Penetration testing in Rwanda: a buyer and compliance guide (2026)

On this page

For banks, fintechs and payment platforms in Rwanda, penetration testing is a regulatory requirement: the National Bank of Rwanda (BNR) mandates it for the institutions it supervises. Technology businesses outside financial services are increasingly asked for the same evidence of security due diligence by clients, partners and the National Cyber Security Authority (NCSA).

This guide explains what a penetration test is, who needs one in Rwanda, what BNR requires and what a test covers. It then sets out how to choose and vet a provider, what testing costs and what happens once the test is over.

What is penetration testing?

A penetration test (often called a pentest, and bought in regulated sectors as VAPT, vulnerability assessment and penetration testing) is a structured, authorised attempt to break into your systems the way a real attacker would. An automated scanner stops at a list of possible weaknesses. A skilled tester chains them together and pursues real business impact (accessing customer data, transferring funds, compromising internal accounts) to prove which vulnerabilities can be exploited.

The aim is to find the weaknesses before a real attacker does, without damaging your systems, then document them clearly and give you a prioritised remediation plan.

Penetration testing vs vulnerability scanning: An automated scanner checks for known vulnerabilities. A penetration test combines tools with human expertise to exploit those vulnerabilities and establish what an attacker could realistically achieve. For regulated industries in Rwanda, manual penetration testing is required. Automated scanning alone does not satisfy BNR requirements. Full comparison: penetration testing vs vulnerability scanning.

Who needs penetration testing in Rwanda?

The following organisations need regular penetration testing:

  • BNR-regulated institutions: commercial banks, microfinance institutions (MFIs), insurance companies, pension funds, payment service providers, mobile money operators, electronic money issuers and savings and credit cooperatives (SACCOs), all explicitly required by BNR to conduct regular VAPT
  • Government agencies and parastatals handling sensitive citizen data or critical services
  • Telecom companies operating in Rwanda, regulated by the Rwanda Utilities Regulatory Authority (RURA)
  • Healthcare organisations handling patient data
  • E-commerce and SaaS companies that need to demonstrate security to enterprise clients
  • Any business seeking ISO 27001 certification: Annex A requires technical vulnerability management, and penetration testing is the standard way to evidence it

What does BNR require?

BNR requires every supervised institution to maintain a formal cybersecurity programme, and penetration testing is an explicit part of it. BNR Regulation N° 50/2022 requires supervised financial institutions to run a penetration test at least annually and vulnerability assessments at least twice a year, conducted by testers holding recognised credentials (the regulation names six, OSCP among them). An executive summary of the findings is filed with the National Bank of Rwanda within 15 days of the test, and an annual statement of self-assessment is due by 15 January. Those are the written minimums. A testing programme that holds up at examination time also includes:

  • Re-testing after significant changes to systems: good practice an examiner will recognise, though the regulation itself does not mandate it
  • Coverage of all internet-facing systems: web applications, APIs, mobile banking platforms, USSD gateways, network perimeter
  • A formal written report with findings ranked by severity and remediation guidance
  • Evidence of remediation and re-testing

For institutions running mobile banking, payment processing or card systems, we recommend testing more frequently than the regulatory minimum. See our detailed breakdown: BNR cybersecurity requirements for banks in Rwanda.

Penetration testing and Rwanda's regulatory obligations

In Rwanda, penetration testing is rarely a standalone exercise. It supplies the evidence for three overlapping obligations, and the report you commission should be written to serve all three at once.

  • BNR Regulation N° 50/2022. For BNR-supervised financial institutions, this is the binding requirement: a penetration test at least annually, vulnerability assessments at least twice a year, an executive summary of findings filed with the National Bank of Rwanda within 15 days of the test, and an annual statement of self-assessment due by 15 January. The report has to be structured so a supervisor can read it. See our BNR-compliant penetration testing service for how we map findings to the regulation.
  • SWIFT Customer Security Programme (CSP). Any institution connected to SWIFT files an annual attestation against the Customer Security Controls Framework, and since 2021 every attestation has had to be supported by an independent assessment, carried out either by an independent internal function such as internal audit or by an external assessor. A penetration test of the SWIFT-connected environment (an advisory control, 7.3A) gives that assessment hands-on evidence that the mandatory controls work. See our SWIFT CSP assessment service.
  • Data Protection Law N° 058/2021 and the NCSA. Rwanda's data protection law requires controllers and processors to put appropriate technical and organisational measures in place to protect personal data, and the NCSA sets expectations for organisations handling sensitive citizen data. A policy can describe those technical measures; a penetration test shows whether they work. See our NCSA and data protection compliance service.

