The Central Bank of Nigeria (CBN) has directed all regulated financial institutions in the country to complete a mandatory cybersecurity self-assessment within a strict timeline of three to five weeks, in a move aimed at strengthening the resilience of the nation’s financial system against growing cyber threats.
The directive, contained in a letter dated March 30, 2026 and made public on Tuesday, introduced a Cybersecurity Self-Assessment Tool (CSAT) designed to evaluate the level of cyber risk exposure across Deposit Money Banks, Payment Service Banks, Microfinance Banks, Payment Service Providers, Finance Companies, and Development Finance Institutions.
According to the apex bank, Deposit Money Banks are required to submit their completed assessments within three weeks, while other regulated financial institutions have up to five weeks to comply.
“The Central Bank of Nigeria, in furtherance of its statutory mandate under the Banks and Other Financial Institutions Act (BOFIA) 2020 and consistent with its commitment to strengthening cybersecurity resilience across the financial sector, hereby notifies all Deposit Money Banks, Payment Service Banks, Microfinance Banks, Payment Service Providers, Finance Companies, and Development Finance Institutions of the deployment of its Cybersecurity Self-Assessment Tool,” the circular stated.
The CBN explained that the CSAT will serve as a supervisory instrument to provide a detailed overview of the cybersecurity posture of financial institutions, enabling regulators to better assess vulnerabilities and strengthen oversight in an increasingly digital financial ecosystem.
The tool, according to the apex bank, will assess key areas including governance structures, risk management frameworks, technological systems, third-party risk exposure, incident response mechanisms, and overall operational resilience.
“The CSAT is a structured supervisory instrument designed to obtain comprehensive information on the cybersecurity posture of regulated institutions,” the bank said, noting that the exercise is part of its broader effort to enforce stronger risk-based supervision across the financial sector.
To ensure compliance, the CBN directed all affected institutions to complete and submit their assessments through a designated portal, with login credentials to be provided to Chief Information Security Officers and other relevant officials within each institution. The regulator also insisted that all submissions must be fully completed and supported with appropriate documentation where necessary.
The data to be submitted must reflect the institutions’ cybersecurity positions as of December 31, 2025, the CBN stated.
In a firm warning, the apex bank stressed that accuracy and transparency are mandatory, adding that any attempt to submit false or misleading information would be treated as a serious regulatory breach.
“Supervised institutions are reminded that all information submitted to the CBN must be accurate, complete, and verifiable. Submission of false, misleading, or inaccurate information constitutes a regulatory breach and will attract appropriate sanctions,” the statement warned.
The regulator also disclosed plans to verify submissions through off-site reviews and supervisory engagements, in order to ensure that the data provided reflects the true state of cybersecurity preparedness across the sector.
The directive comes at a time when Nigeria’s financial system is experiencing rapid growth in digital transactions, alongside an increase in cyber fraud cases that have raised concerns among regulators, financial experts, and consumers alike.
Industry observers have repeatedly warned that weak cybersecurity systems could expose customers to financial losses and undermine confidence in digital banking services, a concern that has been echoed in previous industry discussions and reports.
The latest directive by the CBN is therefore seen as part of ongoing efforts to reinforce digital security, improve regulatory oversight, and protect Nigeria’s expanding financial technology ecosystem from emerging cyber risks.



































Discussion about this post