CBN Mandates Cybersecurity Self-Assessment for Banks

The Central Bank of Nigeria (CBN) has set a three-week deadline for Deposit Money Banks (DMBs) to complete a mandatory cybersecurity self-assessment as part of efforts to strengthen resilience across the financial system. This directive was communicated in a letter dated March 30, 2026, published on the CBN's website.
Financial institutions are required to submit their completed Cybersecurity Assessment Tool (CSAT) within this timeline. The CBN's initiative aligns with its statutory mandate under the Banks and Other Financial Institutions Act (BOFIA) 2020, aimed at enhancing cybersecurity standards in the sector.
The CSAT is designed as a supervisory instrument to provide a comprehensive view of the cybersecurity posture of regulated entities, assessing critical areas such as governance structure, risk management framework, and third-party risk exposure. The CBN has warned against false or incomplete disclosures, emphasizing the need for accuracy and transparency, with strict penalties for regulatory breaches.
This move signals tighter regulatory scrutiny of cyber risks in Nigeria's banking sector amid increasing digital transactions and cyber threats.
Plus234Feed summary based on reporting from Punch Newspapers. Read the original report below.
Read full article
Continue on Punch Newspapers








