Kazakhstan - Digital Transformation Strategy (Resolution No. 269)
Concept of Digital Transformation, ICT Industry Development and Cybersecurity for 2023–2029
Концепция цифровой трансформации, развития отрасли ИКТ и кибербезопасности на 2023–2029 годы
Kazakhstan
RAI-KZ-NA-CDTIIXX-2023A government-approved national strategy (approved by Government Resolution No. 269 of 28 March 2023) setting strategic objectives, targets and an action plan for Kazakhstan’s digital transformation, development of the ICT sector and strengthening of national cybersecurity for the period 2023–2029. It defines governance arrangements, performance indicators, sectoral measures (digital government, data governance, ICT market development, cyber resilience) and an implementation timetable with responsible agencies.
Summary
Read full text ↗Plain English
Overview
The Concept of Digital Transformation, ICT Industry Development and Cybersecurity for 2023–2029 is a government-approved strategic framework designed to accelerate Kazakhstan’s digitalisation agenda, foster a competitive ICT industry and strengthen national cyber resilience. Approved by Government Resolution No. 269 dated 28 March 2023, the Concept organizes actions across four core pillars: (1) digital transformation (including optimisation of public services and e‑government), (2) data governance and information management, (3) ICT industry development and innovation ecosystem growth, and (4) cybersecurity and protection of critical information infrastructure. The document contains a performance-oriented action plan with quantified targets for public service delivery times, connectivity, protection levels of government information systems and population awareness of cyber hygiene. The ministry charged with coordination is the Ministry of Digital Development, Innovations and Aerospace Industry; key operational partners include state ICT operators such as JSC "National Information Technologies" and the Committee for National Security. The full text and implementing plan are published in the national legal information system and on government portals: see Government Resolution No. 269 (adilet.zan.kz) and the explanatory article on the government portal gov.kz.
Definitions
This Concept uses standard policy and technical terms. Key definitions include: "digital transformation" — systemic change in public administration, services and business processes driven by ICT; "e‑government" — the integrated electronic delivery of state services; "data governance" — institutional and technical arrangements for collection, storage, sharing and protection of government and public sector data; "critical information infrastructure" — information systems and networks whose compromise endangers national security, public order or economic stability; "operators of critical information infrastructure" — organizations designated to manage, operate or provide services for such infrastructure; "cybersecurity" — measures to ensure confidentiality, integrity and availability of information assets and communications networks. (See Concept text for authoritative terms and the action plan glossary: adilet.zan.kz.)
Governance and Institutional Framework
The Concept designates the Ministry of Digital Development, Innovations and Aerospace Industry as the primary coordinating and reporting authority responsible for monitoring implementation and liaising with other ministries and agencies. Implementation responsibilities are distributed across central executive bodies, local executive authorities and state corporations; the Committee for National Security is identified for cyber defense and spectrum control tasks. State operators and quasi-public entities such as JSC "National Information Technologies" (АО «НИТ»), the State Technical Service and the Center for Digital Government Support are named as technical implementers. The Concept embeds implementation into Kazakhstan’s State Planning System: ministries must adopt and integrate items into their sectoral action plans and provide periodic reporting under Government procedures. Institutional mechanisms include inter-agency working groups, project management offices for priority initiatives, and dedicated funding lines or procurement processes for infrastructure and software. Governance also foresees public–private engagement with telecom operators, the Astana Hub ecosystem and academic partners to deliver workforce training and R&D programs. See the government publication and the official resolution for assignment of responsibilities and oversight modalities: adilet.zan.kz and Ministry announcements.
Key Focus Areas
The Concept organises policy interventions into discrete focus areas with measurable indicators. Major areas are: (A) Digital public services — streamlining and migrating services to the e‑government platform with targets for the share of services delivered within 5 minutes and progressive annual increases to reach 100% availability by 2029 for targeted services; (B) Data governance — unified approaches to data classification, metadata catalogs, shared data platforms and increased use of administrative data for policy; (C) ICT market development — measures to support domestic suppliers, stimulate investment, public procurement reform, export promotion and strengthening of tech parks and startups; (D) Human capital and skills — large-scale training, curricula updates and programmes to produce ICT specialists; (E) Cybersecurity — strengthening regulatory frameworks, protective measures for e‑government objects, development of centralized registries for radioelectronic devices and spectrum assignments, automated spectrum monitoring systems and public awareness campaigns; (F) Connectivity and spectrum management — ensuring reliable cellular and broadband coverage with international cooperation on spectrum use. Each area contains detailed reforms and a timeline in the attached action plan, balanced between regulatory reforms, capital investments and capacity-building activities. The Concept includes outcome and output indicators (for example, targets on e‑service speed, protection levels of informatization objects and reduction in unlawful spectrum use) which are tracked annually under the State Planning System. For the definitive list of targets and indicators, consult the annexed action plan: adilet.zan.kz.
