Zimbabwe’s Companies and Other Business Entities Act (COBE) re-registration deadline is April 20, 2026 — 24 days away. Every company operating in Zimbabwe, including digital platforms, fintechs, mobile money operators, and crypto exchanges, must have re-registered with the Registrar of Companies and obtained a QR-coded certificate before that date or face removal from the register.
This is not a soft deadline. Under the COBE Act framework, companies that fail to re-register lose their legal standing. Banks and regulators have been informed to treat unregistered entities as non-compliant from April 21. For technology operators already navigating Zimbabwe’s 15% Digital Services Tax and the 2% transaction tax, this adds a third compliance lane — with its own distinct set of penalties.
This checklist maps what you must do, in sequence, before April 20.
Who This Affects
The April 20 deadline applies broadly. If your company is incorporated in Zimbabwe or operates a registered local entity, re-registration is mandatory. Specifically at risk if not yet compliant:
- Digital platforms with a registered Zimbabwe subsidiary or local branch
- Fintech operators holding RBZ fintech licences or mobile money authorisations
- Crypto exchanges and VASPs that registered under the RBZ Virtual Assets Service Provider (VASP) framework
- SaaS and cloud providers with a local corporate entity (distinct from withholding obligations under BETA-322)
- Mobile money operators including EcoCash, InnBucks, and any platform holding a Payment System Provider licence
Foreign companies without a Zimbabwe-registered entity are not directly affected by COBE re-registration — but they remain subject to the 15% DST withholding obligations covered in our earlier analysis.
The Six-Step Compliance Checklist
Step 1 — Confirm COBE registration status (by March 31)
Log into the Companies and Other Business Entities Registry System (COBERS) at cobers.gov.zw and verify your entity’s current registration status. Companies that were previously registered under the old Companies Act must have migrated to COBE. If the status shows “pending migration” or “legacy entity”, treat this as urgent — migration requests filed after April 7 are unlikely to be processed in time.
Step 2 — Obtain a QR-coded certificate of incorporation (by April 7)
This is the key new requirement. Updated certificates issued under the COBE framework carry a QR code that links to the COBERS live register. Banks, government counterparties, and regulators will require this certificate from April 21 for all corporate transactions and licence renewals. The old paper certificates — even if not expired — will not satisfy this requirement.
The certificate application is filed through COBERS. Processing typically takes 5–10 business days. File by April 7 to allow buffer for processing delays.
Step 3 — Update your registered office and officer details (concurrent with Step 2)
COBE re-registration requires up-to-date details for all directors, registered office address, and beneficial ownership. If any of these have changed since your original incorporation, update them in the COBERS filing. Mismatches between COBERS records and RBZ licencing records are a common cause of rejection.
Step 4 — Crypto/VASP operators: obtain POTRAZ data controller licence (by April 14)
Statutory Instrument 155 of 2024 created a data controller licensing obligation that sits alongside COBE compliance, specifically targeting Virtual Asset Service Providers. Under SI 155/2024, any VASP operating in Zimbabwe must:
- Register as a data controller with the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ)
- Appoint a Data Protection Officer (DPO)
- File a data processing record and privacy impact assessment
The penalty structure for non-compliance is distinct from COBE. Operating without a POTRAZ data controller licence carries a penalty of up to US$1,000 and/or seven years’ imprisonment. Failure to appoint a DPO carries up to US$400 and/or two years’ imprisonment. These penalties apply to company officers personally, not only to the entity.
POTRAZ processes data controller applications in 10–15 business days. Given this window, VASPs that have not yet applied should treat April 14 as their internal submission deadline.
Step 5 — Verify KYC records meet the seven-year retention requirement (rolling)
Zimbabwe’s AML/CFT framework, updated alongside the COBE and data protection rules, mandates seven-year retention of all Know Your Customer records. For fintechs and mobile money operators, this means onboarding documents, transaction records, and source-of-funds documentation must be retained for seven years from the date of last transaction with each customer. COBERS re-registration triggers a routine compliance audit window; expect RBZ and ZIMRA inspections in the weeks following April 20.
Step 6 — Update financial institution relationships with new certificate (April 20)
Banks operating in Zimbabwe have been advised that from April 21, corporate accounts for entities that cannot present a valid QR-coded COBE certificate may be flagged for review. Notify your primary banking relationship and any payment system counterparties of your new certificate once issued. For mobile money operators, this includes confirming certificate updates with switch operators and interbank settlement counterparties.
Non-Compliance Consequences: A Penalty Matrix
| Violation | Consequence | Who is at risk |
|---|---|---|
| Missing COBE re-registration by April 20 | Removal from register; loss of legal entity status | All Zimbabwe-registered companies |
| No QR-coded certificate | Bank account review from April 21; licence renewal blocked | All re-registered entities |
| No POTRAZ data controller licence (VASPs) | Up to US$1,000 fine and/or 7 years imprisonment for officers | Crypto exchanges, VASPs |
| No DPO appointed (VASPs) | Up to US$400 fine and/or 2 years imprisonment for officers | Crypto exchanges, VASPs |
| KYC records below 7-year threshold | AML regulatory sanction; RBZ licence suspension risk | Fintechs, mobile money operators |
The Converging Tax Obligations
COBE re-registration does not stand alone. Operators are managing three parallel compliance obligations that reinforce each other through data-sharing between ZIMRA, POTRAZ, and the RBZ:
- 15% DST withholding on payments to non-resident digital service providers (active since January 1, 2026)
- 2% transaction tax on electronic payments above ZWG thresholds
- COBE re-registration + QR certificate — April 20 deadline
ZIMRA cross-references COBERS registration data for tax enforcement. An entity that re-registers under COBE effectively updates ZIMRA’s taxpayer registry. This means re-registration is both a corporate compliance obligation and a tax audit trigger — ZIMRA may initiate a review of DST withholding compliance, particularly for technology companies with significant SaaS spend.
What Comes Next
The April 20 deadline represents the end of Zimbabwe’s two-year COBE transition window. After that date, the Registrar has indicated enforcement action will begin — both through removal from the register and through cross-referral to the RBZ for licenced operators.
For companies that are already compliant with COBE but have not yet addressed the SI 155/2024 POTRAZ data controller requirement, the window is narrowing. POTRAZ has not announced an enforcement cliff date distinct from April 20, but the alignment with the COBE deadline suggests coordinated regulatory action in Q2 2026.
Operators with Zimbabwe exposure should treat this week — and not the final days before April 20 — as the effective deadline for compliance action.
BETAR.africa covers Africa’s digital policy and regulatory landscape. For Zimbabwe’s 15% Digital Services Tax compliance analysis, see our earlier coverage: Zimbabwe’s 15% Digital Services Tax Is the Steepest on the Continent.