A single, well-scoped engagement can produce evidence that addresses all three regimes, which is why scoping the test against your specific obligations matters more than buying a generic "annual pentest" off a price list.

What does a penetration test in Rwanda cover?

A complete penetration test for a Rwandan financial institution typically covers the areas below.

External network and perimeter testing

All internet-facing assets are mapped and tested. This includes web servers, API endpoints, remote access systems (VPN, RDP), email infrastructure and any other service reachable from the internet. We identify misconfigurations, unpatched software and exploitable entry points that an external attacker would use.

Web application penetration testing

Your core banking interface, customer portal, admin panels and other web applications are tested against the OWASP Top 10 and beyond (see our web application penetration testing service for scope and deliverables). That covers SQL injection, broken authentication, insecure direct object references (IDOR), cross-site scripting (XSS) and business logic flaws, among others. Web applications are consistently the most common source of significant findings.

API security testing

Modern banking systems expose a large number of APIs, serving mobile apps, third-party integrations and internal services. These are tested for authentication weaknesses, authorisation bypass, Broken Object Property Level Authorization and the rest of the OWASP API Security Top 10 (2023). See API security in modern banking for common findings.

Mobile application testing (Android and iOS)

Your mobile banking app is tested on both platforms, as set out on our mobile application penetration testing page. We examine client-side storage of sensitive data, certificate pinning, runtime manipulation and deep-link vulnerabilities. Attackers often use the app as a launchpad against the backend APIs. See why your mobile banking app needs a security assessment.

USSD and mobile money testing

For operators running USSD services or mobile money platforms (MTN MoMo, Airtel Money), our team tests session handling, transaction flow manipulation and enumeration attacks. This attack surface is often left out of testing scopes entirely; our methodology covers it in depth. See our USSD security testing guide.

Internal network penetration testing

Our team simulates a scenario where an attacker has already gained internal access (through a phishing email, a compromised workstation or physical intrusion) and tests for lateral movement, privilege escalation and access to critical systems and data.

The human attack surface

Phishing, vishing and pretext-based manipulation remain among the leading causes of security incidents across African institutions, and no amount of technical hardening removes that risk entirely. The most reliable way to lower it over time is sustained staff awareness training that teaches employees to recognise the manipulation patterns attackers use in practice. See our security awareness training service, or IMIZI Aware for recurring, measured phishing simulation.

How to choose a penetration testing company in Rwanda

Providers differ widely in who does the testing and what they deliver. For a detailed guide to evaluating providers in Kigali, including red flags and scoping questions, see our enterprise guide to choosing a penetration testing firm. The factors below matter most.

Verified certifications

The most important thing to verify is whether the person who will test your systems holds a recognised offensive-security certification. A widely used benchmark of hands-on skill is OSCP (Offensive Security Certified Professional), a practical exam in which the candidate must compromise machines under strict exam conditions. For BNR-regulated work, check that the tester holds one of the six certifications Regulation N° 50/2022 names (CISSP, CISM, CISA, CEH, OSCP, LPT) or a similar one, and ask for a sample report to see how that knowledge translates into testing.

Experience with financial institutions

Testing a bank is different from testing an e-commerce website. Banking systems have complex transaction flows, regulatory sensitivities and attack surfaces of their own, such as core banking systems, USSD gateways and SWIFT connections. Ask specifically about the provider's experience with banks and fintechs in the region.

Local presence in Rwanda

For engagements that include on-site testing, internal network assessment or physical-access review, having a team physically located in Kigali matters. If a provider is remote, ask how the on-site phases will be handled and what travel adds to the cost.

