What Nigeria's Cybercrime Act Actually Means for Your Small Business Website

What Nigeria's Cybercrime Act Actually Means for Your Small Business Website

A
Admin Xpiria
September 24, 202610 min read

Mention "Nigeria's Cybercrime Act" to a small business owner and you will usually get one of two reactions: genuine alarm about a vague, unspecified new obligation, or a shrug on the assumption it could not possibly apply to something as modest as a small website. Searching for clarity mostly makes this worse, since the results are dominated almost entirely by law firm content, dense, cautious, written for a compliance audience with an in-house legal team, not a small business owner trying to understand what actually changes for them. This is a plain-English walkthrough of what the Cybercrimes Act, and its 2024 amendment, genuinely means if you run a small Nigerian website or online business.

A diagram showing which businesses the cybersecurity levy applies to versus what a small website actually needs to do

What this law actually is, and what changed in 2024

The Cybercrimes (Prohibition, Prevention, etc.) Act, originally passed in 2015 and significantly amended in February 2024, is Nigeria's core legal framework for defining and prosecuting computer-related crime, hacking, identity theft, online fraud, cyberstalking, and for setting out obligations certain organisations have around protecting the systems and data they hold. The 2024 amendment strengthened penalties for several offences, refined some of the more controversial and vaguely worded provisions from the original 2015 text, and introduced a specific cybersecurity levy, which is the part that has caused the most confusion and, for many small business owners, unnecessary alarm.

The cybersecurity levy: who it actually applies to, stated plainly

This is worth being direct about, since it is the single most misunderstood part of the amendment among small business owners. The levy, set at 0.5 percent of electronic transaction value, applies specifically to organisations named in the Act's own schedule: banks and other financial institutions, telecom and internet service providers, insurance companies, and the Nigerian Stock Exchange. It does not apply to a small ecommerce store, a VTU reseller platform, or a general small business website simply because that business processes online payments through one of these regulated providers. If you are a small business accepting payments through a bank or payment gateway, the gateway or bank itself is the entity within scope of this specific levy, not your own business, and a claim otherwise is a common, avoidable source of unnecessary worry.

What actually is relevant to a small website or online business

Setting the levy confusion aside, the parts of this law genuinely relevant to a small business fall into a few practical categories. Unauthorised access offences, what is commonly called hacking, make it a criminal act for someone to access your systems, your website's admin panel, your customer database, your payment integration, without authorisation, which functions as legal protection for your business, not an obligation placed on it. Identity theft and online fraud provisions similarly protect you and your customers against exactly the kind of scams and impersonation covered in our guides to how VTU business owners actually get scammed and WhatsApp impersonation targeting business owners, giving genuine legal recourse if your business or a customer is victimised this way.

Cyberstalking and harassment provisions become relevant specifically if your website has any feature where the public can post content, a comment section, a public forum, a review system, since you carry some responsibility for how that feature is moderated and used. The 2024 amendment specifically narrowed this provision's language, focusing it on content intended to cause real harm or a breakdown of order, rather than the broader "annoyance" or "grossly offensive" language in the original 2015 text that critics had long argued was too vague and open to misuse.

What genuinely does not apply to a small operation

Beyond the levy, several of this law's more demanding provisions are aimed squarely at organisations the Act itself classifies as operating "critical national information infrastructure," a specific, formally designated category covering systems whose failure would have a serious national impact, banking cores, telecom backbone infrastructure, major government systems. A small business website, an ecommerce store, a VTU reseller platform, does not fall into this category by simply existing online, and the more demanding cybersecurity measures and sectoral Computer Emergency Response Team obligations tied to that designation genuinely do not apply at a small business's scale.

How this relates to NDPR and the Data Protection Act

It is worth being clear that this is a separate law from the data protection framework covered in our NDPR guide for small websites, even though the two overlap in spirit and are frequently confused with each other. The Cybercrimes Act is fundamentally about defining and criminalising harmful computer-related conduct, and NDPR and the Nigeria Data Protection Act are about how personal data specifically must be handled. A small business genuinely needs to think about both, but they are answering different questions, and neither one substitutes for the other.

What a genuinely sensible small-business posture looks like

Given all of this, a proportionate response for most small Nigerian websites is straightforward rather than elaborate. Keep basic security practices in place, the kind covered in our website security guide, since these protect you both practically and, now, with clearer legal backing if you are ever the victim of unauthorised access. If your site has any public content feature, a comment section or forum, have a real, if simple, moderation practice rather than leaving it fully unmoderated, given the cyberstalking and harassment provisions this law contains. Do not assume the cybersecurity levy applies to your own business unless you genuinely are a bank, telecom operator, ISP, insurer, or stock exchange, since it almost certainly does not. And treat this law, correctly, as something that mostly protects you and gives you legal recourse against attackers, rather than as a new compliance burden actively working against you.

