Security audits, penetration testing, and regulatory compliance for organizations operating in Nigeria, aligned with the NDPC, NITDA, and CBN frameworks.
Last updated — August 22, 2026
Nigeria has one of the more developed regulatory frameworks in Sub-Saharan Africa. Personal data protection is governed by the Nigeria Data Protection Act 2023 (NDPA), overseen by the Nigeria Data Protection Commission (NDPC). Information systems security is further addressed by the NITDA Framework, issued by the National Information Technology Development Agency. Financial institutions are additionally subject to the Central Bank of Nigeria's (CBN) Risk-Based Cybersecurity Framework, which imposes specific cyber risk management requirements.
Engagement mode
On-site missions in Lagos and Abuja, remote delivery elsewhere in the country
Working language
English, with deliverables available in French on request
Regulatory coordination
Dedicated contact for interactions with the NDPC, NITDA, and CBN
The Nigeria Data Protection Act 2023 (NDPA), enforced by the Nigeria Data Protection Commission (NDPC).
Yes, they must comply with the Central Bank of Nigeria's (CBN) Risk-Based Cybersecurity Framework, in addition to the NDPA.
It is required for processing activities that present a high risk to data subjects, as defined under the NDPA 2023.
The NDPA governs personal data protection; the NITDA Framework addresses information systems security more broadly, regardless of the type of data processed.
Yes, this sector is a priority given the requirements of the CBN Risk-Based Cybersecurity Framework and its associated risk level.
The NDPA 2023 sets specific notification timelines; we help you meet these deadlines from the moment an incident is detected.
Yes, as part of our governance, risk and compliance service, covering diagnosis and operational compliance.
Yes, technical engagements can be delivered remotely nationwide, with on-site visits as required by the mission.