Clear methodology and deliverables

Ask for a sample report. A good penetration test report includes an executive summary written for leadership as well as technical staff, technical findings with proof-of-concept screenshots, severity ratings (CVSS or equivalent) and specific remediation guidance your IT team can implement, rather than generic advice.

NDA and engagement agreement

A professional provider will always put a signed Rules of Engagement document and a non-disclosure agreement (NDA) in place before testing begins. Together they define the scope, protect your business and establish the legal authority for the test. Never work with a provider who starts testing without a signed agreement.

A scoping call before any quote

A penetration test cannot be priced properly without first understanding what is in scope: how many applications and APIs, whether mobile and USSD are included, whether internal network testing is needed and which compliance report the result has to satisfy. A scoping call before any quote is the baseline. If a fixed number arrives within minutes of first contact, ask what it covers.

Warning signs

  • A quote with no scoping call. Pricing follows scope, so a number produced before anyone has asked about your systems is a guess.
  • "Penetration tests" that are scanner exports. If the deliverable is an unedited Nessus or Acunetix export with no manual validation, no chained exploitation and no business-impact narrative, it is a vulnerability scan being sold as a pentest, and it will not satisfy BNR.

Questions to ask any provider

Whatever kind of firm you are talking to (a local specialist, a regional firm, a generalist IT or risk-and-compliance practice, or an international vendor), verify rather than assume. Every row below is a question worth putting to each bidder, including us.

Selection criterionWhat to askWhat a good answer looks like
Presence and on-site capabilityWhere is the team based, and how are on-site phases handled?A clear plan for any internal or on-site work, with travel costs stated up front
Tester credentialsWho will perform the test, and which certification do they hold?

Named individuals with verifiable certification IDs; for BNR work, one of the credentials Article 10 names

Manual depthWhat share of the effort is manual, and how are business-logic flaws found?A specific answer, backed by a redacted sample report showing chained exploitation
BNR / SWIFT / NCSA fluencyHow will the report support the 15-day BNR filing and other obligations?

An executive summary a supervisor can read, with findings mapped to the relevant framework

Scoped quotingWhat do you need to know before you price this?A scoping call before any number, then a fixed-price proposal

What certifications should your pentest provider hold?

Each certification signals something different for engagements in Rwanda:

  • OSCP (Offensive Security Certified Professional): a widely used hands-on benchmark, and one of the six certifications BNR Regulation N° 50/2022 names. The practical exam shows the tester can compromise live systems under exam conditions.
  • OSEP, OSED and OSWE: advanced Offensive Security certifications in evasion, exploit development and web application exploitation.
  • CEH (Certified Ethical Hacker): knowledge-based and widely recognised; one of the six certifications BNR names.
  • CREST membership: awarded by a UK-based professional body that sets high standards for penetration testing.
  • CISSP, CISM, CISA and LPT: the other certifications BNR names. CISSP, CISM and CISA lean towards governance, management and audit; LPT towards hands-on testing.

IMIZI Cyber tests under recognised offensive-security methodology. Our testing is led by an OSCP-credentialled practitioner, with reporting structured for BNR-aligned engagements. We are based in Kigali and can conduct on-site testing when required.

How long does a penetration test take, and what does it cost?

Timelines depend on scope. Typical durations:

  • Web application test (single app): 3 to 5 business days of testing
  • API security assessment: 2 to 4 business days
  • Mobile app test (one platform): 3 to 5 business days
  • Full external, web and mobile package: 7 to 12 business days
  • Full-scope enterprise engagement (external, web, mobile, API, internal network): 2 to 4 weeks

Pricing is set for your environment. We scope the engagement on a call, send a fixed-price proposal and deliver within an agreed timeline, with payment per milestone on acceptance. Our guide to penetration testing costs in Rwanda explains the factors that drive the price.

After the test: report, debrief, remediation

The deliverable is a formal written report, issued within 5 to 7 business days of the end of testing. A good report contains:

  • Executive summary: suitable for board presentation, covering overall risk posture and key findings in plain language
  • Technical findings: each vulnerability documented with description, severity (Critical/High/Medium/Low), proof-of-concept screenshots, business impact and step-by-step remediation guidance
  • Risk heat map: visual overview of findings by severity and affected system
  • Remediation roadmap: prioritised action plan

After the report is delivered, we conduct a debrief call with your technical team to walk through findings and answer questions. Once remediation is complete, we re-test to verify the fixes. One re-test round is included in every engagement: every Critical and High finding, plus any Medium fixed by the re-test date, followed by a closure letter. Further rounds are billed at the day rate.

