BNR cybersecurity compliance now has a single binding reference point: Regulation N° 50/2022 on Cyber Security in Regulated Institutions, which repealed the 2018 cyber security regulation and applies to every institution the National Bank of Rwanda licenses and supervises. For compliance officers and CISOs at Rwandan banks, microfinance institutions, insurers and fintechs, the requirements are settled. The work in 2026 is meeting them efficiently and proving it when examiners arrive.
This guide is built around the dates that anchor the 2026 compliance year: the annual penetration test and twice-yearly vulnerability assessments that Article 10 mandates, the 15-day executive summary filing after each test, the 15 January statement of self-assessment, and the ICT risk management groundwork behind them. For a short orientation on who is covered and what each obligation involves, start with our BNR cybersecurity requirements explained overview.
BNR ICT risk management framework
BNR expects every supervised institution to operate a formal ICT risk management framework. A framework that sits in a drawer does not count: examiners look for evidence that it is in use, reviewed on a schedule, and actually governs how the institution manages technology risk.
Board-level accountability is the starting point. Regulation N° 50/2022 places cybersecurity governance with the board of directors and senior management. The board approves the cybersecurity policy and receives regular reports on cyber risk: the CISO or IT risk officer should present at least quarterly on current threats, the status of controls, the results of recent assessments and any incidents. Board minutes should show that these discussions happened and that directors asked substantive questions. A board that rubber-stamps IT reports is a finding waiting to happen.
ICT governance structure must set out roles and responsibilities: who owns cybersecurity policy, who leads incident response, and who approves changes to critical systems. BNR expects a separation of duties between the people who develop and operate systems and the people who oversee security. In practice, your IT security function should not report directly to the head of IT operations, because the team that runs a system should not also be the one that signs off its security.
Risk assessment is a continuing process. BNR expects institutions to keep a current register of ICT assets, identify the threats and vulnerabilities affecting those assets, assess the likelihood and impact of compromise, and apply controls proportionate to the risk. Review the register at least annually and update it whenever something significant changes: new systems, new services, organisational restructuring or a shift in the threat environment.
Who is covered: Regulation N° 50/2022 applies to every institution BNR licenses and supervises, from Tier-1 commercial banks to deposit-taking microfinance institutions. Article 24 allows the Supervisory Authority to adjust requirements by directive in proportion to an institution's nature, size, complexity and maturity. Unless such a directive exists, the regulation as written is the obligation.
Penetration testing and vulnerability assessment mandates
Article 10 of Regulation N° 50/2022 is the most concrete and verifiable requirement in the regulation, and it is where examiners can quickly tell whether an institution takes cybersecurity seriously.
Frequency: the regulation requires a penetration test at least once a year and vulnerability assessments at least twice a year. Those are minimums. Institutions that run mobile banking platforms, payment processing, card services or internet banking would be prudent to test more often. Re-testing after a major system change (a new application, an infrastructure migration, a significant architectural change) is standard practice, even though the regulation does not spell it out.
Filing deadlines: two dates anchor the compliance calendar. An executive summary of the test findings must be shared with the National Bank of Rwanda within 15 days of the test, and a written statement of self-assessment certifying that the cybersecurity programme complies with the regulation is due by 15 January each year (Article 22). An institution that tests on time but files late has still missed the requirement.
Scope: testing must cover internet-facing systems: web applications, APIs, mobile banking apps, USSD gateways, email infrastructure, VPN endpoints and any other service reachable from the internet. Institutions with complex IT environments are also expected to test their internal network. Examiners look for evidence that the scope covered the whole attack surface, rather than one application tested while the rest was left alone.
Tester qualifications: Article 10 requires anyone entrusted with a penetration test or vulnerability assessment to hold at least one recognised qualification, and it names six: CISSP, CISM, CISA, CEH, OSCP (Offensive Security Certified Professional) and LPT, plus "any other similar certification". The regulation does not force you to hire an external firm, but whoever performs the work must hold a listed qualification, and a scanner export run by uncertified staff is not a penetration test. For how to evaluate providers against this bar, see our guide on choosing a penetration testing firm in Kigali.
Remediation evidence: finding vulnerabilities is half the job. Article 10 sets the testing cadence; it does not itself require a re-test. An examiner who reads the report will still ask what happened to the findings, and the most convincing answer is remediation verified by a re-test, which is good practice rather than a BNR mandate. A penetration test report from two years ago with critical findings still open is worse than no report at all, because it proves the institution knew about the risk and did nothing.
Preparing for a BNR examination
BNR examinations assess both documentation and operational reality. Policies on paper are necessary but not sufficient: examiners ask for evidence that controls work, that monitoring is active, and that the institution has exercised its incident response plan as well as written one.
Our BNR cybersecurity requirements guide covers examination preparation in full. Use it for:
- The 90-day preparation timeline: what to do at 90, 60 and 30 days out, from gap assessment through remediation to assembling the documentation.
- The evidence checklist: every document an examiner can reasonably request, from the board-approved policy to re-test reports and vendor risk assessments.
- The six most common deficiencies: the findings that recur in examinations (no current penetration test report, unremediated criticals, untested incident response plans, thin board minutes, shared administrator credentials, no vendor risk programme) and how to close each one before an examiner finds it.
If your examination date is already set, start there. The rest of this post stays with what the regulation requires; the preparation section of that guide covers how to prove it.
Technical vulnerabilities an Article 10 test should surface
A penetration test that meets the Article 10 bar should go well beyond scanner output. Our lead tester's earlier financial-sector work, which includes red team work for a Tier-1 Nordic bank and engagements for a pan-African banking group, turned up the same classes of vulnerability again and again in banking environments:
- Insecure direct object references (IDOR) in banking APIs, allowing access to other customers' data by changing a parameter
- Weak or missing authentication on internal APIs that backend systems rely on
- USSD session-handling vulnerabilities that enable session hijacking or transaction replay
- Default credentials on network equipment such as routers, switches and firewalls
- Missing security headers and TLS misconfigurations on internet-facing applications
- Insufficient input validation leading to injection attacks on web and API endpoints
A qualified manual test exists to uncover findings like these. An institution commissioning its first thorough vulnerability assessment and penetration testing (VAPT) engagement should expect a meaningful number of findings. That means the assessment worked.
How we can help
IMIZI Cyber is a Kigali-based offensive-security firm serving regulated institutions across Africa. We help BNR-supervised institutions meet the Article 10 mandate with manual penetration testing and vulnerability assessments led by an OSCP-credentialled practitioner (OSCP is one of the six qualifications the regulation names). Our reports are structured for regulatory examination, with findings, remediation guidance and re-test evidence set out in the form an examiner expects, and the executive summary ready for the 15-day filing.
For scope and deliverables aligned to the regulation, see our BNR-compliant penetration testing service page. For the broader assessment methodology, see security assessments. For context on penetration testing in this market, our complete guide to penetration testing in Rwanda covers providers, costs and credentials.
To discuss your compliance timeline, Book a Free Call. We scope engagements to fit your examination schedule.