For banks, fintechs and payment platforms in Rwanda, penetration testing is a regulatory requirement: the National Bank of Rwanda (BNR) mandates it for the institutions it supervises. Technology businesses outside financial services are increasingly asked for the same evidence of security due diligence by clients, partners and the National Cyber Security Authority (NCSA).
This guide explains what a penetration test is, who needs one in Rwanda, what BNR requires and what a test covers. It then sets out how to choose and vet a provider, what testing costs and what happens once the test is over.
What is penetration testing?
A penetration test (often called a pentest, and bought in regulated sectors as VAPT, vulnerability assessment and penetration testing) is a structured, authorised attempt to break into your systems the way a real attacker would. An automated scanner stops at a list of possible weaknesses. A skilled tester chains them together and pursues real business impact (accessing customer data, transferring funds, compromising internal accounts) to prove which vulnerabilities can be exploited.
The aim is to find the weaknesses before a real attacker does, without damaging your systems, then document them clearly and give you a prioritised remediation plan.
Penetration testing vs vulnerability scanning: An automated scanner checks for known vulnerabilities. A penetration test combines tools with human expertise to exploit those vulnerabilities and establish what an attacker could realistically achieve. For regulated industries in Rwanda, manual penetration testing is required. Automated scanning alone does not satisfy BNR requirements. Full comparison: penetration testing vs vulnerability scanning.
Who needs penetration testing in Rwanda?
The following organisations need regular penetration testing:
- BNR-regulated institutions: commercial banks, microfinance institutions (MFIs), insurance companies, pension funds, payment service providers, mobile money operators, electronic money issuers and savings and credit cooperatives (SACCOs), all explicitly required by BNR to conduct regular VAPT
- Government agencies and parastatals handling sensitive citizen data or critical services
- Telecom companies operating in Rwanda, regulated by the Rwanda Utilities Regulatory Authority (RURA)
- Healthcare organisations handling patient data
- E-commerce and SaaS companies that need to demonstrate security to enterprise clients
- Any business seeking ISO 27001 certification: Annex A requires technical vulnerability management, and penetration testing is the standard way to evidence it
What does BNR require?
BNR requires every supervised institution to maintain a formal cybersecurity programme, and penetration testing is an explicit part of it. BNR Regulation N° 50/2022 requires supervised financial institutions to run a penetration test at least annually and vulnerability assessments at least twice a year, conducted by testers holding recognised credentials (the regulation names six, OSCP among them). An executive summary of the findings is filed with the National Bank of Rwanda within 15 days of the test, and an annual statement of self-assessment is due by 15 January. Those are the written minimums. A testing programme that holds up at examination time also includes:
- Re-testing after significant changes to systems: good practice an examiner will recognise, though the regulation itself does not mandate it
- Coverage of all internet-facing systems: web applications, APIs, mobile banking platforms, USSD gateways, network perimeter
- A formal written report with findings ranked by severity and remediation guidance
- Evidence of remediation and re-testing
For institutions running mobile banking, payment processing or card systems, we recommend testing more frequently than the regulatory minimum. See our detailed breakdown: BNR cybersecurity requirements for banks in Rwanda.
Penetration testing and Rwanda's regulatory obligations
In Rwanda, penetration testing is rarely a standalone exercise. It supplies the evidence for three overlapping obligations, and the report you commission should be written to serve all three at once.
- BNR Regulation N° 50/2022. For BNR-supervised financial institutions, this is the binding requirement: a penetration test at least annually, vulnerability assessments at least twice a year, an executive summary of findings filed with the National Bank of Rwanda within 15 days of the test, and an annual statement of self-assessment due by 15 January. The report has to be structured so a supervisor can read it. See our BNR-compliant penetration testing service for how we map findings to the regulation.
- SWIFT Customer Security Programme (CSP). Any institution connected to SWIFT files an annual attestation against the Customer Security Controls Framework, and since 2021 every attestation has had to be supported by an independent assessment, carried out either by an independent internal function such as internal audit or by an external assessor. A penetration test of the SWIFT-connected environment (an advisory control, 7.3A) gives that assessment hands-on evidence that the mandatory controls work. See our SWIFT CSP assessment service.
- Data Protection Law N° 058/2021 and the NCSA. Rwanda's data protection law requires controllers and processors to put appropriate technical and organisational measures in place to protect personal data, and the NCSA sets expectations for organisations handling sensitive citizen data. A policy can describe those technical measures; a penetration test shows whether they work. See our NCSA and data protection compliance service.
