Nigeria

NG · NGA · Middle East & Africa · Last verified 6 Oct 2026

5 regulators · 6 laws & regulations · 6 obligations · 1 upcoming deadline

Nigeria — hero image

Regulation 2018

CBN Risk-Based Cybersecurity Framework and Guidelines

Issued by Central Bank of Nigeria

Effective: 1 Jan 2019

Last amended: 1 Jul 2024

Plain-English summary

The CBN Risk-Based Cybersecurity Framework and Guidelines are a legally binding subsidiary legislation enacted through the powers vested in it via BOFIA 2020, which seeks to put in place the minimum cybersecurity requirements for financial institutions in Nigeria. While the initiative was initially launched on January 1, 2019, for large commercial banks before being expanded to other financial institutions, the framework operates within the ambit of a highly revamped 10-point framework, which took effect on July 1, 2024. This framework compels the banks and fintechs to have an independent Chief Information Security Officer (CISO) as well as undertake vulnerability assessments and have real-time threat intelligence. Under the tight leash of the CBN, firms are expected to submit data through the automated Cybersecurity Self-Assessment Tool (CSAT) by February 28 each year or suffer very stern enforcement measures like million-naira administrative fines and loss of operating license.

Who it applies to

Banking · Payments & Fintech

Topics

Cybersecurity & IT Risk

Official source

Latest news

No related news yet. We publish updates as regulators act.

Browse all newsSubscribe for updates