On Approval of the Rules for passing a national or International Technical Audit by Data Processing Centers and requirements for data processing centers used to host digital Objects Containing government digital data, Restricted Access data, or Critical digital Objects
Order of the Deputy Prime Minister - Minister of Artificial Intelligence and Digital Development of the Republic of Kazakhstan dated June 18, 2026 No. 327/NK. Registered with the Ministry of Justice of the Republic of Kazakhstan on June 19, 2026 No. 38997
In accordance with paragraphs 2 and 4 of Article 27 of the Digital Code of the Republic of Kazakhstan, I ORDER:
1. Approve the attached documents:
1) Rules for passing a national or international technical audit by data processing centers;
2) Requirements for data processing centers used to host digital objects containing government digital data, restricted access data, or mission-critical digital objects.
2. To invalidate the Order of the Minister of Digital Development, Innovation and Aerospace Industry of the Republic of Kazakhstan dated September 30, 2024 No. 613/NK "On Approval of the Rules for Organizing the operation of a data Processing center and conducting an international or national technical Audit" (registered in the Register of State Registration of Regulatory Legal Acts No. 35169).
3. The Telecommunications Committee of the Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan, in accordance with the procedure established by the legislation of the Republic of Kazakhstan, shall ensure:
1) the state registration of this order in the Ministry of Justice of the Republic of Kazakhstan;
2) posting of this order on the Internet resource of the Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan after its official publication.
3) within ten working days after the state registration of this order with the Ministry of Justice of the Republic of Kazakhstan, submit to the Legal Department of the Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan information on the implementation of measures provided for in subparagraphs 1) and 2) of this paragraph.
4. Control over the execution of this order is entrusted to the supervising Vice Minister of Artificial Intelligence and Digital Development of the Republic of Kazakhstan.
5. This order will enter into force on July 12, 2026 and is subject to official publication.
Deputy Prime Minister – Minister of Artificial Intelligence and Digital Development of the Republic of Kazakhstan
J. Madiev
The National Security Committee of the Republic of Kazakhstan HAS BEEN "APPROVED"
Approved by the Order of the Deputy Prime Minister- Minister of Artificial Intelligence and Digital Development of the Republic of Kazakhstan on June 18, 2026 No. 327/NK
Rules for passing a national or international technical audit by data processing centers
Chapter 1. General provisions
1. These Rules for passing a national or international technical audit by data processing centers (hereinafter referred to as the Rules) have been developed in accordance with paragraph 2 of Article 27 of the Digital Code of the Republic of Kazakhstan (hereinafter referred to as the Code) and define the passage of a national or international technical audit by data processing centers.
2. The national technical audit of the data processing center is conducted in order to assess the level of reliability, fault tolerance, security and readiness of the data processing center infrastructure to ensure the uninterrupted operation of digital facilities and digital systems, including critical digital facilities.
The national technical audit of the data center is aimed at confirming the compliance of the data center infrastructure with the requirements for engineering, energy, telecommunications and technological stability, including the availability of backup systems, uninterrupted power supply, cooling, physical security and cybersecurity.
Conducting a national technical audit of the data processing center ensures:
1) determining the reliability level of the data center;
2) assessment of the data processing center's ability to ensure the continuity of the hosted digital systems;
3) identification of infrastructural and technical inconsistencies affecting the sustainability of the data center.
