BNR-compliant penetration testing for Rwanda's financial institutions

BNR Regulation N°50/2022 requires every supervised financial institution to run a penetration test at least once a year and vulnerability assessments at least twice a year, and to file the results with the National Bank of Rwanda. We deliver the manual, evidence-led testing and the report your examiner expects: led by an OSCP-credentialled practitioner, the credential the regulation itself names.

Aligned to: BNR Regulation N°50/2022 | OSCP-credentialled practitioner | Annual pentest + bi-annual VA | Evidence-led, file-ready reporting

What the regulation requires

01

Annual penetration test

A manual penetration test at least once a year. That is the regulation's floor; many institutions also test after major system changes as good practice.

02

Bi-annual vulnerability assessments

Vulnerability assessments at least twice a year across your internet-facing and internal systems.

03

A qualified tester

The regulation names recognised offensive-security credentials, OSCP among them. Our testing is led by an OSCP-credentialled practitioner.

04

Results filed with BNR

An executive summary of findings filed with the National Bank of Rwanda within 15 days of the test, and an annual self-attestation due by 15 January.

What BNR Regulation N°50/2022 requires

BNR Regulation N°50/2022 on cyber security sets the testing obligations for institutions supervised by the National Bank of Rwanda. Two requirements drive your testing calendar: a penetration test at least once a year and vulnerability assessments at least twice a year. The regulation also expects the tester to hold recognised offensive-security credentials, and it names OSCP among them. Re-testing after a major change to your infrastructure or applications is not a BNR mandate, but it is sound practice for the systems that carry your customer funds.

The obligation does not end at the test. An executive summary of the findings is filed with the BNR within 15 days of the test, and supervised institutions submit an annual self-attestation by 15 January. A report that is technically thin, or that a scanner produced, is what gets a programme flagged at examination time.

Who this is for

The testing and reporting obligations apply to institutions licensed or supervised by the National Bank of Rwanda:

If the BNR licenses or supervises you, the annual penetration test and bi-annual vulnerability assessment obligations apply to your environment.

What we deliver

We run the engagement by hand, not as a repackaged scanner report, and we structure the output so it files cleanly with your regulator:

Why the OSCP credential matters here

Most regulations ask for "qualified" testers without saying what that means. BNR Regulation N°50/2022 is more specific: it names recognised offensive-security credentials, and OSCP is on that list. Our testing is led by an OSCP-credentialled practitioner with red-team and penetration-testing experience inside a Tier-1 Nordic bank and across pan-African banking, so the tester your examiner asks about meets the credential the regulation calls for. For the detail behind those obligations, see our guide to BNR cybersecurity requirements for banks in Rwanda and our BNR audit preparation guide.

How an engagement runs

Scoping

We map your in-scope systems against what the regulation expects and agree rules of engagement, timeline, and the filing deadline you are working to.

Testing

Manual penetration testing and vulnerability assessment by hand, with clear communication and immediate escalation of anything critical.

Reporting

An evidence-led report structured to file with the BNR: executive summary, technical findings, CVSS ratings, and prioritised remediation.

Retest & file

Free retest on remediated findings and a clean report for your 15-day filing and your 15 January self-attestation.

Frequently asked questions

Does BNR require penetration testing?
Yes. BNR Regulation N°50/2022 requires every supervised financial institution to run a penetration test at least once a year and vulnerability assessments at least twice a year. An executive summary of the findings is filed with the National Bank of Rwanda within 15 days of the test, and an annual self-attestation is due by 15 January.
How often must a Rwandan bank run a penetration test?
At minimum once a year, plus a vulnerability assessment at least every six months. That is the floor the regulation sets; testing again after a major infrastructure or application change is good practice rather than a BNR mandate, and many institutions test critical systems such as internet banking, mobile banking, and payment APIs more frequently.
What tester credential does BNR Regulation N°50/2022 require?
The regulation lists recognised offensive-security credentials a qualifying tester may hold, and OSCP (Offensive Security Certified Professional) is named among them. Our testing is led by an OSCP-credentialled practitioner, so your examiner can see the tester meets the credential the regulation calls for. Individual credentials are on our about page.
Who must comply with BNR Regulation N°50/2022?
Institutions licensed or supervised by the National Bank of Rwanda: commercial banks, deposit-taking microfinance institutions, and payment service providers. If the BNR licenses or supervises you, the testing and reporting obligations apply.
Do you provide the report our BNR examiner needs?
Yes. Every engagement produces an evidence-led report: an executive summary, technical findings with proof-of-concept evidence and CVSS ratings, prioritised remediation guidance, and a clean retest report after you fix the findings. The package is structured to file with the BNR and to hand to your auditor.
How much does a BNR-compliant penetration test cost in Rwanda?
Every engagement is scoped individually based on the systems in scope, infrastructure complexity, and testing depth. Tell us your environment and the deadline you are working to, we reply within 24 hours, and a scoped proposal follows within 48 hours of the scoping call. For the factors that drive pricing, see our guide to penetration testing cost in Rwanda.

For the full scope of our manual testing across web, network, mobile, API, and cloud, see our penetration testing service, or read the cornerstone guide to penetration testing in Rwanda.

Working to other regulatory deadlines? See our SWIFT CSP independent assessment service for banks on the SWIFT network, and our NCSA & Law 058/2021 security testing service for data-protection compliance across government, healthcare, and telecom.

Working to a BNR deadline?

Tell us your in-scope systems and the date you are filing toward. We reply within 24 hours, and a scoped proposal follows within 48 hours of the scoping call.

Chat on WhatsApp Chat with us