What changed recently
CBN reported that a revised Risk-Based Cybersecurity Framework for Deposit Money Banks and Payment Service Banks took effect on 1 July 2024. In March 2026, CBN also announced deployment of a Cybersecurity Self-Assessment Tool for banks and selected Other Financial Institutions. Teams should work from the framework and circular that applies to their licence rather than treating one testing schedule as universal.
Start with the CBN circular register and the CBN payment-service-provider resources, then confirm applicability with your compliance adviser.
The CBN Risk-Based Cybersecurity Framework
The CBN maintains strict cybersecurity guidelines for Other Financial Institutions (OFIs) and Payment Service Providers (PSPs). The framework emphasizes a proactive approach to identifying and mitigating technical vulnerabilities.
Vulnerability Assessments
Applicable CBN frameworks expect institutions to identify, assess, track, and remediate vulnerabilities across infrastructure, applications, APIs, and third parties. The required frequency depends on the institution and payment scheme.
Penetration Testing
Independent penetration testing provides evidence that important controls work under active testing. Confirm the required cadence and scope against the framework, scheme rules, and current circulars that apply to your institution.
Data Protection (NDPR/NDPC)
The Nigeria Data Protection Commission requires strict controls over PII (Personally Identifiable Information). Penetration testing proves to auditors that your customer data - like BVNs and transaction histories - cannot be exposed via API flaws (like BOLA) or insecure storage.
Secure Software Development Lifecyle (SSDLC)
Regulators increasingly look at how you build software, not just the finished product. Integrating security reviews into your sprint cycles demonstrates a mature SSDLC to CBN examiners.
How Simpa Labs reports support your audit
A compliance auditor needs records showing that you find and fix vulnerabilities. A generic scanner report lacks the context required for that review.
Simpa Labs provides detailed, contextual reporting that helps satisfy auditor requests:
- Executive & Management Summaries: Clear, high-level overviews of your risk posture suitable for board members and CBN examiners.
- Methodology documentation: Records showing that testing used manual methods, OWASP guidance, and your application architecture.
- Remediation verification: Retest records showing which critical vulnerabilities were fixed and which remain open.
Build an evidence map before the review
For each requirement, record the control owner, policy, system, evidence, review date, open gap, and repair plan. Link claims to records: access reviews, change approvals, incident exercises, vulnerability work, independent test reports, fix tickets, and retest results.
A penetration test report proves the scope and results of that test. It does not prove that every governance, privacy, resilience, vendor, or operational control works. Keep the report beside the wider audit evidence and state its boundaries.
What to ask from a testing provider
- A signed scope with systems, roles, environments, dates, and exclusions.
- A method tied to the application and infrastructure in scope.
- Verified findings with evidence, impact, and clear repair steps.
- A management summary that does not expose exploit details.
- A retest record that shows the status of each finding.
Have a compliance deadline approaching? We scope and execute fast.
Discuss CBN readinessRelated services and resources
CBN readiness commonly involves vulnerability assessment, independent penetration testing, documented remediation, and evidence that relevant controls operate as intended. Confirm frequency and scope against the requirements that apply to your institution. For developer guidance, see our fintech security checklist and the OWASP Top 10 for fintech.
Frequently asked questions
What are the CBN cybersecurity requirements for fintech companies?
The exact obligations depend on the institution's licence, scheme participation, and applicable CBN framework. Common expectations include cybersecurity governance, risk assessment, vulnerability management, resilience, incident response, secure development, third-party oversight, testing evidence, and documented remediation.
How often must a CBN-licensed fintech do penetration testing?
Testing frequency depends on the framework and payment scheme that applies to the institution. Some CBN payment-system requirements specify periodic vulnerability assessments and annual penetration tests, while other obligations are risk-based. Confirm the applicable schedule with your compliance team and current CBN circulars.
Can a Simpa Labs report be submitted to CBN examiners?
You can submit the parts requested for your review. Confirm the required format with your compliance adviser or examiner. Our report states the scope, method, dates, findings, evidence, repair guidance, and retest status. It does not replace the rest of your audit evidence.
What happens if a CBN-licensed fintech lacks security testing evidence?
Without evidence of independent security testing, you risk regulatory sanctions during CBN examinations, increased liability if a breach occurs, and potential issues with license renewal. The CBN's Risk-Based Cybersecurity Framework explicitly expects proactive vulnerability identification and remediation.