CBN Cybersecurity Framework

The CBN's cyber mandate: named accountability, risk-based controls and a self-assessment you file.

Market regime · CBN Risk-Based Cybersecurity Framework, with the CSAT return

Issued by

Central Bank of Nigeria

Region

Nigeria

Effective

Banks framework effective 2019; OFIs 2022; CSAT return 2026

Oversight

CBN supervision, with the CSAT self-assessment filed

Applies when

Deposit money banks and payment service providers under CBN supervision

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

The CBN's cybersecurity framework makes cyber a supervised discipline: a designated CISO, a board-approved strategy, risk assessments, incident reporting on a short clock, and the CSAT self-assessment return that puts your posture on the record.

Its shape rhymes with NIST CSF and ISO 27001, which is the practical opportunity: the same control set, cross-mapped, satisfies the international standards and the CBN return at once.

Where programmes are tested.

01

Governance and the CISO

Named accountability, board engagement and a strategy the institution actually follows.

02

Risk-based controls

Assessments that drive control selection, with the technical estate evidenced.

03

Incident reporting and CSAT

Incidents reported within the mandated window, and the self-assessment filed honestly.

Curated once, evidenced continuously.

  • The framework and CSAT questions are curated and cross-walked to ISO 27001 and NIST CSF, so one technical control set answers all three.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

CBN Cybersecurity Framework, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Who must comply with the CBN cybersecurity framework?

Deposit money banks and payment service providers under the original framework, with other financial institutions brought in by later guidelines. If the CBN licenses you, some version of the framework almost certainly reaches you.

What is the CSAT?

The Cybersecurity Self-Assessment Tool: a structured return, introduced by circular in 2026, in which institutions assess themselves across the framework's operational areas and file the result with the CBN. It puts your cyber posture formally on the record, which raises the cost of optimistic answers.

What incident reporting does the framework require?

Cyber incidents must be reported to the CBN within a short mandated window, with the assessment and response documented. The clock, not the severity debate, is what catches institutions out, which is why incident workflows should carry the deadline natively.

How does the framework relate to ISO 27001 and NIST CSF?

It shares their substance: governance, risk assessment, protective controls, detection, response and recovery. Cross-mapped properly, one technical control set evidences all three, so the CSAT return, the ISO certificate and the CSF posture stop being separate projects.

Where it connects.

The full catalog
Carried by these modules
Who answers to it

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.