South Africa is behind its neighbours on the plumbing of digital IDs

South Africa is behind its neighbours on the plumbing of digital IDs


Zambia switched on the cryptographic foundations of its digital state this week, the second country in the region to do so inside a fortnight, after Namibia.

The Zambia Information and Communications Technology Authority (Zicta) and Altron Security, the identity business inside the JSE-listed Altron group, announced the completion of a production key ceremony in Lusaka giving the country its own “national root of trust”. Namibia got there eight days earlier and has gone a step further.

South Africa has the policy, the draft regulations and a presidential promise but nothing is deployed commercially yet.

Public key infrastructure (PKI) is the machinery that issues and verifies digital certificates, closer to a passport office for the internet than to software. Encrypting data is easy; proving who sits at the other end is hard. Without one, a government cannot issue a digital identity anyone else can verify.

The keys were generated inside a purpose-built secure facility, a joint statement from Altron and Zicta said, overseen by a notary and independently audited, with key material held offline and split between custodians so no one person holds the root keys.

Zicta is now the country’s national root certification authority. Board chair Mundia Muya told the launch the national digital trust anchor had been operationalised through that role, giving other institutions a foundation for their own certificate services. Certificates gain legal footing through Zambia’s Electronic Communications and Transactions Act, which expressly regulates the national PKI.

Namibia got there first

Altron Security said it won the work through a public tender three years ago and has since built the root and issuing certification authorities and governance and security processes.

Not everyone in Lusaka was celebrating the build. Smart Zambia Institute national coordinator Percy Chinyama warned that institutions can become dependent on suppliers, partly because they lack the staff to run what they buy. “Launching the NPKI is only the beginning,” he said. “Its value will depend on whether government can sustain the infrastructure, develop the necessary skills, provide adequate resources and ensure that public institutions are prepared to adopt and use the technology effectively.”

Namibia’s Communications Regulatory Authority (Cran) held its key signing ceremony on 28 August and launched its national PKI in Windhoek on 31 August, branded DigiNam. Cran is the country’s root certification authority, with statutory backing from the country’s Electronic Transactions Act, whose electronic signature provisions took effect on 15 June.

Cran accredited the ministry of home affairs as the country’s first certification service provider, licensed for four years to issue and manage the digital certificates that verify people using government services.

Altron Security MD Andrew Whittaker
Altron Security MD Andrew Whittaker

Home affairs, on paper, wants something very much like what Cran and Zicta have built.

Its annual performance plan, signed off by minister Leon Schreiber and reported by TechCentral in April, describes the digital identity system as comprising a PKI, a certificate authority, an identity platform, verifiable credentials and biometric-secured wallets. It targets completion of the hosting infrastructure, inside the Sars environment, by 31 March 2027, and roll-out in 2027/2028.

Draft amendments to the Identification Regulations, gazetted on 4 May, set out a smartphone-based digital identity called MyMzansi. Comment closed on 6 June, but no commencement date is fixed and the National Identification and Registration Bill is only due in parliament in 2027/2028.

South Africa has a trust layer, but a differently owned one. Under the Electronic Communications and Transactions Act of 2002, the South African Accreditation Authority accredits providers whose signatures qualify as advanced electronic signatures, and three hold it: Altron Security, TrustFactory and Impression Signatures. Zambia and Namibia hold state root keys; South Africa delegates the job to commercial operators and audits them.

Delegation is a defensible model, and a common one. In the EU, qualified trust service providers are private companies, supervised and listed by member states rather than run by them. The difficulty is that home affairs’ own plan now lists a certificate authority among the things it intends to build, without saying who would hold the keys.

Repeat business

Andrew Whittaker, MD of Altron Security, told TechCentral the more difficult test comes later.

“What we did for Zambia is technical, but it is also about compliance,” he said. “After 12 months, the system needs to pass an international WebTrust audit. So, it’s not just about how you build it, but how you run it.”

WebTrust for Certification Authorities, run by Chartered Professional Accountants of Canada, is one of two regimes, with Europe’s ETSI standards, that check whether an authority runs the way its policies say it does.

Zambia is not a one-off for Altron Security. “We definitely see this as a repeat business, and we are currently looking at the African market for opportunities to build sovereign trust systems,” he said.

Altron is not the only qualified player. Germany’s Veridos ran Nigeria’s root certification authority ceremony in June 2021, and trade title Biometric Update reported that Veridos had signed an implementation agreement with the Namibian government through Cran, an arrangement neither party has formally disclosed.

digital ID

Asked whether Altron would bid to build home affairs’ certificate authority, Whittaker declined to discuss South African specifics, then added: “I’m not aware that DHA is currently looking for a system like that, but over time there will be real value for sovereign African nations to have their own national trust infrastructures.”  — (c) 2026 NewsCentral Media