Skip to main content

POJK 11/2022 + SEOJK 29/2022

Cybersecurity compliance for commercial banks: POJK 11/2022 and SEOJK 29/2022

In short

How commercial banks (Bank Umum) meet POJK 11/2022 and SEOJK 29/2022: the annual cyber risk and maturity assessments, OJK incident reporting requirements, and Alpha Code services that help banks satisfy them.

Banking solutions

Indonesia's commercial banks handle the deposits, loans, and transfers that reach tens of millions of customers every day. When core banking systems, mobile applications, and connections to payment infrastructure become the backbone of that service, a technology failure is felt by customers, not just by the IT team. OJK addressed this directly when it issued POJK 11/2022, then reinforced its technical requirements through SEOJK 29/2022.

These two instruments together form the cyber resilience framework that applies to every OJK-licensed commercial bank. This page sets out the concrete obligations they contain and how Alpha Code services help banks satisfy them. For a deeper treatment of the specific controls and their technical context, see our articles on OJK cybersecurity requirements for Indonesian banks and penetration testing requirements for Indonesian banks under POJK 11/2022.

This page focuses on commercial banks specifically. For the wider picture of compliance and GRC across BFSI in Indonesia, including how commercial banks compare with BPR, insurers, and payment operators, see compliance and GRC for BFSI.

POJK 11/2022 + SEOJK 29/2022

POJK 11/2022 governs IT implementation by commercial banks, and its Chapter V covers cyber resilience and security. SEOJK 29/2022 is the implementing circular: banks assess their inherent cyber risk and cyber security maturity annually, combine the two into a cyber risk level reported to OJK, run a four-stage cyber resilience process, test security regularly in-house or through a third party, and maintain a cyber unit independent of IT management. Incident reporting runs on two clocks, an initial notification within 1x24 hours and a full report within 5 working days.

Authority: OJKStatus: In effect since 2022

Who these regulations apply to

POJK 11/2022 and SEOJK 29/2022 apply to commercial banks (Bank Umum) operating under an OJK licence, including conventional banks, sharia banks, foreign banks operating in Indonesia, and regional development banks (BPD). They do not apply to rural banks (BPR and BPRS), which are governed by a separate framework under POJK 34/2025, and they do not apply to payment system operators overseen by Bank Indonesia under PBI 2/2024.

Commercial banks that also operate payment services or other products licensed by Bank Indonesia may face both regulatory frameworks at once. In that situation, mapping each regulator's requirements separately is the right starting point. Terms like "information security" and "cyber resilience" appear on both sides, but with slightly different scopes and control expectations, so assuming one compliance programme covers two regulators is a risk in itself.

How SEOJK 29/2022 is structured

SEOJK 29/2022 is the implementing circular for Chapter V of POJK 11/2022, and it runs to ten sections. Rather than a flat list of controls, it sets an annual assessment cycle around a set of process obligations. That cycle is worth understanding first, because it is what the bank reports to OJK each year and what OJK reviews.

The cycle starts with inherent cyber risk. A bank assesses its own inherent risk against four factors: technology, bank products, organisational characteristics, and its cyber incident track record. The result is a rating from 1 (low) to 5 (high), taken at the end-December position and submitted to OJK within 15 working days after the reporting year ends. OJK reviews what it receives, and where it judges that the rating does not reflect the bank's actual condition, it can adjust the rating itself.

The other half of the cycle is the maturity assessment, which scores the quality of two things. The first is cyber security risk management, covering risk governance with active Board of Directors and Board of Commissioners oversight and defined risk appetite and tolerance, the risk management framework, the risk management process with its people and management information systems, and the risk control system. The second is the quality of the cyber resilience process. Inherent risk and maturity combine into the bank's cyber risk level, rated 1 to 5, also reported to OJK and also open to adjustment by OJK.

