Operating Cyber Security Company in Nepal March 17, 2026 - BY Admin

Operating Cyber Security Company in Nepal

Operating cyber security company in Nepal requires compliance with multiple regulatory frameworks including the Companies Act 2063, Electronic Transaction Act 2063, Draft Information Technology and Cyber Security Bill 2080 (2024), and National Cyber Security Policy 2023. The cybersecurity industry in Nepal is experiencing unprecedented growth, driven by increasing digital threats and government initiatives to strengthen national digital security. Company registration is completed at the Office of Company Registrar (OCR) with minimum capital of NPR 100,000 for domestic companies and NPR 5 million for foreign investment.

For entrepreneurs and investors seeking to establish cybersecurity firms, understanding the legal requirements, licensing procedures, and compliance obligations becomes essential. This guide examines the step-by-step registration process, regulatory framework, and operational requirements for cybersecurity companies in Nepal.

What is Cyber Security Company Registration in Nepal?

Cyber security company registration in Nepal refers to the legal process of establishing a technology-based business entity specializing in information security services, cyber defense solutions, data protection, and digital risk management. Under the Companies Act 2063, cybersecurity firms are registered as private limited companies or public limited companies depending on scale and investment structure.

The cybersecurity sector in Nepal encompasses diverse services including network security, threat intelligence, vulnerability assessment, penetration testing, security auditing, incident response, and cloud security. These services are governed by the Electronic Transaction Act 2063, Individual Privacy Act 2075, and the forthcoming Information Technology and Cyber Security Bill 2080.

Unlike general IT companies, cybersecurity firms face additional regulatory scrutiny due to their involvement with sensitive data, critical infrastructure protection, and national security considerations. The Draft Cyber Security Bill 2024 mandates specific licensing for data centers and cloud service providers, with compliance requirements extending to security audits and data localization.

Legal Framework for Cybersecurity Companies in Nepal

The cybersecurity legal framework in Nepal comprises multiple statutes and policies governing digital security operations:

Legislation/PolicyKey ProvisionsApplicability
Companies Act 2063Company incorporation, governance, shareholder rightsAll cybersecurity companies
Electronic Transaction Act 2063Digital signatures, cybercrime penalties, security standardsElectronic security services
Draft IT and Cyber Security Bill 2080 (2024)Data center licensing, CII protection, security audits, data localizationData centers, cloud providers, critical infrastructure
National Cyber Security Policy 2023Strategic framework, institutional arrangements, capacity buildingAll cybersecurity operators
Individual Privacy Act 2075Personal data protection, consent requirements, breach penaltiesData processing companies
Data Act 2079Data governance, public data management, digital transformationGovernment data contractors
Foreign Investment and Technology Transfer Act 2075FDI procedures, technology transfer, repatriationForeign-owned cybersecurity firms

Draft Information Technology and Cyber Security Bill 2080 (2024):

This landmark legislation introduces significant requirements for cybersecurity companies:

  • Mandatory licensing for data centers and cloud service providers within one year of enactment
  • Security audit requirements for critical information infrastructure and cybersecurity firms
  • Data localization mandates for government, financial, and health service providers
  • Cyber incident reporting obligations for critical infrastructure operators
  • National Cyber Security Center establishment for coordination and response

National Cyber Security Policy 2023:

The Policy establishes a Steering Committee chaired by the Minister of Communications and Information Technology, with members including the Nepal Rastra Bank Governor, Secretaries from key ministries, and FNCCI President. This high-level coordination ensures cybersecurity alignment across government and private sectors.

Step-by-Step Cybersecurity Company Registration Process

Cybersecurity company registration in Nepal follows the standard company incorporation procedure with additional technology sector considerations. The process typically requires 7 to 15 working days for domestic companies and 30 to 45 days for foreign investment cases.

Step 1: Name Reservation at OCR

Visit the Office of Company Registrar website or office to verify name availability. Submit a name reservation application with three proposed names following naming guidelines. The name should reflect technology or cybersecurity services. Pay the prescribed fee of NPR 100 per name. Obtain name reservation approval, which remains valid for 35 days.

Naming Tips:

  • Avoid generic names like "Nepal Cyber Security"
  • Include distinctive elements reflecting specialization
  • Ensure no similarity to existing registered companies

Step 2: Prepare Memorandum and Articles of Association

Draft the Memorandum of Association (MOA) defining:

  • Company objectives (cybersecurity services, consulting, auditing)
  • Authorized capital and share structure
  • Specific IT business activities (network security, penetration testing, etc.)

Prepare Articles of Association (AOA) outlining:

  • Internal management rules and director powers
  • Shareholder rights and voting procedures
  • Data protection and client confidentiality protocols
  • Incident response and breach notification procedures

Both documents must comply with Company Act 2063 requirements. For cybersecurity companies, clearly listing services in the objectives section is mandatory.