What to actually do if your business is the victim of a genuine cybercrime

Knowing this law exists mostly to protect you is only useful if you also know the practical, concrete step that follows from it: reporting. The Nigeria Police Force operates a dedicated cybercrime unit, and reports can also be lodged with the Economic and Financial Crimes Commission for cases specifically involving financial fraud, which covers the large majority of what a small business is actually likely to experience, a drained account, a fraudulent transaction, a phishing-driven compromise. Keep clear, specific records as you go, screenshots, transaction references, timestamps, the specific account or number involved, since a vague report is far harder to act on than a specific one, and this record-keeping habit is worth building before you ever need it, not improvised for the first time during an actual incident.

A brief, honest note on VPNs and this law, since the question comes up often

A common, specific worry among Nigerian internet users is whether using a VPN itself is illegal under this law, and the honest, direct answer is no, using a VPN for a legitimate purpose, accessing region-locked content, protecting your connection on public wifi, working remotely, is not itself an offence under the Cybercrimes Act. What the law does criminalise is using any tool, a VPN included, specifically as part of genuinely unauthorised access or fraud, in which case the underlying conduct, not the VPN itself, is what carries legal consequence. A small business owner using a VPN for entirely ordinary, legitimate reasons has nothing to be concerned about under this specific law.

A worked example: a small ecommerce store's actual exposure

Picture a small Nigerian ecommerce store, accepting payments through a payment gateway, with no comment section or public posting feature of any kind, just product pages and a checkout. Under this law, the store's real, practical relationship to it is almost entirely protective: if someone breaks into the store's admin panel and steals customer data, that is a criminal act the owner can report and pursue, with the law's penalties applying to the attacker, not the store. The cybersecurity levy does not apply to the store directly, since it is not a bank, telecom, ISP, insurer or stock exchange, only the payment gateway processing transactions on the store's behalf sits within that specific schedule. The store's actual to-do list arising from this law is short: keep the site itself reasonably secure, which it should be doing regardless, and understand that if it is ever attacked, this law is squarely on its side.

Mistakes worth avoiding around this specific law

Believing the cybersecurity levy applies to your own small business. This specific piece of misinformation has spread widely and caused real, unnecessary anxiety among small business owners; the levy's scope is explicitly limited to the schedule named in the Act, and a small ecommerce or VTU business is not on it.

Treating this law and NDPR as interchangeable, or assuming compliance with one covers the other. They address genuinely different questions, and a business should think about both separately, covered in this guide's companion piece on NDPR.

Leaving a public comment or posting feature completely unmoderated, unaware that this carries some real responsibility under this law. A simple, honest moderation practice, reviewing flagged content and removing genuinely harmful posts, is a modest task that meaningfully addresses this.

Not realising this law gives you real legal standing when your business is the victim, not just an obligation on how you operate. Businesses that experience genuine unauthorised access or fraud have clearer legal recourse under the 2024 amendment's strengthened penalties than many owners realise.

A short glossary

Critical national information infrastructure: a formally designated category of systems whose failure would have serious national impact, not a category a small business website falls into automatically. Cybersecurity levy: the 0.5 percent charge on electronic transaction value introduced by the 2024 amendment, applying specifically to banks, telecoms, ISPs, insurers and the stock exchange, not to a typical small online business. Unauthorised access: what is commonly called hacking, a criminal offence under this law regardless of a business's size. CERT: Computer Emergency Response Team, a formal incident-response obligation relevant to larger, designated organisations rather than a small website.

Where this fits into building your business properly

None of this replaces genuine legal advice for a business with real, specific exposure or an unusual situation, a business handling identity documents at scale, or one that is unsure whether it might fall within a regulated category, and a proper conversation with a Nigerian lawyer is worth the investment at that point. For the overwhelming majority of small businesses, understanding this law is mostly about clearing up misinformation and recognising it as a source of legal protection, not a new burden. Our guide to starting an online business in Nigeria covers the wider set of legal and practical foundations this specific topic sits alongside, and you can start building free on a platform already built with these basics in place.

A
Admin Xpiria
Xpiria Tech Team

Comments

No comments yet. Be the first to share your thoughts.

Leave a comment

Comments are reviewed before they appear. Links are not allowed.

Related Articles