060 293 3939   cipa@nationalkeypointtraining.co.za
PSIRA • SASSETA • SAQA Aligned
Home / Blog / Legislation / CIPA Act 8 of 2019

Chapter 4: Powers and Duties of Persons in Control of Critical Infrastructure

2026   •   9 min read   •   Legislation

Kendal Power Station, Mpumalanga

Kendal Power Station, Mpumalanga. Photo: Bruce Paulmac, CC BY-SA 3.0, via Wikimedia Commons.

Once infrastructure is declared, Chapter 4 places direct legal duties on the person in control — the operator responsible for a site's day-to-day security. This includes implementing security measures, controlling access, and reporting. At facilities the scale of Kendal or Majuba Power Station, these duties translate directly into the physical protection systems and access-control training that security personnel are deployed to enforce.

Reading the Act, Chapter by Chapter

This page covers Chapter 4 of the Critical Infrastructure Protection Act, 2019 (Act 8 of 2019), Government Gazette No. 42866. Read the Act's full text below, or jump to another chapter in the sidebar.

Full Text: Chapter 4

INFRASTRUCTURE Powers and duties of person in control of critical infrastructure

Section 24

(1) On receipt of a notice referred to in section 20(2), the person in control of a critical infrastructure must, subject to subsection (4), take such steps as may be prescribed to secure such critical infrastructure at that person's own expense.

(2) The person in control of critical infrastructure that is under the control of a Government department or any other organ of state, must take steps to ensure that such critical infrastructure is protected by the employees of that government department or organ of state.

(3) Where the Government department or organ of state referred to in subsection (2) is unable to protect a critical infrastructure as contemplated in subsection (2), the person in control of that critical infrastructure must take steps to ensure that a security service provider is appointed to protect the critical infrastructure: Provided that such security service provider may only be appointed after the successful completion of security vetting by the State Security Agency.

(4) (a) Subject to paragraphs (b) and (c), the Minister may, if the person in control of critical infrastructure shows good cause in the application contemplated in sections 17(1) or 18(1)(b), determine that the Head of a Government department is responsible for all or some of the expenses necessary to implement the steps contemplated in subsection (1). (b) For purposes of determining the extent to which the Head of a Government department contemplated in paragraph (a) is responsible for the expenses, the Minister must— (i) in the case of a national department, consult the Minister of Finance and the Minister responsible for the affected department; (ii) in the case of a provincial department, consult the relevant Member of the Executive Council responsible for finance and the relevant Member of the Executive Council responsible for the affected department; (iii) in the case of a municipality, consult the relevant Municipal Council; and (iv) where applicable, take into account any policy of the Cabinet, the relevant Executive Council or Municipal Council regarding the standards of any security measures and the reasonable costs that may be incurred by the State. (c) The Minister must, in writing, inform the Head of the Government department and the person in control of that critical infrastructure of the decision, setting out the extent to which— (i) the Head of the Government department contemplated in paragraph (b); and (ii) the person in control of the critical infrastructure, is responsible for expenses necessary to implement the steps contemplated in subsection (1).

(5) In the event that a person in control of a critical infrastructure fails to take the steps contemplated in subsection (1), the Minister may, by written notice in the prescribed form and manner, order him or her to take, within a period specified in the notice and at his or her own expense, such steps in respect of the security of the critical infrastructure as may be specified in the notice.

(6) If the person in control of a critical infrastructure refuses or fails to take the steps specified in the notice within the period specified therein, the Minister must take or cause steps to be taken in respect of the security of that critical infrastructure and the Minister must recover the reasonable cost thereof from the person in control of that critical infrastructure to such extent as the Minister may determine.

(7) A person in control of a critical infrastructure must appoint a person in the employ of the critical infrastructure as security manager to— (a) implement and monitor, on behalf of the person in control of the critical infrastructure, the prescribed security policy and plan compiled for that critical infrastructure; (b) authorise access to critical infrastructure or oversee the authorisation of such access by security personnel working under his or her direction; (c) liaise with any security service provider appointed by the person in control of that critical infrastructure; (d) implement the directions contemplated in section 25(1)(b); (e) provide monthly reports to the person in control of that critical infrastructure on the functions contemplated in paragraphs (a), (b) and (c); and (f) perform such other functions related to the securing of that critical infrastructure as may be assigned to him or her by the person in control of that critical infrastructure: Provided that such security manager may only be appointed after successful completion of security vetting by the State Security Agency.

(8) A person in control of a critical infrastructure must as far as practically possible demarcate and place a notice, in the prescribed format and manner, on premises constituting a critical infrastructure, in order to notify persons that the premises are declared a critical infrastructure.