A single, well-scoped engagement can produce evidence that addresses all three regimes, which is why scoping the test against your specific obligations matters more than buying a generic "annual pentest" off a price list.
What does a penetration test in Rwanda cover?
A complete penetration test for a Rwandan financial institution typically covers the areas below.
External network and perimeter testing
All internet-facing assets are mapped and tested. This includes web servers, API endpoints, remote access systems (VPN, RDP), email infrastructure and any other service reachable from the internet. We identify misconfigurations, unpatched software and exploitable entry points that an external attacker would use.
Web application penetration testing
Your core banking interface, customer portal, admin panels and other web applications are tested against the OWASP Top 10 and beyond (see our web application penetration testing service for scope and deliverables). That covers SQL injection, broken authentication, insecure direct object references (IDOR), cross-site scripting (XSS) and business logic flaws, among others. Web applications are consistently the most common source of significant findings.
API security testing
Modern banking systems expose a large number of APIs, serving mobile apps, third-party integrations and internal services. These are tested for authentication weaknesses, authorisation bypass, Broken Object Property Level Authorization and the rest of the OWASP API Security Top 10 (2023). See API security in modern banking for common findings.
Mobile application testing (Android and iOS)
Your mobile banking app is tested on both platforms, as set out on our mobile application penetration testing page. We examine client-side storage of sensitive data, certificate pinning, runtime manipulation and deep-link vulnerabilities. Attackers often use the app as a launchpad against the backend APIs. See why your mobile banking app needs a security assessment.
USSD and mobile money testing
For operators running USSD services or mobile money platforms (MTN MoMo, Airtel Money), our team tests session handling, transaction flow manipulation and enumeration attacks. This attack surface is often left out of testing scopes entirely; our methodology covers it in depth. See our USSD security testing guide.
Internal network penetration testing
Our team simulates a scenario where an attacker has already gained internal access (through a phishing email, a compromised workstation or physical intrusion) and tests for lateral movement, privilege escalation and access to critical systems and data.
The human attack surface
Phishing, vishing and pretext-based manipulation remain among the leading causes of security incidents across African institutions, and no amount of technical hardening removes that risk entirely. The most reliable way to lower it over time is sustained staff awareness training that teaches employees to recognise the manipulation patterns attackers use in practice. See our security awareness training service, or IMIZI Aware for recurring, measured phishing simulation.
How to choose a penetration testing company in Rwanda
Providers differ widely in who does the testing and what they deliver. For a detailed guide to evaluating providers in Kigali, including red flags and scoping questions, see our enterprise guide to choosing a penetration testing firm. The factors below matter most.
Verified certifications
The most important thing to verify is whether the person who will test your systems holds a recognised offensive-security certification. A widely used benchmark of hands-on skill is OSCP (Offensive Security Certified Professional), a practical exam in which the candidate must compromise machines under strict exam conditions. For BNR-regulated work, check that the tester holds one of the six certifications Regulation N° 50/2022 names (CISSP, CISM, CISA, CEH, OSCP, LPT) or a similar one, and ask for a sample report to see how that knowledge translates into testing.
Experience with financial institutions
Testing a bank is different from testing an e-commerce website. Banking systems have complex transaction flows, regulatory sensitivities and attack surfaces of their own, such as core banking systems, USSD gateways and SWIFT connections. Ask specifically about the provider's experience with banks and fintechs in the region.
Local presence in Rwanda
For engagements that include on-site testing, internal network assessment or physical-access review, having a team physically located in Kigali matters. If a provider is remote, ask how the on-site phases will be handled and what travel adds to the cost.
Clear methodology and deliverables
Ask for a sample report. A good penetration test report includes an executive summary written for leadership as well as technical staff, technical findings with proof-of-concept screenshots, severity ratings (CVSS or equivalent) and specific remediation guidance your IT team can implement, rather than generic advice.
NDA and engagement agreement
A professional provider will always put a signed Rules of Engagement document and a non-disclosure agreement (NDA) in place before testing begins. Together they define the scope, protect your business and establish the legal authority for the test. Never work with a provider who starts testing without a signed agreement.
A scoping call before any quote
A penetration test cannot be priced properly without first understanding what is in scope: how many applications and APIs, whether mobile and USSD are included, whether internal network testing is needed and which compliance report the result has to satisfy. A scoping call before any quote is the baseline. If a fixed number arrives within minutes of first contact, ask what it covers.
