October to January is about 90 days. In that window, a Nigerian bank or large fintech has to do four things at once. It has to be on a certified cloud provider. It has to have its payment transaction data localised. It has to have filed its cybersecurity self-assessment with the CBN. And it has to hold a current NDPC data protection audit.
None of those four is optional, and they overlap. This article is the execution calendar. It sets out what to do, in what order, between now and January 1, 2027.
Articles One through Six built the architecture. Article Seven covered the provider contract. This article is the timeline that ties it together. For teams that have been reading the series and wondering when the work actually happens, this is the answer.
Why 90 days matters
The Certified Cloud Register is scheduled to go live in October 2026. The CBN data localisation deadline is January 1, 2027. Between them is roughly one quarter. That is the window where the plan either becomes a working migration or becomes a compliance gap.
As of September 2026, about four months remain to the CBN deadline. That sounds like enough until the dependencies are written out. A provider cannot be migrated to before one is picked. One cannot be picked before the register goes live. Cut-over cannot start before the control plane is built and replication is tested. Each step waits on the one before it.
There is no evidence the CBN will extend the deadline. The circular says January 1, 2027, and nothing in the CBN's recent behaviour suggests flexibility. It put the country's PoS terminals on a 60-day geotagging clock (Article One covers this), and it issued the cybersecurity self-assessment tool with sanctions attached for false submissions. The enforcement posture is real.
The four obligations, and what happens if you miss
Here are the four things that land in that window, and the cost of missing each one.
Certified cloud provider. From October, banks, fintechs, and agencies source cloud from NITDA's register. Miss this and the data is localised but not on approved infrastructure. The CBN deadline and the NITDA register are two different gates. An institution can clear one and fail the other. Article Seven covers how to pick the provider.
Localised payment data. The CBN circular PSS/DIR/PUB/CIR/001/004 (June 15, 2026) requires all payment transaction data generated in Nigeria to be stored and processed in Nigeria by January 1, 2027. This is the headline obligation. It covers deposit money banks, microfinance banks, mobile money operators, switching and processing companies, and payment service providers.
Cybersecurity self-assessment filed. In a circular dated 30 March 2026, the CBN's Cybersecurity Self-Assessment Tool requires deposit money banks to submit within three weeks and other institutions within five. The data is as of December 31, 2025, and a false submission is treated as a regulatory breach under BOFIA 2020. This is separate from localisation but lands in the same window.
A current NDPC audit. Under the NDPA 2023 and the GAID directive (effective September 2025), institutions that count as data controllers of major importance must appoint a DPO, file annual compliance audit returns through a licensed DPCO, and notify breaches within 72 hours. The NDPC is enforcing. By early 2026 it had concluded more than 240 investigations and taken 11 major enforcement actions, and collected about 7.2 billion naira in registrations, compliance revenue and fines (Riotimes). Fines have names attached. MultiChoice Nigeria was fined 766.2 million naira. Fidelity Bank was fined 555.8 million naira in 2024.
The stakes are visible. The CBN revoked the operating licences of 46 microfinance banks with effect from July 1, 2026. Not every failure is a data localisation failure, but the message is consistent. The regulators are not issuing warnings anymore.
The calendar
Here is the execution calendar. It assumes the work starts in September 2026. Teams that have not started compress the early steps; the order does not change.
September. Run the data flow inventory and classification from Article Three. It is not possible to schedule what has not been classified. In parallel, open conversations with colocation providers so the institution can move fast when the register goes live. Locking capacity early is the difference between a choice of provider and whatever is left.
October. Select the provider and negotiate the contract, using the checklist from Article Seven. Decide the DR site. If the institution is in the CSAT group that gets five weeks, submit it now so it is not competing with the migration for attention.
Late October. The register goes live. Confirm the provider is on it, in writing. Build the migration control plane from Article Four: identity, networking, deployment, and monitoring. Test it by moving a non-production workload end to end.
November. Start the cut-over. Move the "must be onshore" workloads first. Test replication between the primary and DR site under production load, and measure the latency. Fix what is slow before moving the rest. Article Six covers the latency trap.
December. Validate. Confirm the onshore environment can serve the full transaction load independently. Build the compliance evidence: residency attestation, audit logs, and the audit trail the DPCO will need. Freeze changes. Keep a rollback plan that still works.
January 1. Cut-over done. Data onshore. Provider certified. CSAT filed. NDPC audit current. The institution has a defensible position for the CBN, the NDPC, and its board.
Where teams get it wrong
Over-migrating out of fear. The circular does not say move everything. It says move payment transaction data. Moving analytics, AI training data, and archival onshore adds cost and latency with no compliance benefit. Classify first, as Article Three argues.
Skipping the second site. A Lagos-only migration clears the CBN check but rebuilds the single-region risk left behind on the hyperscaler. Design the DR site before signing the primary contract. This is Article Five.
Signing before certification. A provider contract signed before the register is confirmed is the fastest way to migrate twice. Make certification a contract condition. This is Article Seven.
Treating the calendar as optional. The dates are fixed. The teams that start in October will be the ones explaining to their board in January why the data is still in Cape Town.
The checklist
Print this and put it on the wall.
- Data flow inventory complete and every path classified.
- Provider selected and contract signed with a certification condition and an exit right.
- DR site confirmed in a different city.
- Control plane built and tested with a non-production workload.
- Replication tested under load, latency measured.
- Onshore environment can run the full load independently.
- Compliance evidence assembled for the NDPC audit.
- CSAT filed and acknowledged.
- Rollback plan current and tested.
- January 1: data onshore, provider certified, audit current.
The position of this Journal
The run is short, but it is enough if the steps happen in order. The architecture is the easy part. The calendar is where most teams fall behind.
FIG. J8 — EXECUTION CALENDAR · SEPTEMBER TO JANUARY · THE ORDER IS THE PLAN