Step 3: Document Compilation and Submission

Required documents for cybersecurity company registration:

Document CategorySpecific Requirements
Identity DocumentsCitizenship certificates of all promoters and directors (notarized)
PhotographsRecent passport-size photos of promoters and directors
Office ProofRegistered office rental agreement or ownership certificate
Bank ProofBank voucher showing minimum paid-up capital deposit
Consent LettersDirector appointment acceptance letters
Share AgreementShare subscription agreement among promoters
Name ApprovalOCR name reservation approval letter
Foreign ApprovalDOIT approval for foreign investors (if applicable)

Submit the complete application package to OCR with applicable registration fees.

Step 4: OCR Examination and Certificate Issuance

The Office of Company Registrar reviews submitted documents for:

  • Legal compliance and completeness
  • MOA/AOA alignment with cybersecurity business
  • Capital adequacy verification
  • Director eligibility confirmation

Upon satisfactory verification, OCR issues the company registration certificate with a unique company registration number. This certificate legally establishes the cybersecurity company's existence.

Step 5: PAN and VAT Registration

Visit the Inland Revenue Office with the company registration certificate to apply for Permanent Account Number (PAN). Submit PAN application with required documents and obtain PAN certificate immediately.

VAT registration is mandatory if annual turnover exceeds:

  • NPR 5 million for goods
  • NPR 2 million for services

Most cybersecurity companies exceed these thresholds and must register for VAT.

Step 6: Municipal and Ward Office Registration

Register the cybersecurity company at the local municipal office where the registered office is located. Submit:

  • Business registration application
  • Company documents
  • Office ownership proof
  • Prescribed fees (NPR 500-5,000 depending on location)

Obtain municipal business operation license, which must be renewed annually.

Step 7: Special Cybersecurity Licensing (If Applicable)

Under the Draft IT and Cyber Security Bill 2080, data centers and cloud service providers must obtain specialized licenses from the Department of Information Technology within one year of the Bill's enactment. Security audit firms may require certification from relevant government security agencies.

Capital Requirements for Cybersecurity Companies

Capital requirements vary based on company type and ownership structure:

Company TypeMinimum Authorized CapitalMinimum Paid-up CapitalForeign Investment
Private Limited (Domestic)NPR 100,000NPR 25,000 (25%)Not applicable
Private Limited (Foreign Investment)NPR 5,000,000NPR 5,000,000 (100%)Minimum NPR 5 million
Public LimitedNPR 10,000,000NPR 2,500,000 (25%)Minimum NPR 50 million
IT Export-OrientedNPR 100,000NPR 25,000NPR 5 million (foreign)

Foreign Investment Notes:

  • Foreign investors must obtain prior approval from the Department of Industry (DOIT)
  • Technology transfer agreements require separate DOIT approval
  • Repatriation of profits permitted under Foreign Investment and Technology Transfer Act 2075
  • No minimum capital requirement for IT startups through automatic route (simplified procedure)

Post-Registration Compliance for Cybersecurity Companies

After completing cybersecurity company registration, ongoing compliance obligations must be fulfilled:

Compliance CategoryRequirementFrequency
Annual General MeetingShareholder meeting for financial approvalWithin 6 months of fiscal year end
Annual Return FilingSubmission to OCR with financial statementsWithin 1 month of AGM
Tax ReturnsIncome tax filingBy mid-January (Poush end)
VAT ReturnsMonthly or quarterly based on turnoverMonthly/quarterly
Social Security FundEmployee contributionsMonthly
Municipal License RenewalBusiness operation permitAnnually
Cybersecurity AuditsSecurity assessment for CII companiesAs mandated by Bill
Data Protection CompliancePrivacy Act adherenceContinuous

Critical Compliance: 3-Month Rule
Within 90 days of registration, companies must file "Share Lagat" (Shareholder Details) at OCR. Failure results in compounding fines.

Data Protection and Privacy Compliance

Cybersecurity companies must comply with Individual Privacy Act 2075 when handling personal data:

Key Compliance Requirements:

RequirementImplementation
ConsentExplicit written consent before data collection
Purpose LimitationData use limited to stated collection purpose
Security MeasuresEncryption, access controls, authentication
Data Subject RightsAccess, correction, deletion, objection rights
Breach ResponseImmediate mitigation and affected individual notification
Cross-Border TransferRestricted; government/financial/health data must stay in Nepal

Penalties for Non-Compliance:

  • Imprisonment up to 3 years
  • Fines up to NPR 30,000
  • Compensation to affected individuals
  • Reputational damage and contract termination

Critical Information Infrastructure (CII) Protection

The Draft Cyber Security Bill 2080 mandates CII identification and protection:

CII Sectors Include:

  • Government and public administration
  • Banking and financial services
  • Telecommunications
  • Energy and power
  • Transportation
  • Healthcare
  • Water supply
  • Emergency services

CII Operator Obligations:

  • Mandatory security audits by licensed cybersecurity firms
  • Incident reporting to National Cyber Security Center
  • Data localization for sensitive information
  • Business continuity and disaster recovery plans

Opportunity for Cybersecurity Companies:
CII operators must engage licensed cybersecurity firms for audits and compliance, creating significant business opportunities for registered and certified companies.

