The Agency for Regulation and Development of the Financial Market of the Republic of Kazakhstan outlined minimum information security requirements that have applied to all financial market participants since July 12, 2026. Banks face stricter requirements covering cyber risk management, incident response capabilities, information systems continuity, regular security audits and penetration testing. Compliance is monitored through regulatory reporting, off-site supervision and risk-based inspections, with supervisory measures used to address violations and improve information security. The agency also advised consumers to protect account credentials, use secure access controls and verify urgent requests for transfers, confirmation codes, application installations or device access through official channels.
Agency for Regulation and Development of the Financial Market of the Republic of Kazakhstan2026-08-13
Agency for Regulation and Development of the Financial Market of the Republic of Kazakhstan details mandatory cybersecurity requirements for all financial market participants
Kazakhstan’s financial regulator detailed mandatory minimum information security requirements applying to all financial market participants since July 12, 2026, with stricter controls for banks. Compliance is monitored through reporting and supervisory reviews, while consumers are urged to verify suspicious requests through official channels.