Implementation Framework
Implementation is managed through a multi-year action plan annexed to the Concept. The plan lists specific reforms, deliverables, completion deadlines and responsible institutions. Priority measures (2023–2025) include modernizing e‑government platforms, launching awareness campaigns on cyber hygiene, establishing registries for radioelectronic means and spectrum assignments, and improving access control for personal data services. Medium-term measures (2025–2027) focus on industry capacity, national R&D and standardization, and completion of automated spectrum monitoring systems. Long-term measures (2027–2029) consolidate gains and aim for full delivery of the Concept’s headline targets. Funding sources are a mix of state budget allocations, state-owned enterprise investments, public–private partnerships and potential international financing. Project management tools include designated project teams within the ministry, periodic progress dashboards and mandatory reporting under Government Resolution No. 269. The plan explicitly mandates integration with sectoral programs and requires implementing bodies to adapt legislation where necessary to achieve the Concept’s objectives (adilet.zan.kz).
Monitoring and Evaluation
The Concept establishes a monitoring and evaluation (M&E) regime aligned with Kazakhstan’s State Planning System. Implementing entities must submit scheduled progress reports and performance data to the coordinating ministry, which compiles consolidated reports for the Government. The action plan specifies target indicators, responsible agencies and reporting cadence for each measure. Monitoring includes quantitative metrics (service delivery times, percentage of systems connected to access-control services, spectrum use violations) and qualitative assessments (user satisfaction, readiness of human capital). M&E arrangements envisage mid-term reviews, independent evaluations for major infrastructure investments, and corrective action procedures when targets are missed. Publication of consolidated progress reports is expected through official government portals to maintain transparency and enable stakeholder oversight. Relevant data reporting and performance dashboards are managed by state IT operators in coordination with the Ministry (gov.kz).
Penalties, Liability, and Appeals
The Concept itself is a strategic planning instrument and does not prescribe criminal penalties; enforcement of obligations arising from its measures uses existing administrative, civil and sectoral legal frameworks. Implementing agencies are accountable under administrative law for failure to report or to implement assigned tasks; operators of critical information infrastructure may face administrative liability or operational sanctions under sectoral regulations for non‑compliance with information security requirements. Liability and appeals procedures follow general administrative law, sectoral statutes (for communications, data protection and state service provision) and internal rules of state operators. The Concept calls for harmonization of legal acts and improving enforcement mechanisms where gaps are identified, including clarifying responsibilities for service disruption, security breaches and unauthorized use of spectrum. Ministries are required to propose legislative changes in a timely manner to enable effective enforcement of Concept measures (adilet.zan.kz).
Relationship to Other Instruments
The Concept supersedes earlier sectoral ICT strategy instruments (for example, prior ICT industry concepts referenced in Government planning) and is designed to be implemented in coordination with the National Plan for 2025 and other cross-sectoral development strategies. It explicitly aligns with Kazakhstan’s State Planning System and references the relevant Government methodology for attaching reforms to sectoral action plans. Where specific regulatory or statutory updates are required, the Concept instructs responsible ministries to propose changes and submit them through standard legal drafting and approval channels. The action plan cross-references other official documents, such as the Concept for AI development (where applicable), investment policy initiatives and sectoral development plans, ensuring coherence across public policy instruments (adilet.zan.kz).
International Alignment
The Concept emphasises international cooperation and alignment with global practices in cybersecurity, data protection and spectrum management. It contemplates participation in international agreements and notes the importance of aligning national regulations with internationally recognised standards to facilitate cross‑border data exchange and interoperability. The text references interactions with multilateral organisations and invites coordination with foreign partners for technology transfer, standardization and joint capacity building. One specific international consideration mentioned in related commentary is Kazakhstan’s dialogue with the Council of Europe concerning conventions on data protection and automated data processing; implementation steps are to be coordinated with the Ministry of Foreign Affairs and relevant agencies. The Concept therefore frames many measures with an outward-facing orientation intended to improve regulatory compatibility and attract foreign investment in ICT industries (gov.kz).
