CBN Data Localization: Frequently asked questions
Common questions from Nigerian banks, fintechs, and payment service providers.
What is the CBN Data Localization Regulation?+
The Central Bank of Nigeria requires that all payment transaction data generated by Nigerian banks, fintechs, and payment service providers be stored on servers physically located in Nigeria. The regulation takes full effect on 1 January 2027.
Who is subject to the regulation?+
Commercial banks, microfinance banks, fintechs and payment service providers (PSPs), mobile money operators, and other CBN-licensed payment participants that process payment transaction data of Nigerian residents.
What is the deadline?+
1 January 2027. We recommend completing your data inventory in the first 30 days, controls assessment by day 45, and finalising your migration plan by day 60 to stay ahead of the deadline.
What counts as payment data that must be localised?+
Card data, transaction records, customer PII tied to payments, authentication data, tokenisation keys, and any logs or backups that contain the above. If in doubt, treat it as in-scope until legal review says otherwise.
Can I use a foreign cloud provider?+
Only if the provider offers a Nigeria-resident region, or if the payment data itself remains inside Nigeria (for example, in a Nigerian data centre) with strict controls on cross-border replication. GRC Command Center helps you inventory every store and prove residency.
What is the penalty for non-compliance?+
CBN can impose administrative fines, restrict licences, and require remediation on a compressed timeline. Beyond direct penalties, non-compliance creates reputational and audit exposure with partner banks and payment schemes.
How does GRC Command Center help?+
You get a 22-control CBN Data Localization assessment, a full CBN Risk-Based Cybersecurity Framework browser (10 Parts, 25 clauses as CBN publishes them), a payment data store inventory, an evidence vault, an auto-generated Plan of Action and Milestones, a live readiness score, and a board-ready PDF report. Shareable links let external auditors and CBN examiners view your posture without a login.
What is the difference between the 22-control assessment and the CBN Framework browser?+
The 22-control assessment is Symbiosis's data-localization focused working list, grouped into 4 domains (Data Localization, Security of Local Infrastructure, NDPA 2023 intersection, Business Continuity). The CBN Framework browser at /cbn-controls shows the wider Risk-Based Cybersecurity Framework the way CBN publishes it: 10 Parts and 25 clauses, with intent and summary for each clause. Both live in the same workspace.
Can I record status and attach evidence against individual CBN clauses?+
Yes. Signed-in users can mark each clause In place, Partially, Not applicable, or Not assessed, add notes, and attach evidence directly from the CBN Framework browser. Everything is scoped to your organization.
How do I attach evidence to a specific CBN clause?+
Open the CBN Framework browser, sign in, and expand the clause you want to evidence (for example, 3.6 Incident Response). Click Attach evidence to jump into the CBN evidence vault, upload a PDF, DOCX, XLSX, PNG, or JPG (25MB max), choose a category (Policy Document, Audit Report, Penetration Test Report, Architecture Diagram, Configuration Screenshot, Vendor Contract, Migration Plan, or Other), set the document date, and tick the clause it satisfies. The upload is written back to the clause automatically, and the clause card shows a live evidence count.
How is evidence stored, and how are Current vs Expired decided?+
Every uploaded artifact is stored in a private, per-organization backend bucket and indexed against the clauses it satisfies. On the clause card, each artifact shows its file name, category, owner (You or Team member), and collection date. Status is derived from the document date: Current when the date is within the last 365 days, Expired when older, Undated when no document date was captured. Expired artifacts stay visible so auditors can see history, but readiness reports flag them for refresh.
Who in my organization can edit CBN evidence and status?+
Anyone signed into your organization can view CBN clauses and their evidence register. Only members of that organization (with write access) can set clause status, add or edit notes, upload evidence, or remove artifacts. Actions are recorded per user, and shareable read-only report links (for CBN examiners or external auditors) never grant edit access.
Is the NIST 800-53 crosswalk part of CBN's official framework?+
No. The NIST 800-53 Rev 5 mapping is a third-party crosswalk from Open Security Architecture, not CBN's own numbering. It is exposed in a clearly labelled secondary tab of the CBN Framework browser for teams that also work in NIST. CBN's own Parts and clauses are always the primary view.
Do you also cover NDPA 2023?+
Yes. The Professional plan includes the Nigeria Data Protection Act 2023 module, so you can manage CBN localization, the wider CBN Cybersecurity Framework, and NDPA privacy obligations from one workspace.
How long does the assessment take?+
Most teams complete initial setup in 15 minutes and finish the 22-control assessment in a few working sessions. Walking the full 25-clause CBN Framework and attaching evidence per clause takes longer and is typically done alongside your annual CSAT preparation.