Costs and Timeline Summary

Total Registration Costs:

Cost ComponentAmount (NPR)
Name Reservation100 per name
Company Registration Fee0.1% of authorized capital (min 1,000)
Stamp Duty on MOA/AOA1,000
PAN RegistrationFree
VAT RegistrationFree
Municipal License500-5,000
Legal Documentation10,000-50,000
Notarization500-2,000
Total Estimated15,000-75,000

Timeline Summary:

Process StageDuration
Name Reservation1-2 days
Document Preparation2-3 days
OCR Verification3-5 days
Certificate Issuance1 day
PAN/VAT Registration1-2 days
Municipal Registration2-3 days
Standard Total7-15 days
Foreign Investment (with DOIT)30-45 days

Frequently Asked Questions (FAQs)

How do I register a cybersecurity company in Nepal?

Cybersecurity company registration involves: (1) Name reservation at OCR, (2) MOA/AOA preparation with cybersecurity objectives, (3) Document submission with citizenship and office proof, (4) OCR examination and certificate issuance, (5) PAN/VAT registration at Inland Revenue Office, and (6) Municipal business licensing. Foreign investors require additional DOIT approval.

What is the minimum capital for cybersecurity companies in Nepal?

Domestic cybersecurity companies require minimum NPR 100,000 authorized capital with NPR 25,000 paid-up. Foreign investment requires minimum NPR 5 million fully paid-up capital. Public limited companies need NPR 10 million authorized capital.

Are there special licenses for cybersecurity companies in Nepal?

Under the Draft IT and Cyber Security Bill 2080, data centers and cloud service providers must obtain licenses within one year of enactment. Security audit firms may require certification from government security agencies. General cybersecurity consulting currently operates under standard IT company registration.

Can foreigners own cybersecurity companies in Nepal?

Yes, foreigners can own cybersecurity companies with minimum NPR 5 million investment and DOIT approval under Foreign Investment and Technology Transfer Act 2075. Technology transfer agreements require separate approval. Profits can be repatriated according to NRB regulations.

What data protection laws apply to cybersecurity companies?

Cybersecurity companies must comply with the Individual Privacy Act 2075, Data Act 2079, and Electronic Transaction Act 2063. The Draft Cyber Security Bill 2080 introduces additional data localization requirements for government, financial, and health data.

How long does cybersecurity company registration take?

Standard registration takes 7-15 working days. Foreign investment cases require 30-45 days due to DOIT approval and Nepal Rastra Bank verification. Expedited processing is available for additional fees.

What are the ongoing compliance requirements?

Ongoing compliance includes: annual general meetings, annual return filing with OCR, income tax returns by mid-January, monthly/quarterly VAT returns, Social Security Fund contributions, annual municipal license renewal, and cybersecurity audit compliance (when Bill enacted).

Is data localization required in Nepal?

Yes, data localization is mandated under the Draft Cyber Security Bill 2080 for government, financial, and health service providers. Critical Information Infrastructure operators must store certain sensitive data within Nepal. Cross-border transfer restrictions apply.

What penalties exist for cybersecurity non-compliance?

Penalties include: up to 3 years imprisonment and NPR 30,000 fines under Privacy Act for data breaches; business license revocation; contract termination; and reputational damage. The Draft Bill proposes enhanced penalties for CII operators.

What business opportunities exist for cybersecurity companies?

Opportunities include: CII security audits (mandatory under Draft Bill), government digital security contracts, banking sector compliance services, healthcare data protection, cloud security services, incident response, and cybersecurity training/education.

Conclusion: Establishing Your Cybersecurity Business in Nepal

Operating cyber security company in Nepal presents significant opportunities in a rapidly growing digital economy. The Draft Information Technology and Cyber Security Bill 2080 and National Cyber Security Policy 2023 create a structured regulatory environment with mandatory compliance requirements driving demand for professional cybersecurity services.

For entrepreneurs and investors, understanding the registration process, capital requirements, licensing obligations, and compliance frameworks ensures successful market entry. The 7-15 day registration timeline for domestic companies and established legal protections under the Companies Act 2063 provide a favorable business environment.

With foreign investment permitted, data localization requirements creating service demand, and CII protection mandates generating audit opportunities, Nepal's cybersecurity sector offers promising prospects for registered and compliant operators.

Need Legal Assistance for Cybersecurity Company Registration?

Attorney Nepal PVT LTD specializes in IT company registration, cybersecurity compliance, foreign investment facilitation, and technology sector legal services. Our experienced team navigates OCR procedures, DOIT approvals, and regulatory compliance for cybersecurity entrepreneurs.

Contact us today for confidential consultation:

  • Phone: +977-9768717747
  • Email: info@attorneynepal.com
  • Office: Kathmandu, Nepal

Register your cybersecurity company. Ensure full legal compliance.

Disclaimer: This blog provides general legal information for educational purposes only and does not constitute legal advice. Laws change frequently, and individual circumstances vary. Consult a qualified attorney for specific legal guidance. The Draft Information Technology and Cyber Security Bill 2080 is pending enactment—monitor official sources for updates.