator will be able to restrict internet access.
The new rules therefore provide not for instantly disconnecting a user once a threat is detected, but for a step-by-step procedure: identifying the incident, notifying the subscriber, and giving them 48 hours to resolve the problem.


