Ministry of Information, Communications and Technology (MoICT)

Kenya · owned by Government of Kenya (Kenya) · moict.go.ke · 9 vendors

The Ministry of Information, Communications and Technology (MoICT) is a Kenyan government ministry responsible for formulating and implementing national policies related to ICT, broadcasting, and digital innovation. It oversees the development of Kenya's digital economy, e-government services, and the regulation of the ICT sector. The ministry also coordinates initiatives such as the National Broadband Strategy and digital literacy programmes.

Resilience scores

Technology vendors

Insights

Last updated 2026-08-03 · revision 3

9 direct vendors, 132 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

MoICT exhibits a medium level of migration readiness. A key strength is the existing adoption of cloud services, including Microsoft Azure (Government Tenant) and Microsoft 365, which indicates familiarity and capability with cloud environments. The strategic intent for digital transformation is clear through initiatives like the Government Cloud (G-Cloud Kenya) and the Kenya National Digital Master Plan, suggesting a roadmap for future cloud adoption and interoperability. The policy focus on modern technologies such as AI, IoT, and Blockchain also aligns with cloud-native architectures and future-proofed services. However, significant challenges exist. The internal tech stack reveals a hybrid environment with substantial reliance on traditional government data center infrastructure and core enterprise systems (eCitizen Platform, IFMIS, GHRIS, Oracle ERP). Migrating these complex, often highly integrated, and customized legacy systems typically requires extensive refactoring or re-platforming, which is time-consuming and costly. There is a high potential for vendor lock-in due to the deep integration with major ecosystems like Microsoft (Azure, M365, SharePoint) and Oracle (ERP), making transitions to alternative platforms challenging. The vendor data is inconsistent, stating "Total Vendors: 0" but then providing details on vendor HQ countries (United States, China) and geographic diversity (2 unique countries). This ambiguity complicates a precise assessment of vendor lock-in risk, though the implied vendors suggest a concentration. Crucially, there are critical data gaps regarding the specific regulatory environment, explicit data residency requirements, and financial stability (ability to fund a large-scale migration). As a government entity, strict data residency within Kenya is highly probable, which could limit migration options to global cloud providers or necessitate specific sovereign cloud solutions, adding complexity and cost.

Compliance

4 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

As an ICT policy ministry, MoICT may utilize cloud services or provide digital services that could benefit from SOC2 compliance. However, SOC2 is typically voluntary for government entities, reducing immediate compliance risk while maintaining operational importance.

Kenya Information and Communications Act — Assessment Required

As the national ICT policy ministry, MoICT must comply with Kenya's Information and Communications Act. This is fundamental legislation governing their core mandate. Non-compliance could undermine their regulatory authority and lead to legal challenges.

Kenya Data Protection Act 2019 — Assessment Required

As a Kenyan government entity, MoICT must comply with Kenya's Data Protection Act 2019. Non-compliance could result in significant penalties, legal action, and reputational damage. Government entities are expected to lead by example in data protection compliance.

Financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report