Law / Nigeria

Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, Reporting of Cyber Threats to the National CERT

Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, section 21, Reporting of Cyber Threats

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A vulnerability and incident reporting rule binding public and private bodies.

As of 17 September 2026.

What it requires

  • This binds any person or institution, whether public or private, that operates a computer system or a network in Nigeria; there is no sector or size gate.
  • Immediately inform the National Computer Emergency Response Team (CERT) Coordination Center of any attack, intrusion, or other disruption liable to hinder the functioning of another computer system or network.
  • Report the incident to the National CERT within 7 days of its occurrence. Failing to do so is itself an offence, punishable by denial of internet services and a mandatory fine of N2,000,000 payable into the National Cyber Security Fund.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Failing to report a qualifying incident to the National CERT within 7 days is itself described as an offence, but section 21(3) states only denial of internet services plus a mandatory fine of N2,000,000; no term of imprisonment is stated for this specific offence.

Penalty structure

Section 21(3)'s fixed fine for failing to report a qualifying incident to the National CERT within 7 days of its occurrence, payable into the National Cyber Security Fund. The same subsection separately imposes denial of internet services, a non-monetary sanction this fixed_cap figure does not capture.

Rule
Fixed only
As of
17 September 2026
Currency
NGN
Fixed cap
2,000,000

Who enforces it

Enforcement body

Office of the National Security Adviser (ONSA), the Act's own coordinating body for all security and enforcement agencies under it; the National Computer Emergency Response Team (CERT) Coordination Center is the reporting recipient named in section 21 itself.

What it reaches

Obligation class

Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 21 of the Cybercrimes (Prohibition, Prevention, etc.) Act, 2015 requires any person or institution, whether public or private, that operates a computer system or network in Nigeria to immediately inform the National Computer Emergency Response Team (CERT) Coordination Center of any attack, intrusion, or other disruption liable to hinder the functioning of another computer system or network, so that the National CERT can take the necessary measures to address the issue.

The National CERT Coordination Center may propose isolating an affected computer system or network pending resolution. A person or institution that fails to report such an incident to the National CERT within 7 days of its occurrence commits an offence and is liable to denial of internet services, and must in addition pay a mandatory fine of N2,000,000 into the National Cyber Security Fund.

The Office of the National Security Adviser is the Act's own coordinating body for all security and enforcement agencies under it.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Cybercrimes (Prohibition, Prevention, etc.) Act
2015, official PDF originally published by the Nigeria Computer Emergency Response Team (cert.gov.ng), read through an Internet Archive capture of that PDF the same primary text and channel this jurisdiction's scraping-topic instrument for the Act's section 6 already cites. The document's own front matter carries an unfilled commencement-clause placeholder, so no commencement date is confirmed from this text.

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2023. Publisher's page: https://www.cert.gov.ng/ngcert/resources/CyberCrime__Prohibition_Prevention_etc__Act__2015.pdf

Back to the example  ·  Lint your app