South AfricaIn ForceFintechCybercrime

Directive in Respect of Cybersecurity and Cyber-Resilience within the National Payment System (Directive 1 of 2024)

za-npscyberdirective-2024 · Guidance

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

Directive No. 1 of 2024, issued by the South African Reserve Bank (SARB) on 17 May 2024 under the National Payment System Act 78 of 1998, establishes binding cybersecurity and cyber-resilience requirements for participants in the national payment system (NPS). It responds to the growing frequency and sophistication of cyber-attacks on payment infrastructure and is intended to protect the integrity, safety and continuity of payments in South Africa. The directive applies to designated NPS participants and other entities the SARB specifies, including banks and designated clearing and settlement participants that increasingly include fintech-enabled operators. It requires affected institutions to establish and maintain a cybersecurity and cyber-resilience framework proportionate to their role and risk, including board-level governance and accountability for cyber risk, identification and protection of critical payment systems and data, capabilities to detect, respond to and recover from cyber incidents, and regular testing of resilience. Institutions must report material cyber incidents to the SARB within prescribed timeframes and provide assurance of their compliance. The directive aligns South African payments oversight with international standards on operational and cyber resilience for financial market infrastructures. Institutions were expected to demonstrate compliance within a transition period, and the directive was confirmed to take effect on 1 June 2025. The SARB supervises compliance and may take enforcement action, including directives and sanctions, against participants that fail to meet the requirements. Because it governs cyber-security specifically within digital payment infrastructure, the instrument carries both a fintech and a cybercrime dimension and is an important part of the operational-risk framework for payment providers in South Africa.

Key provisions
  1. Binding cybersecurity and cyber-resilience requirements for national payment system participants
  2. Board-level governance and accountability for cyber risk
  3. Identification and protection of critical payment systems and data; detection, response and recovery capabilities
  4. Regular resilience testing and assurance of compliance
  5. Mandatory reporting of material cyber incidents to the SARB within prescribed timeframes
  6. SARB supervision and enforcement; effective 1 June 2025
Related instruments
Entry history
Entry history
  1. 24 June 2026
    ATLPF Research Team (AI-assisted)
    SARB Directive No. 1 of 2024: Directive in respect of cybersecurity and cyber-resilience within the national payment system (issued 17 May 2024; effective 1 June 2025)