3. The following basic concepts and definitions are used in these Rules:
1) critically important digital objects (hereinafter referred to as CSCs) – digital objects, the disruption or termination of which leads to the illegal collection and processing of personal data with limited access and other information containing legally protected secrets, a social and (or) man-made emergency, or significant negative consequences for defense, security, international relations, the economy, certain areas of the economy, or for the livelihoods of the population living in in the relevant territory, including infrastructure: heat supply, electricity, gas supply, water supply, industry, healthcare, communications, banking, transport, hydraulic structures, law enforcement, "digital government";
2) the authorized body in the field of communications (hereinafter referred to as the authorized body) is the central executive body determined by the Government of the Republic of Kazakhstan, which implements state policy in the field of communications, state control, coordination and regulation of the activities of persons providing or using communications services;
3) a data processing center (hereinafter referred to as a data center) is a digital infrastructure facility designed to accommodate and provide an environment for the operation of other digital facilities through technological, engineering, technical means and software;
4) the owner of the data processing center is a legal entity registered in the territory of the Republic of Kazakhstan or an individual who receives temporary possession and use of the data processing center.;
5) the owner of the data processing center is a legal entity registered in the territory of the Republic of Kazakhstan or an individual who owns the data processing center.;
6) Classification of data center reliability levels (hereinafter referred to as data center level classification) is a standardized ranking system used to classify a data center based on its downtime, uptime, and reliability;
7) national technical audit of the data processing center – a voluntary assessment of the reliability of the data processing center;
8) the cybersecurity Center (hereinafter referred to as the CSCC) is a legal entity or a structural subdivision of a legal entity that is a resident of the Republic of Kazakhstan without the participation of foreign legal entities and individuals engaged in the protection of digital objects.;
9) international company — a legal entity engaged in international technical audit and assessment of data center infrastructure, including assessment of compliance with international standards;
10) international technical audit — a voluntary assessment of the reliability of a data center for compliance with international standards and regulations;
11) digital data — information provided in digital form and suitable for automated and (or) analytical collection, storage, processing, use, transmission, distribution or deletion, regardless of the method of its receipt and the form of digital provision;
12) digital systems — a functionally connected complex of digital resources that uses digital infrastructure facilities to ensure the creation, collection, processing, storage and dissemination of digital data, as well as automating the interaction of subjects of the digital environment and (or) providing services in the digital environment;
13) a digital object is a separate element of the digital environment created, used or transmitted through digital technologies, possessing unique digital characteristics and allowing subjects of the digital environment to exercise ownership, use or disposal powers to the extent established by the legislation of the Republic of Kazakhstan.;
14) digital environment — a set of infrastructure, technologies, processes and conditions for the creation, circulation, storage, transfer and use of digital data and digital objects, the exercise and transfer of rights to them, regardless of the territory of their location or registration of rights in the part affecting the public relations regulated by the Code.
Chapter 2. Procedure for passing the national technical audit by data processing centers
4. After the data center is put into operation, the owner or the owner of the data center conducts a national technical audit of the data center.
5. To conduct a national technical audit of a data center, the owner or owner of the data center sends to the Central Bank an application for conducting a national technical audit of the data center in accordance with Annex 1 to these Rules via the Central Bank's Internet resource (if available), e-mail or postal communication with the following documents attached:
1) information about the location of the data center;
2) information about the engineering, energy, telecommunications and technological infrastructure that ensures its uninterrupted, fault-tolerant and safe operation;
3) information about the power supply, cooling, communication and redundancy system.
6. Within 5 (five) business days from the date of receipt of the documents, the CSCB carries out their preliminary review for completeness and reliability.
7. If the incompleteness of the submitted documents or the unreliability of the information contained therein is revealed, the CSCB sends an official letter to the owner or owner of the data center notifying them of the need to eliminate the identified comments and (or) provide the missing documents via the CSCB Internet resource (if any), e-mail or postal communication.
Missing documents and information are submitted within 10 (ten) business days from the date of receipt of the letter notifying of the need to eliminate the identified comments and (or) provide the missing documents.
If the documents are not submitted within the prescribed period, the application remains without consideration.
8. The duration of the national technical audit of the data center is no more than 10 (ten) business days from the date of acceptance of the full package of documents for consideration.
9. Based on the results of the national technical audit of the data center, the CSCB issues a conclusion on the classification of the data center by level in accordance with the form in accordance with Annex 2 to these Rules.
10. Following the results of the national technical audit of the data center, the CSCB sends an official letter to the authorized body with information on the results of the national technical audit of the data center.:
1) Data center information;
2) assigned reliability level;
3) identified inconsistencies (if any);
4) the date of the national technical audit of the data center.
The information is sent within 3 (three) business days from the date of issuing the conclusion on the classification of the data center by level.
11. The owner or owner of the data center posts information on the results of the national technical audit of the data center on his Internet resource within 5 (five) business days.
12. The published information on the results of the national technical audit of the data center includes:
1) the fact of passing or not passing the national technical audit of the data center;
2) the reliability level of the data center (if any);
3) the date of the national technical audit of the data center.