For how a penetration test and a vulnerability assessment differ for regulated institutions, see our guide on penetration testing versus vulnerability scanning and assessment.

Get started

IMIZI Cyber is a Kigali-based firm providing manual, evidence-led penetration testing for banks, fintechs, telecoms, government and healthcare institutions across Africa, with reporting structured for BNR-aligned engagements.

For full details on our methodology, deliverables and engagement process, see our penetration testing service page. For broader needs such as compliance gap analysis, see our security assessments service page. When you are ready to scope an engagement, contact us and we will send a fixed-price proposal within 48 hours of the scoping call.

Frequently asked questions

Who is required to do penetration testing in Rwanda?
Under Regulation N° 50/2022, the National Bank of Rwanda (BNR) requires every financial institution it supervises, including commercial banks, microfinance institutions, insurance companies, payment service providers and mobile money operators, to run a penetration test at least annually and vulnerability assessments at least twice a year.
Which companies provide penetration testing in Rwanda?
Providers in Rwanda fall into four groups: the global audit and consulting firms, regional security firms headquartered in Kenya or South Africa, Kigali-based specialist firms such as IMIZI Cyber, and independent freelancers. For a BNR-supervised institution the useful questions are the same for all of them: which certified individual will do the testing, whether the report is structured for filing with the BNR, how each finding is evidenced, and whether a re-test of your fixes is included.
How do I choose a penetration testing provider in Rwanda?
Verify that the person doing the testing holds a recognised offensive-security credential (OSCP, PNPT or CREST), ask for named experience inside banks or other regulated environments, confirm the work is manual testing rather than a repackaged scanner report, and require a BNR-fileable report with a re-test round included. Insist on a scoping call before any quote: a price given without one, or a "penetration test" that turns out to be a scanner export, is a red flag.
How much does a penetration test cost in Rwanda?
Each engagement is priced individually, according to the number of systems, the complexity of the applications and the depth of testing. Contact us and we will send a fixed-price proposal within 48 hours of the scoping call.
How long does a penetration test take in Rwanda?
A focused web application penetration test typically takes 3 to 5 business days of testing. A full-scope engagement covering network, web applications and mobile can take 2 to 4 weeks from kickoff to final report.
Will the penetration test disrupt our systems?
A properly scoped penetration test should not cause outages. We test against a scope agreed in advance, avoid denial-of-service techniques unless you explicitly approve them, and can work outside business hours on critical systems. Production safety shapes how we plan and run every engagement.
Can we do a penetration test on a test or staging environment?
Yes. Where production testing carries operational risk, we often recommend testing a staging environment first. Production testing is more realistic, though, because it exercises what staging usually lacks: real transaction data and live integrations.
Do we need a penetration test if we already had a vulnerability assessment?
Yes. A vulnerability assessment uses scanning to identify known vulnerabilities. A penetration test proves which of them are exploitable and finds what scanners miss, such as business logic flaws, authentication weaknesses and chained vulnerabilities. BNR, like most compliance frameworks, requires penetration testing in its own right; a vulnerability scan does not satisfy that requirement.
How often should we conduct penetration tests?
At minimum, annually. For BNR-supervised institutions, Regulation N° 50/2022 sets the floor at an annual penetration test plus vulnerability assessments at least twice a year. Beyond that floor, testing after significant system changes and before major regulatory inspections is good practice, and quarterly testing is best practice for payment systems and mobile banking.

This article is general information, not legal advice. Check the current text of any regulation with your counsel or regulator.

Talk to us about your next test

IMIZI Cyber is a Kigali-based penetration testing firm working with banks, fintechs and regulated institutions across Africa. Our testing is led by an OSCP-credentialled practitioner. After a free scoping call, you get a fixed-price proposal within 48 hours.