Dashboard
118 days until CBN payment data localization deadline (January 1, 2027)
For Nigerian Banks, Fintechs & Payment Service Providers

Is Your Payment Data Ready for the CBN Localization Deadline?

January 1, 2027. Nigerian banks, fintechs, and payment service providers must store all payment transaction data on local servers. Start your compliance assessment today, free.

Start Free Assessment
Data must stay in Nigeria

Are you certain every payment transaction record is hosted on Nigerian soil?

Local hosting, new obligations

Local servers create new security duties. Are your controls prepared?

NDPA 2023 still applies

Localized data still falls under NDPA. Do your controls cover both regimes?

GRC Command Center: Your CBN Compliance Workspace

Four guided steps that take you from data discovery to a board-ready readiness report.

Step 1
Payment Data Inventory

Map every data store and identify non-compliant hosting immediately.

Step 2
Controls Assessment

Assess 22 controls across data localization, security, NDPA, and business continuity.

Step 3
Evidence Vault

Upload and organise your compliance evidence in one secure workspace.

Step 4
Readiness Report

Generate a professional PDF report ready for CBN auditors or board presentation.

Simple pricing for Nigerian regulated entities

Prices shown in both NGN and USD. NGN pricing honoured for Nigeria-domiciled entities.

Starter
₦150,000/month
or $99/month
  • One workspace
  • Up to 5 users
  • Full assessment and report
Start Free
Most Popular
Professional
₦500,000/month
or $349/month
  • Three workspaces
  • Up to 20 users
  • Priority support
  • NDPA compliance module included
Start Free
Advisory
Custom
  • Everything in Professional
  • Hands-on support from Symbiosis LLC consultants
  • Contact for pricing
Contact Sales
22 controls across 4 domains

The full CBN control library

Every control your assessment covers, grouped by domain. You answer each one inside the compliance workspace with evidence, status, and notes.

This 22-control set is Symbiosis's data-localization focused working list, not CBN's own control catalogue. To browse the wider CBN Risk-Based Cybersecurity Framework the way CBN publishes it (10 Parts, 25 clauses), open the CBN Framework browser.

Showing 22 of 22 controls

Domain 1: Data Localization
6 controls
  • CBN-DL-01All payment transaction data generated in Nigeria is stored on servers physically located within Nigeria
  • CBN-DL-02A complete inventory of all payment data stores has been documented and classified
  • CBN-DL-03Data migration plan from offshore to local storage has been formally documented and approved
  • CBN-DL-04Local server infrastructure has been procured or contracted with a Nigerian data centre
  • CBN-DL-05Data residency can be demonstrated to CBN auditors with documented evidence
  • CBN-DL-06Real-time and batch payment data flows have been re-routed to local storage endpoints
Domain 2: Security of Local Infrastructure
7 controls
  • CBN-SI-01Physical access controls are in place for local server rooms or data centre space (biometric access, visitor logs, CCTV)
  • CBN-SI-02Network perimeter security (firewall, IDS/IPS) is deployed and configured for local payment data infrastructure
  • CBN-SI-03All payment transaction data at rest is encrypted using AES-256 or equivalent
  • CBN-SI-04All payment transaction data in transit is encrypted using TLS 1.2 minimum
  • CBN-SI-05Privileged access to local payment data servers is logged, reviewed, and MFA-protected
  • CBN-SI-06Vulnerability scanning of local payment infrastructure is performed monthly minimum
  • CBN-SI-07A penetration test of local payment infrastructure has been completed within the last 12 months
Domain 3: NDPA 2023 Intersection
5 controls
  • CBN-ND-01Security measures applied to locally stored payment data meet NDPA 2023 Article 27 proportionality standard
  • CBN-ND-02Retention schedule for locally stored payment data complies with NDPA data minimization principle
  • CBN-ND-03Data subject rights (access, erasure, rectification) can be fulfilled for payment data stored on local infrastructure
  • CBN-ND-04A Data Protection Officer or equivalent has oversight of locally stored payment transaction data
  • CBN-ND-05Breach notification procedures for local infrastructure incidents meet NDPA 72-hour reporting requirement
Domain 4: Business Continuity
4 controls
  • CBN-BC-01Local server infrastructure has documented uptime SLA and backup power (UPS, generator)
  • CBN-BC-02Payment data backup is performed daily minimum to a second local site or secure offline media
  • CBN-BC-03Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for local payment infrastructure are documented and tested
  • CBN-BC-04A business continuity plan specifically addresses local infrastructure failure scenarios

CBN Data Localization: Frequently asked questions

Common questions from Nigerian banks, fintechs, and payment service providers.

