Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, Reporting of Cyber Threats to the National CERT
Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, section 21, Reporting of Cyber Threats
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A vulnerability and incident reporting rule binding public and private bodies.
As of 17 September 2026.
What it requires
- This binds any person or institution, whether public or private, that operates a computer system or a network in Nigeria; there is no sector or size gate.
- Immediately inform the National Computer Emergency Response Team (CERT) Coordination Center of any attack, intrusion, or other disruption liable to hinder the functioning of another computer system or network.
- Report the incident to the National CERT within 7 days of its occurrence. Failing to do so is itself an offence, punishable by denial of internet services and a mandatory fine of N2,000,000 payable into the National Cyber Security Fund.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Failing to report a qualifying incident to the National CERT within 7 days is itself described as an offence, but section 21(3) states only denial of internet services plus a mandatory fine of N2,000,000; no term of imprisonment is stated for this specific offence.
Penalty structure
Section 21(3)'s fixed fine for failing to report a qualifying incident to the National CERT within 7 days of its occurrence, payable into the National Cyber Security Fund. The same subsection separately imposes denial of internet services, a non-monetary sanction this fixed_cap figure does not capture.
- Rule
- Fixed only
- As of
- 17 September 2026
- Currency
- NGN
- Fixed cap
- 2,000,000
Who enforces it
Enforcement body
Office of the National Security Adviser (ONSA), the Act's own coordinating body for all security and enforcement agencies under it; the National Computer Emergency Response Team (CERT) Coordination Center is the reporting recipient named in section 21 itself.
What it reaches
Obligation class
Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 21 of the Cybercrimes (Prohibition, Prevention, etc.) Act, 2015 requires any person or institution, whether public or private, that operates a computer system or network in Nigeria to immediately inform the National Computer Emergency Response Team (CERT) Coordination Center of any attack, intrusion, or other disruption liable to hinder the functioning of another computer system or network, so that the National CERT can take the necessary measures to address the issue.
The National CERT Coordination Center may propose isolating an affected computer system or network pending resolution. A person or institution that fails to report such an incident to the National CERT within 7 days of its occurrence commits an offence and is liable to denial of internet services, and must in addition pay a mandatory fine of N2,000,000 into the National Cyber Security Fund.
The Office of the National Security Adviser is the Act's own coordinating body for all security and enforcement agencies under it.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Cybercrimes (Prohibition, Prevention, etc.) Act
2015, official PDF originally published by the Nigeria Computer Emergency Response Team (cert.gov.ng), read through an Internet Archive capture of that PDF the same primary text and channel this jurisdiction's scraping-topic instrument for the Act's section 6 already cites. The document's own front matter carries an unfilled commencement-clause placeholder, so no commencement date is confirmed from this text.