13. A repeated application for a national technical audit of the data center is sent to the CSCB in accordance with Annex 1 to these Rules by the owner or owner of the data center within 15 (fifteen) calendar days after the completion of the modernization of the data center infrastructure or the elimination of previously identified inconsistencies.
Chapter 3. The procedure for passing an international technical audit by data processing centers
14. After the data center is put into operation, an international technical audit of the data center is conducted on a voluntary basis.
15. The owner or owner of the data center enters into an agreement with an international company to conduct an international technical audit of the data center.
16. An international technical audit is conducted on the basis of technical documentation, information about engineering and telecommunications infrastructure, backup systems, power supply, cooling, physical security and cybersecurity of data centers.
17. The owner or owner of the data center provides an international company with access to the information and documentation necessary for conducting an international technical audit of the data center.
18. Based on the results of the international technical audit of the data center, an international company issues a conclusion on the classification of the data center by level.
19. The owner or owner of the data center posts on his Internet resource information about the passage or non-passage of the international technical audit of the data center within 5 (five) business days from the date of receipt of the conclusion on the classification of the data center by level.
20. In case of modernization of the data center infrastructure, changes in the reliability level, or elimination of previously identified inconsistencies, a second international technical audit of the data center is conducted on the initiative of the owner or owner of the data center within 15 (fifteen) calendar days.
21. The published information on the results of the international technical audit of the data center includes:
1) the fact of passing or not passing the international technical audit of the data center;
2) the reliability level of the data center (if any);
3) the date of the international technical audit of the data center.
Appendix 1 to the Rules for passing a national technical audit or international data processing centers
Form
Application for the national technical audit of the data processing center
1. Name of the owner or owner of the data processing center:___________________________________________________________________
2. Business identification number/Individual identification number:___________________________________________________________________
3. Legal address: _______________________________________________
4. Contact information (phone, e-mail):___________________________________________________________________
5. Name and location of the data processing center:___________________________________________________________________
6. Brief information about the data center infrastructure:___________________________________________________________________
7. List of attached documents:
1) ________________________________________________________________;
2) ________________________________________________________________;
3) ________________________________________________________________.
I confirm the accuracy of the submitted information and documents.Responsible person:___________________________________________________________________(Last name, first name, patronymic (if any), signature)Date: "__" __________ ___ year
Appendix 2 to the Rules for passing a national technical audit or international data processing centers
Form
Conclusion on the classification of the data processing center by level
Information about the data center:
1. Form of ownership:___________________________________________________________________
2. Year of creation:___________________________________________________________________
3. Address:___________________________________________________________________(postal code, region, district, street, house number, phone number)
4. Contact details of the owner or owner of the data processing center:___________________________________________________________________(Last name, first name, patronymic (if any), business phone number, email address)
5. Checking account:___________________________________________________________________(account number, name and location of the bank)
6. Bank details _____________________________________________
7. Business identification number/individual identification number of the owner or owner of the data processing center:___________________________________________________________________
8. Type of activity:___________________________________________________________________(license number and series, in case of licensing activity)
Classification by level (Tier):
Level: (mark appropriate)
1) Level I (Tier I)
2) Level II (Tier II)
3) Level III (Tier III)
4) Level IV (Tier IV)
Brief description of the level:___________________________________________________________________Evaluation of infrastructure components:___________________________________________________________________Level compliance:___________________________________________________________________Description of the tests and tests performed: ____________________________Recommendations: ________________________________________________________________________________________________________________________The conclusion on the classification of the data center by level:___________________________________________________________________Signatures of responsible persons:___________________________________________________________________(Last name, first name, patronymic (if any))
Approved by the Order of the Deputy Prime Minister- Minister of Artificial Intelligence and Digital Development of the Republic of Kazakhstan on June 18, 2026 No. 327/NK
Requirements for data processing centers used to host digital objects containing government digital data, restricted access data, or mission-critical digital objects
1. Data processing centers (hereinafter referred to as data centers) used to host digital objects containing government digital data, restricted access data, or critical digital objects (hereinafter referred to as data centers) are located on the territory of the Republic of Kazakhstan.
