Uganda’s gaming regulator secures ISO/IEC 27001:2022 certification

Uganda’s gaming regulator secures ISO/IEC 27001:2022 certification

The certificate covers the board’s head office operations in Kampala, including its personnel, supporting systems and information assets.

Uganda.- The National Lotteries and Gaming Regulatory Board (NLGRB) has achieved ISO/IEC 27001:2022 certification, a development the regulator says confirms its compliance with the international standard for information security management systems.

The Ugandan gaming regulator announced the certification on July 20, describing it as a milestone in its efforts to strengthen information security, governance and the protection of sensitive information.

The certificate, issued by Certi-Trust, confirms that the NLGRB’s information security management system complies with ISO/IEC 27001:2022. It covers the board’s head office operations in Kampala, including its personnel, supporting systems and information assets, in accordance with its Statement of Applicability Version 4.0 dated May 15, 2026.

The certification cycle began on June 9, 2026, and remains valid until June 8, 2029, subject to annual surveillance audits.

According to the NLGRB, the certification supports its efforts to strengthen information security, apply risk-based controls, maintain regulatory compliance and ensure business continuity across its operations.

ISO/IEC 27001:2022 is the latest version of the globally recognised standard for establishing, implementing, maintaining and continually improving an information security management system. It provides organisations with a structured framework for managing information security risks and protecting sensitive information.

As the latest international standard for information security management systems, ISO/IEC 27001:2022 provides a framework for organisations to identify, assess and manage information security risks while protecting the confidentiality, integrity and availability of information.

For the gambling sector, the certification reinforces the regulator’s ability to securely manage licensing records, operator submissions, compliance data and other sensitive information used in its oversight functions. It also aligns the board’s information security practices with internationally recognised requirements for managing information security risks and safeguarding sensitive data.

In this article:
ISO/IEC 27001:2022