What is the CBN Data Localization Regulation?+
The Central Bank of Nigeria requires that all payment transaction data generated by Nigerian banks, fintechs, and payment service providers be stored on servers physically located in Nigeria. The regulation takes full effect on 1 January 2027.
Who is subject to the regulation?+
Commercial banks, microfinance banks, fintechs and payment service providers (PSPs), mobile money operators, and other CBN-licensed payment participants that process payment transaction data of Nigerian residents.
What is the deadline?+
1 January 2027. We recommend completing your data inventory in the first 30 days, controls assessment by day 45, and finalising your migration plan by day 60 to stay ahead of the deadline.
What counts as payment data that must be localised?+
Card data, transaction records, customer PII tied to payments, authentication data, tokenisation keys, and any logs or backups that contain the above. If in doubt, treat it as in-scope until legal review says otherwise.
Can I use a foreign cloud provider?+
Only if the provider offers a Nigeria-resident region, or if the payment data itself remains inside Nigeria (for example, in a Nigerian data centre) with strict controls on cross-border replication. GRC Command Center helps you inventory every store and prove residency.
What is the penalty for non-compliance?+
CBN can impose administrative fines, restrict licences, and require remediation on a compressed timeline. Beyond direct penalties, non-compliance creates reputational and audit exposure with partner banks and payment schemes.
How does GRC Command Center help?+
You get a 22-control CBN Data Localization assessment, a full CBN Risk-Based Cybersecurity Framework browser (10 Parts, 25 clauses as CBN publishes them), a payment data store inventory, an evidence vault, an auto-generated Plan of Action and Milestones, a live readiness score, and a board-ready PDF report. Shareable links let external auditors and CBN examiners view your posture without a login.
What is the difference between the 22-control assessment and the CBN Framework browser?+
The 22-control assessment is Symbiosis's data-localization focused working list, grouped into 4 domains (Data Localization, Security of Local Infrastructure, NDPA 2023 intersection, Business Continuity). The CBN Framework browser at /cbn-controls shows the wider Risk-Based Cybersecurity Framework the way CBN publishes it: 10 Parts and 25 clauses, with intent and summary for each clause. Both live in the same workspace.
Can I record status and attach evidence against individual CBN clauses?+
Yes. Signed-in users can mark each clause In place, Partially, Not applicable, or Not assessed, add notes, and attach evidence directly from the CBN Framework browser. Everything is scoped to your organization.
How do I attach evidence to a specific CBN clause?+
Open the CBN Framework browser, sign in, and expand the clause you want to evidence (for example, 3.6 Incident Response). Click Attach evidence to jump into the CBN evidence vault, upload a PDF, DOCX, XLSX, PNG, or JPG (25MB max), choose a category (Policy Document, Audit Report, Penetration Test Report, Architecture Diagram, Configuration Screenshot, Vendor Contract, Migration Plan, or Other), set the document date, and tick the clause it satisfies. The upload is written back to the clause automatically, and the clause card shows a live evidence count.
How is evidence stored, and how are Current vs Expired decided?+
Every uploaded artifact is stored in a private, per-organization backend bucket and indexed against the clauses it satisfies. On the clause card, each artifact shows its file name, category, owner (You or Team member), and collection date. Status is derived from the document date: Current when the date is within the last 365 days, Expired when older, Undated when no document date was captured. Expired artifacts stay visible so auditors can see history, but readiness reports flag them for refresh.
Who in my organization can edit CBN evidence and status?+
Anyone signed into your organization can view CBN clauses and their evidence register. Only members of that organization (with write access) can set clause status, add or edit notes, upload evidence, or remove artifacts. Actions are recorded per user, and shareable read-only report links (for CBN examiners or external auditors) never grant edit access.
Is the NIST 800-53 crosswalk part of CBN's official framework?+
No. The NIST 800-53 Rev 5 mapping is a third-party crosswalk from Open Security Architecture, not CBN's own numbering. It is exposed in a clearly labelled secondary tab of the CBN Framework browser for teams that also work in NIST. CBN's own Parts and clauses are always the primary view.
Do you also cover NDPA 2023?+
Yes. The Professional plan includes the Nigeria Data Protection Act 2023 module, so you can manage CBN localization, the wider CBN Cybersecurity Framework, and NDPA privacy obligations from one workspace.
How long does the assessment take?+
Most teams complete initial setup in 15 minutes and finish the 22-control assessment in a few working sessions. Walking the full 25-clause CBN Framework and attaching evidence per clause takes longer and is typically done alongside your annual CSAT preparation.

Start your CBN compliance assessment in 15 minutes.

No credit card required. Cancel anytime.