2. The posting of data containing government digital data, restricted access data, or CSCs outside the Republic of Kazakhstan is permitted in cases and in accordance with the procedure provided for by the laws of the Republic of Kazakhstan or international treaties ratified by the Republic of Kazakhstan.
3. The placement of digital objects, government digital data, or restricted access data is allowed in data centers that have proven their reliability by passing a national or international technical audit of the data center.
Information on the results of the national or international technical audit of the data center is sent by the owner or owner of the data center to the authorized body within 5 (five) business days from the date of receipt of the conclusion on the classification of the data center by level.
4. Data centers provide round-the-clock operation of engineering and technological infrastructure, redundancy of critical digital systems, control of physical and logical access, automatic switching to backup power sources, autonomous operation for at least 72 (seventy-two) hours, operation of uninterruptible power supply systems, maintenance of temperature conditions in the range from +18°C to +27°C and relative humidity in the range of 40 to 60 percent, the use of redundant air conditioning and cooling systems, availability of automatic fire early detection systems, gas fire extinguishing systems and backup smoke extraction systems, as well as information security systems and at least two independent power inputs.
5. Data centers are located in detached buildings and (or) structures or a specially equipped part of the building, protected from natural disasters (earthquakes, floods and other dangerous natural phenomena), with proper waterproofing and ventilation to maintain optimal working conditions for computing and telecommunications equipment, the presence of a fire safety system that includes automatic fire detection and extinguishing, the availability of an access control system and video surveillance to ensure physical security.
6. Data centers are equipped with precision systems to maintain optimal temperature and humidity.
7. Backup cooling systems are provided to prevent overheating of computing and telecommunication equipment in the event of a failure of the main system.
8. Control and management of access to the premises of the data center is carried out using digital identification systems, registration and monitoring of the actions of users and maintenance personnel.
9. The owner or owner of the data center:
1) Provides continuous monitoring of security events;
2) Has and maintains an up-to-date cybersecurity incident response plan.
10. Data centers are classified by levels and divided into:
1) Tier I - 99.671% or 1,729 (one thousand seven hundred and twenty-nine) minutes of downtime per year.
A Tier I data center is the basic capacity level of an infrastructure to support digital technologies.
Level I (Tier I) includes:
(redundancy scheme N*) equipment failures or repair work lead to the shutdown of the data center. There are no raised floors, backup power supplies, or uninterruptible power supplies in the data center. The engineering infrastructure is not reserved;
2) Tier II – 99.741% or 1,361 (one thousand three hundred and sixty-one) minutes of downtime per year.
The Tier II data center provides power and cooling, ensuring higher quality of service and safety in case of failures.
Level II (Tier II) includes:
(redundancy scheme – N + 1) minimum redundancy level, the data center must have raised floors and backup power and cooling sources, however, repairs also cause the data center to shut down;
3) Tier III – 99.982% or 95 (ninety-five) minutes of downtime per year.
Tier III is a level of reliability characterized by the ability to perform maintenance on components of engineering systems without stopping the operation of the data center (parallel maintenance). A redundancy scheme of at least N + 1 is used for active equipment, and at least 2N for distribution flows (power supply and cooling paths). It is allowed to carry out any routine maintenance and repair work, including replacing system components, adding or removing equipment, without interrupting the operation of the data center.;
4) Tier IV - 99.995% or 26 (twenty-six) minutes of downtime per year.
Data center of tier IV (redundancy scheme – 2×(N + 1)) – it is possible to carry out any work without stopping the operation of the data center, engineering systems are twice reserved, both the main and additional systems are duplicated.
Note:
* Necessity (from the English word need) is the necessary number of pieces of equipment and systems, without which the data center will not be able to function normally.
Constitution Law Code Standard Decree Order Decision Resolution Lawyer Almaty Lawyer Legal service Legal advice Civil Criminal Administrative cases Disputes Defense Arbitration Law Company Kazakhstan Law Firm Court Cases Declaration Decree Order Resolution Decision Report Conclusion Statement Conclusion Convention Contract Memorandum Methodology Norms Note Rules Program Charter Charter Article Commentary Resolution Regulations Protocol Draft Program Rules Messages