Implementation Timeline
| Period | Key Milestones | Responsible Bodies |
|---|---|---|
| 2023 (immediate) | Approval (Resolution No. 269); launch priority projects: e‑government modernisation; cyber hygiene campaigns; initial spectrum registry work. | Government; Ministry of Digital Development, Innovations and Aerospace Industry; KNB; JSC "NIT". |
| 2023–2025 | Rollout of access-control services for personal data; e‑service speed targets (25% 5‑min in 2023 → 60% in 2025); first stage cyber protection improvements. | Implementing ministries; state ICT operators; local authorities. |
| 2025–2027 | Industry support measures, R&D acceleration, expanded training programmes, automated spectrum monitoring system deployment. | Ministry; state corporations; Astana Hub; education institutions. |
| 2027–2029 | Consolidation and achievement of headline targets (connectivity, service delivery, protection levels); independent evaluations and final reporting. | All implementing bodies; Government monitoring units. |
Compliance Checklist
| Requirement | Who Must Comply | Evidence / Documentation |
|---|---|---|
| Integrate assigned reforms into ministry action plans | All central and local executive bodies | Updated sectoral action plans; progress reports |
| Implement cybersecurity baseline for e‑government informatization objects | State ICT operators; KNB; AО "НИТ" | Security assessment reports; certification records |
| Connect government systems to access-control service for personal data | Owners of state information systems | Connectivity logs; audit confirmations |
| Conduct public awareness and training campaigns | Ministry; KNB; education institutions | Training schedules; attendance; survey results |
| Deploy radioelectronic registries and automated spectrum monitoring | KNB; Ministry; spectrum authorities | Registry database; monitoring system reports |
Sources and References
Kazakhstan's new Concept of Digital Transformation, ICT Industry Development and Cybersecurity for 2023–2029 is a national strategy that sets out a roadmap for the country's digital future, impacting government bodies, state-owned enterprises, and private entities involved in critical information infrastructure. Approved on March 28, 2023, this policy framework aims to accelerate digitalization, boost the information and communication technology (ICT) sector, and enhance national cybersecurity over the next six years.
The Concept primarily applies to all central and local government bodies, state corporations, and state ICT operators like JSC "National Information Technologies." It also extends to "operators of critical information infrastructure," which can include private companies managing essential services. These entities must integrate the Concept's reforms into their own action plans and report on progress.
Key obligations include: - Modernizing and migrating public services to e-government platforms, with targets for faster service delivery. - Implementing robust cybersecurity measures for government information systems and critical infrastructure. - Establishing unified data governance practices, including access control for personal data. - Developing the domestic ICT market and fostering innovation.
While the Concept itself doesn't impose new criminal penalties, non-compliance by implementing agencies can lead to administrative accountability under existing laws. Operators of critical information infrastructure could face administrative liability or operational sanctions for failing to meet information security requirements. The strategy took effect on March 28, 2023, with priority measures running until 2025 and the overall plan concluding in 2029.
A practical pitfall is that while this is a high-level strategy, it explicitly mandates ministries to propose necessary legislative changes. This means businesses, especially those designated as critical information infrastructure operators, should anticipate new, specific regulations and enforcement mechanisms to emerge in the coming years, potentially creating direct compliance burdens beyond current administrative accountability.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 5 marked completePlain-English obligations under Kazakhstan - Digital Transformation Strategy (Resolution No. 269). Not legal advice — verify against the official text before relying on it.
- #1CriticalKey Focus Areas (E) Cybersecurity⏰ Dec 31, 2025
Applies to: State ICT operators, Committee for National Security, JSC "National Information Technologies".
“protective measures for e‑government objects”
- #2CriticalKey Focus Areas (B) Data governance⏰ Dec 31, 2025
Applies to: Owners of state information systems.
“Rollout of access-control services for personal data”
- #3CriticalGovernance and Institutional Framework⏰ Mar 28, 2023
Applies to: All central and local executive bodies.
“ministries must adopt and integrate items into their sectoral action plans”
- #4CriticalMonitoring and Evaluation
Applies to: All implementing entities.
“Implementing entities must submit scheduled progress reports and performance data to the coordinating ministry”
- #5ImportantPenalties, Liability, and Appeals
Applies to: Responsible ministries.
“Ministries are required to propose legislative changes in a timely manner to enable effective enforcement of Concept measures”
Related Regulations
Concept for the Development of Artificial Intelligence for 2024–2029 (Концепция развития искусственного интеллекта на 2024–2029 годы)
Kazakhstan91% similar
Цифровой кодекс Республики Казахстан
Kazakhstan89% similar
Закон Республики Казахстан от 24 ноября 2015 года № 418-V «Об информатизации»
Kazakhstan88% similar
Kazakhstan AI Regulation Overview
Kazakhstan87% similar
Digital Strategy of South Korea (national digital transformation strategy)
South Korea87% similar
© Regulations.AI — created on 13-Jun-2026