SARB Joint Standard 2

South Africa's cyber mandate for financial institutions: governance to testing, with the regulators notified.

Market regime · SARB/FSCA Joint Standard 2 of 2024: Cybersecurity and Cyber Resilience

Issued by

SARB Prudential Authority & FSCA

Region

South Africa

Effective

Issued 2024; in force from June 2025

Oversight

Prudential Authority and FSCA, jointly

Applies when

South African financial institutions under the twin-peaks regulators

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

Joint Standard 2 makes cyber resilience a supervised obligation for South African financial institutions: governance with board accountability, protective and detective capability, response and recovery, testing programmes, third-party cyber risk, and notification of material incidents to the authorities.

It is the South African counterpart of the CBN's cybersecurity framework and shares its substance with ISO 27001 and NIST CSF, which is the practical point: one technical control set, cross-mapped, evidences the standard and the international frameworks at once.

Where programmes are tested.

01

Governance and strategy

Board-owned cyber strategy, roles and reporting that the Prudential Authority can test.

02

Protect, detect, respond, recover

The operational lifecycle: controls, monitoring, incident response and recovery capability, evidenced end to end.

03

Testing and assurance

Scenario and resilience testing on a programme, with results and remediation on the record.

04

Third parties and notification

Cyber risk managed across providers, and material incidents notified to the authorities.

Curated once, evidenced continuously.

  • Joint Standard 2 maps onto the same governance and technical controls as the CBN cybersecurity framework, NIST CSF and ISO 27001, one implementation, four reporting languages.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

SARB Joint Standard 2, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Who must comply with Joint Standard 2?

Financial institutions supervised under South Africa's twin-peaks model, banks, insurers, market infrastructures and other regulated entities, per the standard's application schedule. It is issued jointly, so both the Prudential Authority and the FSCA supervise against it.

When did it take effect?

The standard was made in 2024 with effect from June 2025, giving institutions a defined runway. Supervisory engagement started well before the date, which is why programmes were expected to be demonstrably in flight, not merely planned.

How does it relate to ISO 27001 and NIST CSF?

Its substance, governance, protection, detection, response, recovery and testing, is the same discipline those frameworks codify. Cross-mapped properly, the controls you run for ISO 27001 evidence the Joint Standard too; what changes is the supervisory reporting around them.

What incidents must be reported?

Material cyber incidents are notifiable to the authorities within the standard's timelines, with the assessment behind materiality documented. The clock discipline mirrors the CBN's and CBK's regimes: workflows should carry the deadline natively rather than rely on judgement under pressure.

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.