NBU cybersecurity requirements
These are four different resolutions. The knowledge base already summarises each one. This page only says who it applies to, and where to read the summary. SecBoard is at the end, as a place to keep records, not as a replacement for the text.
Who each resolution applies to
No. 143 of 9 December 2025 is information security and cyber protection for insurers, credit unions, financial companies, and pawnshops. The knowledge-base summary says it does not apply to payment service providers or to postal operators with currency-trading rights. The objects named there are insurance secrecy, financial-service secrecy, and the information and communication systems that support core processes or connect to NBU systems.
No. 123 of 10 October 2024 is the management system of a financial payment service provider: payment institutions except small ones, e-money institutions, postal operators that may provide financial payment services, and branches of foreign payment or e-money institutions. It covers governance, internal control, and reporting to the NBU, including the three lines of defence.
No. 95 of 28 September 2017 is information security in the banking system. It applies to banks. The summary says Section III, on cryptographic protection in NBU information systems, also reaches non-bank participants of those systems. It does not set the physical security of bank premises, and it leaves cloud to a separate act.
No. 67 of 14 June 2024 is uninterrupted functioning in a special period. It applies to banks, branches of foreign banks, non-bank financial institutions, and other supervised persons. It defines three modes and the duty to keep a protocol for moving into each mode, and to activate the relevant protocol when a special period is in effect or when the NBU Board introduces a restricted or critical mode.
Where the requirement areas are written out
Each knowledge-base article keeps the resolution first: what it is, how it is structured, and the requirement areas. The module map is after that. Read the article for the resolution you actually fall under. This page does not repeat those sections.
After the resolution: where records can sit
SecBoard does not replace the resolution and does not certify the institution. Where the articles describe implementation, they point at a local or custom framework in the compliance module for controls and evidence, and at the existing modules for risk, assets, access, documents, incidents, and third parties. Start from the article. Open a module only when you already know which record the resolution asks for.