The cyber resilience process is where the technical controls sit, in four stages: identifying assets, threats, and vulnerabilities; protecting assets; detecting cyber incidents; and handling and recovering from them. Identification covers IT asset inventory, valuation, and configuration records, plus regular security testing. Protection covers comprehensive security controls, data and information security management, protection of networks, hardware and software, access and user protection, safeguards in arrangements with IT service providers including cloud, secure coding, and patching. Detection covers baseline performance documentation for critical functions, monitoring for suspicious activity, and continuous vulnerability detection. Handling and recovery covers the containment and recovery plan, the cyber incident response team's roles, escalation and reporting paths, and post-incident lessons learned.

The circular then requires an organisational home for all of it. The bank must establish a unit or function that handles cyber resilience and security and that is independent of the IT management function, meaning IT planning, development, operation, and monitoring. That unit coordinates the resilience process, both self-assessments, the cyber risk level determination, security testing, and the cyber incident response team.

ObligationStatus
Annual inherent cyber risk self-assessment, reported to OJKMandatory
Annual cyber security maturity assessment and cyber risk levelMandatory
Cyber resilience process: identify, protect, detect, handle and recoverMandatory
Cyber unit or function independent of the IT management functionMandatory
Scenario-based cyber security test at least once a yearMandatory
Vulnerability-analysis testing, including penetration tests, on a regular cycleMandatory
Initial incident notification within 24 hours, full report within 5 working daysMandatory
Electronic systems hosted in Indonesia unless OJK grants permissionMandatory

Incident reporting deadlines

One of the most operationally demanding aspects of SEOJK 29/2022 is the incident reporting obligation, which runs on two clocks: a short one for the initial notification and a second one for the full report. These cannot be improvised when an incident is already active. The procedures, escalation paths, and ability to assemble a regulatory report all need to be in place beforehand.

The diagram below shows the two reporting windows. The time axis is compressed so that both deadlines are legible in a single view.

Incident reporting deadlines to OJK under SEOJK 29/2022Incident discovered24 hrs5 working daysInitialnotification1x24 hoursFull incidentreport5 working daysTime axis is compressed: the two segments represent different durations.
Incident reporting deadlines to OJK under SEOJK 29/2022 (Alpha Code, based on SEOJK No. 29/SEOJK.03/2022)

The initial notification is sent in writing through electronic means, such as email, within 1x24 hours of discovering a cyber incident. That window is tight when the team is focused on technical containment, which is exactly why the reporting procedure must be ready before any incident occurs. The full incident report follows within 5 working days and covers the reporter information, impact assessment, chronology of events, root cause analysis, and final assessment. The reporting duty covers cyber incidents broadly: anything affecting customer-facing systems, involving data exfiltration, or triggering BCP activation clearly qualifies.

OJK treats the ability to report accurately and on time as evidence that incident management actually works in practice, not merely as written policy.

Mandated testing schedule

Security testing is not optional under SEOJK 29/2022, and it comes in two forms. Scenario-based testing validates how the bank contains and recovers from an incident, including its communications plan, and must run at least once a year. It covers formats such as tabletop exercises, cyber range exercises, social engineering exercises, and adversarial attack simulation, and the results reach OJK within 10 working days of the test being completed.

Vulnerability-analysis testing is the second form. It starts with vulnerability identification and continues into penetration testing, and its frequency is set by the bank's own evaluation of system criticality and of changes that raise cyber risk exposure, rather than by a fixed calendar. Banks running digital banking or other online services must carry it out. Those results go to OJK as part of the annual IT status report, within 15 working days after the reporting year ends.

Either form can be run by the bank's own team or by a third party. Where a third party is used, the bank must satisfy itself that the provider has adequate competence, evidenced for example by certification or recognition from a competent body in Indonesia or abroad, and the bank remains responsible for the testing. Results are presented to the directors as a basis for improving governance, policies, and internal control, not simply retained as a technical document. Banks seeking or renewing SWIFT connectivity face an additional layer of testing requirements under the SWIFT Customer Security Programme (CSP), aligned with OJK expectations.

