For years, an internet outage in Kenya has mostly meant an apology, maybe a follow-up call, and nothing else. That's changing. The Kenya Information and Communications (Consumer Protection) Regulations, 2026 — developed by the Cabinet Secretary for Information, Communications and the Digital Economy together with the Communications Authority of Kenya (CA) — now legally require licensed operators, ISPs included, to compensate subscribers when service goes down because of the provider's own failure. This isn't a guideline or a best-practice suggestion. It's a compliance obligation with a clock already running.

What the regulations actually require

The core of the new rules is what's being called an outage-credit system: ISPs must stand up either an automatic or a claim-based mechanism that compensates subscribers for downtime caused by the provider. Crucially, that system can't just be invented internally — it has to be submitted to the Communications Authority for approval before it's used, and once approved it becomes a standard part of subscriber agreements. Outages caused by force majeure or circumstances genuinely outside the operator's control are exempt.

Alongside the outage-credit requirement, the regulations tighten complaint handling: every consumer complaint must be acknowledged and issued a unique reference number, tracked, and resolved free of charge — with unresolved cases escalating to the CA if a provider doesn't sort them out. Billing also comes under scrutiny, with a requirement that invoices clearly show billing periods, itemised charges, applicable rates, totals and payment deadlines, and that tariff changes come with advance notice rather than surprise charges.

The compliance window is short

Licensees have three months from the regulations taking effect to come into compliance, with extensions possible only for good cause. Given that the rules were already being reported on by July 2026, that window is closing fast for operators who haven't started. Non-compliance isn't a soft risk either — violations can carry fines of up to KES 1 million and, in some cases, up to six months' imprisonment. Separately, the CA has also signalled it's raising the bar on network quality itself, moving the minimum acceptable service-performance score from 80% to 90%, with quarterly penalties for operators who fall short.

Why this is a billing-system problem, not just a policy one

The hard part of these regulations isn't the policy — it's the plumbing. To run an outage-credit system that the CA will actually approve, an ISP needs to be able to answer, per subscriber, exactly when their connection went down, how long it stayed down, and why. That means downtime has to be tied to real session data, not estimates from a support ticket. It also means credits need to flow automatically into the next invoice rather than being manually calculated by a support agent trying to reconstruct what happened from memory.

The complaint-tracking requirement adds another layer: every complaint needs a reference number and a resolution trail that can be produced on demand, which is difficult to sustain with a spreadsheet or a shared inbox once a subscriber base grows past a few hundred accounts. And the billing-clarity requirement — itemised charges, clear billing periods, advance notice on tariff changes — is exactly the kind of thing that's trivial in a purpose-built billing platform and painful to bolt onto an ad hoc one.

Where this leaves smaller and mid-sized ISPs

Large operators have compliance and legal teams to build this kind of system from scratch. Smaller and regional ISPs generally don't — which makes the underlying billing and network-management platform the thing that determines whether this regulation is a manageable software update or a genuine operational headache. Real-time RADIUS visibility into session start/stop times gives an ISP the actual data an outage-credit system needs; automated, itemised M-Pesa and Kopo Kopo-linked billing gives it a place to apply the credit without a manual step; and structured client and ticket records give it the audit trail the complaint-handling rules ask for. That's the exact combination XpressRADIUS was built around for Kenyan ISPs — not because of this regulation specifically, but because accurate session data and clean, automated billing were always going to matter once outages stopped being just a support problem and started being a compliance one.

If you're an ISP operator in Kenya sizing up what these regulations mean for your next three months, the practical starting point is the same either way: know exactly what your platform can already tell you about downtime and billing, and figure out the gap from there.

See how XpressRADIUS pairs real-time RADIUS session data with automated, itemised billing for Kenyan ISPs.

Start a free trial
← Back to all posts