A bill built for accountability, not for cybercrime
On August 5, 2026, South Africa's Portfolio Committee on Police held its first substantive session on the South African Police Service (SAPS) Amendment Bill, calling the legislation "an opportunity to strengthen police integrity and capacity" (Parliament of South Africa). Committee chair Ian Cameron set the tone bluntly: "Lifestyle audits and integrity testing must not be optional or inconsistently applied; they must be mandatory." That is the right instinct. A police service still governed by a 1995 statute, and still absorbing the fallout of multiple Constitutional Court rulings and commission findings on corruption, needs enforceable integrity rules more than it needs another discretionary policy that senior officers can quietly ignore.
The Bill also proposes expanding municipal police services into public order policing and strengthening the legal footing of Community Police Forums — modest, sensible moves toward using policing capacity that already exists rather than only adding new capacity from scratch. Committee members went further, floating whether trained metro officers could eventually take on defined investigative functions, subject to oversight. That is a reasonable question to ask of a police service that, by its own acting minister's account, cannot currently do everything the law asks of it.
The steelman: SAPS genuinely cannot police what it cannot see
The case for statutory reform here is stronger than reflexive skepticism of new police powers usually allows. Acting Police Minister Firoz Cachalia told Parliament during the May 19, 2026 budget vote that "the challenges facing the forensic services must be addressed as a priority including DNA analysis, ballistics, digital forensics, chemistry and cybercrime investigation capabilities" (gov.za). That is not rhetorical throat-clearing. South Africa's own numbers back it up: banking-sector cyber-attacks topped 100,000 in 2024, an 86% year-on-year increase, causing roughly R1.8 billion in losses — while SAPS had only 544 cyber-related fraud cases on its books for the same period, according to figures the Democratic Alliance has used to push for a dedicated Chapter 9 Cyber Commissioner (DA). Whatever one thinks of that specific institutional fix, the underlying diagnosis is hard to dispute: SAPS is recording a small fraction of the cybercrime actually occurring, which means resourcing decisions are being made on data that understates the problem by orders of magnitude. A police service that cannot see the crime cannot credibly claim jurisdiction over it, and Cachalia is right to name digital forensics and cybercrime investigation as a distinct capacity gap rather than folding it into generic "modernisation" language.
Where the Bill actually falls short
Here is the problem: none of that cybercrime urgency shows up in the Bill itself. Coverage of the August 5 committee session and of the Bill's substance — Constitutional Court alignment, use-of-force standards, municipal policing, disciplinary governance — contains no provision creating digital forensics capacity, cybercrime investigation units, or dedicated funding streams on a statutory footing (EWN). Cachalia's forensic-services commitment lives entirely inside an annual budget speech, which he himself described as part of a "multi-year turnaround strategy" rather than something an annual appropriation can lock in. Budget lines are not durable; a minister's successor can quietly deprioritise digital forensics in next year's allocation with no legislative consequence, while a statutory mandate — a defined cybercrime investigation function, a minimum staffing or training requirement, a reporting obligation — survives changes in political leadership.
This is precisely the wrong sequencing for a pro-innovation, evidence-based reform agenda. South Africa's digital economy — mobile banking, e-commerce, a fast-growing fintech sector — depends on credible law enforcement response to fraud and intrusion, not just on private-sector security spending. Under-resourced, under-trained cyber investigation capacity does not just fail victims; it pushes the compliance burden onto banks and platforms to over-engineer their own fraud controls, raising costs and friction for legitimate users, because they cannot rely on police follow-through when a customer is defrauded. That is a real cost to innovation, not an abstract one.
A narrower, better fix
The committee does not need to abandon its integrity-first framing to close this gap — it needs to add one more layer to it. A statutory cybercrime and digital forensics mandate inside the SAPS Amendment Bill, with minimum resourcing and reporting requirements, would do more for South Africa's digital economy than a standalone Cyber Commissioner office layered on top of an already-strained institutional architecture. The committee's own instinct — make integrity testing mandatory rather than discretionary — is exactly the right template to apply to cybercrime capacity too. Given how directly Cachalia has already tied forensic and cyber capability to the reset agenda, folding a statutory mandate into the Bill now, while it is still in committee, is a far cheaper fix than legislating it separately once the annual-budget approach has predictably failed to keep pace with an 86%-a-year growth curve in attacks.