(9) A person to whom functions are assigned in terms of this Chapter must exercise such powers and perform such duties subject to the Constitution and with due regard to the fundamental rights of every person. Access to critical infrastructure

Section 25

(1) Subject to section 24, the person in control of a critical infrastructure must— (a) take such lawful steps as he or she may consider necessary, for the securing of a critical infrastructure and the contents thereof, as well as for the protection of the persons present at the critical infrastructure; (b) issue a notification in the prescribed form that the critical infrastructure may only be entered upon in accordance with the provisions of subsection (2) and that persons or vehicles may be searched upon entering or leaving the premises in terms of subsection (5); and (c) ensure that a notification as contemplated in paragraph (b) is placed at the entrance to that critical infrastructure.

(2) (a) No person may, without the permission of the security manager, or the security personnel under the direction of the security manager enter into or upon any critical infrastructure in respect of which a direction has been issued in terms of subsection (1)(b). (b) For the purpose of granting permission, the security manager or the security personnel under the direction of the security manager, may require of a person to— (i) furnish his or her name, address and any other relevant information required by the authorised person; (ii) produce proof of his or her identity; (iii) declare whether he or she has any dangerous object in his or her possession or under his or her control; (iv) declare the contents of any vehicle, suitcase, bag, handbag, folder, envelope, parcel or container of any nature, which he or she has in his or her possession, custody or control, and show the content to the security manager; (v) subject himself or herself and anything in his or her possession or under his or her control to an examination by an electronic or other apparatus, in order to determine the presence of any dangerous or prohibited object; and (vi) subject to subsection (6), be searched by a security manager or security personnel under the direction of the security manager.

(3) Where the security manager or the security personnel under the direction of the security manager grants permission to a person in terms of subsection (2), the person may enter subject to conditions regarding— (a) the carrying or displaying of proof that the necessary permission has been granted; (b) restrictions relating to persons with whom he or she may come into contact in or on the critical infrastructure; (c) restriction of access to certain parts of the critical infrastructure; (d) the duration of his or her presence on or in the critical infrastructure; (e) being escorted while he or she is on or in the critical infrastructure; and (f) other requirements as the security manager or the security personnel may consider necessary.

(4) Without derogating from the provisions of the Trespass Act, 1959 (Act No. 6 of 1959), a security manager or the security personnel under the direction of the security manager may, at any time, remove any person from any critical infrastructure if— (a) that person enters the critical infrastructure or any part of the critical infrastructure concerned, without the required permission contemplated in subsection (2); (b) that person refuses or fails to observe a condition contemplated in subsection (3); or (c) it is necessary for the securing of the critical infrastructure concerned or the contents thereof or for the protection of the people therein or thereon.

(5) The person in control of a critical infrastructure may determine that persons and vehicles leaving that critical infrastructure must be searched subject to subsection (6).

(6) (a) Any search of a person's body conducted under subsections (2)(b)(vi) or (5) must be carried out by a person of the same gender, or as preferred in terms of paragraph (d)(ii), with strict regard to the right to privacy and dignity and must be in accordance with the provisions of this section and any other prescribed directive. (b) When conducting a search of a person's body under subsections (2)(b)(vi) and (5), the manner of search is restricted to a pat-down of the person's outer garments to establish whether that person is in possession or control of a prohibited or dangerous object. (c) A search of a person's body under subsection (2)(b)(vi) or (5) may only be performed if— (i) a reasonable suspicion exists that such a person did not declare a dangerous or prohibited object in his or her possession or under his or her control; and (ii) the manner of or place where the search is performed does not infringe upon the privacy and dignity of the person to be searched. (d) Before a security manager or security personnel under the direction of the security manager may search a person referred to in paragraph (c)(i), the person to be searched must be— (i) informed of the gender of the person who will conduct the search, the manner of search and the place where the search will be performed; and (ii) provided with an opportunity to express a preference regarding the gender of the member of the security personnel who must conduct the search.

(7) If it is not practicable to examine or keep in custody on or in the critical infrastructure concerned, anything which may be examined or kept in custody under subsection (2), may be removed to a suitable place for that purpose.

(8) The person in control of a critical infrastructure must indicate in a notice, in the prescribed form and manner, at every entry point of a critical infrastructure that the critical infrastructure may only be entered upon in accordance with the provisions of subsection (2) and the conditions determined by the security manager.

Train Your Team to CIPA, Not the Old Act

Get accredited, audit-ready Critical Infrastructure / NKP training mapped to current legislation.

Book a Consultation