Warning signs
- A quote with no scoping call. Pricing follows scope, so a number produced before anyone has asked about your systems is a guess.
- "Penetration tests" that are scanner exports. If the deliverable is an unedited Nessus or Acunetix export with no manual validation, no chained exploitation and no business-impact narrative, it is a vulnerability scan being sold as a pentest, and it will not satisfy BNR.
Questions to ask any provider
Whatever kind of firm you are talking to (a local specialist, a regional firm, a generalist IT or risk-and-compliance practice, or an international vendor), verify rather than assume. Every row below is a question worth putting to each bidder, including us.
| Selection criterion | What to ask | What a good answer looks like |
|---|---|---|
| Presence and on-site capability | Where is the team based, and how are on-site phases handled? | A clear plan for any internal or on-site work, with travel costs stated up front |
| Tester credentials | Who will perform the test, and which certification do they hold? | Named individuals with verifiable certification IDs; for BNR work, one of the credentials Article 10 names |
| Manual depth | What share of the effort is manual, and how are business-logic flaws found? | A specific answer, backed by a redacted sample report showing chained exploitation |
| BNR / SWIFT / NCSA fluency | How will the report support the 15-day BNR filing and other obligations? | An executive summary a supervisor can read, with findings mapped to the relevant framework |
| Scoped quoting | What do you need to know before you price this? | A scoping call before any number, then a fixed-price proposal |
What certifications should your pentest provider hold?
Each certification signals something different for engagements in Rwanda:
- OSCP (Offensive Security Certified Professional): a widely used hands-on benchmark, and one of the six certifications BNR Regulation N° 50/2022 names. The practical exam shows the tester can compromise live systems under exam conditions.
- OSEP, OSED and OSWE: advanced Offensive Security certifications in evasion, exploit development and web application exploitation.
- CEH (Certified Ethical Hacker): knowledge-based and widely recognised; one of the six certifications BNR names.
- CREST membership: awarded by a UK-based professional body that sets high standards for penetration testing.
- CISSP, CISM, CISA and LPT: the other certifications BNR names. CISSP, CISM and CISA lean towards governance, management and audit; LPT towards hands-on testing.
IMIZI Cyber tests under recognised offensive-security methodology. Our testing is led by an OSCP-credentialled practitioner, with reporting structured for BNR-aligned engagements. We are based in Kigali and can conduct on-site testing when required.
How long does a penetration test take, and what does it cost?
Timelines depend on scope. Typical durations:
- Web application test (single app): 3 to 5 business days of testing
- API security assessment: 2 to 4 business days
- Mobile app test (one platform): 3 to 5 business days
- Full external, web and mobile package: 7 to 12 business days
- Full-scope enterprise engagement (external, web, mobile, API, internal network): 2 to 4 weeks
Pricing is set for your environment. We scope the engagement on a call, send a fixed-price proposal and deliver within an agreed timeline, with payment per milestone on acceptance. Our guide to penetration testing costs in Rwanda explains the factors that drive the price.
After the test: report, debrief, remediation
The deliverable is a formal written report, issued within 5 to 7 business days of the end of testing. A good report contains:
- Executive summary: suitable for board presentation, covering overall risk posture and key findings in plain language
- Technical findings: each vulnerability documented with description, severity (Critical/High/Medium/Low), proof-of-concept screenshots, business impact and step-by-step remediation guidance
- Risk heat map: visual overview of findings by severity and affected system
- Remediation roadmap: prioritised action plan
After the report is delivered, we conduct a debrief call with your technical team to walk through findings and answer questions. Once remediation is complete, we re-test to verify the fixes. One re-test round is included in every engagement: every Critical and High finding, plus any Medium fixed by the re-test date, followed by a closure letter. Further rounds are billed at the day rate.
For how a penetration test and a vulnerability assessment differ for regulated institutions, see our guide on penetration testing versus vulnerability scanning and assessment.
Get started
IMIZI Cyber is a Kigali-based firm providing manual, evidence-led penetration testing for banks, fintechs, telecoms, government and healthcare institutions across Africa, with reporting structured for BNR-aligned engagements.
For full details on our methodology, deliverables and engagement process, see our penetration testing service page. For broader needs such as compliance gap analysis, see our security assessments service page. When you are ready to scope an engagement, contact us and we will send a fixed-price proposal within 48 hours of the scoping call.