10 Goba Close, Wuse II Abuja, FCT, Nigeria

info@policyregistry.org

Letter to all Banks and Select OFIs on the deployment of the CSAT - final

Finance & Economy
Share
Overview

The Central Bank of Nigeria (CBN) issued a letter to banks, selected other financial institutions (OFIs), and payment service providers (PSPs) regarding the deployment of the Cybersecurity Self-Assessment Tool (CSAT). The CSAT is a supervisory instrument aimed at obtaining detailed information on the cybersecurity posture of regulated entities, covering areas such as cybersecurity governance, risk management, technology and third-party risk controls, incident response capabilities, and operational resilience. The data will support risk-based supervision and enhance regulatory oversight of cybersecurity risks. Institutions are required to submit the completed CSAT via a dedicated portal; access credentials and guidance will be provided to Chief Information Security Officers. Timelines for submission: three weeks for Deposit Money Banks (DMBs) and five weeks for all other regulated institutions (including Payment Service Banks, Microfinance Banks, Payment Service Providers, Finance Companies, and Development Finance Institutions). The cut-off date for data is December 31, 2025. All submissions must be accurate, complete, and verifiable; false information constitutes a regulatory breach under BOFIA 2020 and will attract sanctions. The CBN will conduct validation exercises including off-site reviews and supervisory engagements. Clarifications can be directed to cmd.enterprisesecurity@cbn.gov.ng. The letter takes immediate effect.

Download

Ask AI about this document
What is this document about? What are the key points? Summarise in 3 bullets Who is the intended audience?

Ask any question about
Letter to all Banks and Select OFIs on t...