For detailed guidance on the penetration testing requirements for banks under POJK 11/2022, see our article on penetration testing requirements for Indonesian banks.

A path to compliance

There is no fixed sequence that works for every bank, because each starts from a different position. The pattern that most often succeeds begins with understanding the current state, then improving governance and technical controls, followed by building the testing and reporting capabilities that run continuously.

  1. 1

    Gap assessment

    Map existing controls, policies, and procedures against the ten sections of SEOJK 29/2022. Run the inherent risk and maturity self-assessments to find where the real gaps sit.

  2. 2

    Governance and technical controls

    Establish board-level oversight of cyber risk, stand up the independent cyber unit, strengthen privileged account management, and complete the IT asset inventory.

  3. 3

    Testing and monitoring

    Schedule the annual scenario-based test, build the vulnerability-analysis testing cycle, and implement continuous monitoring for suspicious activity and vulnerabilities.

  4. 4

    Incident procedures and reporting

    Document the incident response plan with OJK escalation paths, test it at least twice a year, and confirm the teams involved are trained and ready.

The gap assessment at the outset prevents the bank from improving what is already adequate while overlooking the gaps that actually carry risk. Its output becomes a prioritised roadmap that can be taken to the board and directors for budget decisions and timeline planning.

How Alpha Code helps

We begin with a gap assessment that maps the bank's information security posture against the specific obligations of POJK 11/2022 and SEOJK 29/2022. The result is not a simple list of problems but a prioritised map that distinguishes what is already in place, what is partially covered, and what needs immediate attention, giving the bank a clear basis for planning budget and time.

For the monitoring obligations mandated by SEOJK 29/2022, our SOC service provides continuous log monitoring and anomaly detection, along with log collection and storage that meets the five-year retention requirement. We also help banks set up periodic detection-system testing as required by the regulation.

When an incident occurs, our incident response service covers technical containment alongside support for assembling the report to OJK within the applicable deadline. Our team understands the content and structure that regulators expect in incident disclosures, so the bank is not learning that process for the first time while managing an active incident.

For the mandated penetration test, we provide testing by an independent team and deliver a report in the format that OJK examiners expect, including risk categorisation and remediation recommendations with clear deadlines. Results can be presented directly to the Board Risk Committee.

On the governance side, our GRC consulting helps align information security policies, strengthen third-party risk management, and prepare the documentation that OJK examines. For banks that need security leadership without hiring a full-time CISO, our vCISO service provides that function with a more flexible engagement model.

Next steps

POJK 11/2022 and SEOJK 29/2022 are already in force. For banks that have not yet completed a gap assessment against both regulations, starting now is considerably better than waiting until an OJK examination or an incident forces a rushed response. If you want to understand where your bank stands against these obligations, our team is ready to help you set out a clear and concrete first step.

References

  1. 1.OJK, SEOJK No. 29/SEOJK.03/2022 on Cyber Resilience and Security for Commercial Banks
  2. 2.OJK, POJK No. 11/POJK.03/2022 on Information Technology Implementation by Commercial Banks
  3. 3.KPMG Indonesia, Cyber Security and Resiliency for Indonesia Banking Sector (January 2023)

Frequently asked questions

POJK 11/2022 governs how commercial banks implement information technology, covering IT governance, architecture, risk management, cyber resilience and security, IT service providers, data management, and reporting. SEOJK 29/2022 is its implementing circular for cyber resilience. It requires an annual inherent cyber risk assessment and maturity assessment that combine into a cyber risk level reported to OJK, a four-stage cyber resilience process, regular security testing, a cyber unit independent of IT management, and cyber incident reporting.

Related

Ready to strengthen your security posture?

Talk to our Jakarta-based team about your requirements.

Jakarta-based team. We reply within one business day.

WhatsApp