Bangladesh Launches National Cybersecurity Rating System: 4-Pillar Framework
ICT Division unveils NRS with 131 indicators across IT governance, infrastructure, cybersecurity, and digital service maturity; comes as 188 cyber incidents reported in 2024
Dhaka, August 4, 2026 — Bangladesh is set to launch a National Rating System (NRS) that will, for the first time, give every government and private institution a standardised score based on how well it manages IT, information and cybersecurity — a landmark reform as the country's rapidly expanding digital landscape continues to face cyber breaches, fraud, and financial theft.
Built on a four-pillar framework called the National ICT and Cybersecurity Maturity Rating, the system is expected to provide the country's first evidence-based benchmark for measuring institutional cyber readiness. The system will be unveiled today at the ICT Division, according to documents obtained by The Daily Star.
🏛️ Four-Pillar Framework: How Scoring Works
The NRS assigns weighted scores across four pillars, with each pillar measuring a distinct dimension of an institution's cybersecurity and IT maturity. The four-pillar architecture is designed to capture the full spectrum of cyber readiness — from governance and leadership down to operational infrastructure, data protection, and user-facing digital service quality.
- 👥 Pillar 1: IT and Information Security Governance (20%) — Assesses leadership, policies, organisational structure, and administrative accountability
- 🖥️ Pillar 2: Infrastructure and Operations (30%) — Evaluates IT infrastructure, data centres, networks, servers, backup and disaster recovery systems, and change management
- 🔒 Pillar 3: Cybersecurity and Data Protection (30%) — Covers security controls, data protection, risk management, incident response, vulnerability management, and audit compliance
- 💻 Pillar 4: Digital Service and User Maturity (20%) — Assesses quality of digital services, user-centricity, IT service management, software governance, and continuous improvement
📊 Scoring Scale and Letter Grades
Each of the 131 indicators under the four pillars will be scored on a five-point maturity scale, ranging from 0 (not implemented) to 4 (fully implemented or optimised). The intermediate levels are:
- ⚫ 0 — Not implemented
- 🟢 1 — Initial/ad hoc
- 🟡 2 — Partially implemented
- 🟠 3 — Largely implemented
- ✅ 4 — Fully implemented or optimised
The weighted scores will then be combined into a total score out of 100 and converted into a letter grade from A (excellent) to E (poor). The grading system is designed to make cybersecurity readiness easily comparable across institutions — a critical capability that has been missing from Bangladesh's institutional landscape.
🌏 Why Bangladesh Needs This Now
Bangladesh has long lacked a unified system to assess how well operators of critical information infrastructure, government agencies, and private institutions are prepared to deal with cyber-attacks, data theft, ransomware, and service disruptions, an ICT Division official said. The absence of such a benchmark has made it difficult to compare cyber readiness across institutions or identify areas that need improvement.
He added that institutions currently differ widely in their policies, technical safeguards, staffing, infrastructure, and digital service management — making it difficult to compare their cyber readiness or identify areas that need improvement. The NRS is designed to close this gap by providing a common, standards-aligned measurement framework.
Officials said the indicators were developed in line with internationally recognised standards and frameworks, allowing an institution's overall ICT and cybersecurity readiness to be assessed through a single integrated system rather than through fragmented, ad hoc audits.
📋 Expected Benefits for Institutions
The government expects the rating system to deliver several concrete benefits for institutional cyber risk management:
- 🔍 Identify institutional weaknesses and risks through standardised assessment
- 🧪 Prioritise IT audits and VAPT (Vulnerability Assessment and Penetration Testing)
- 💰 Support budget, staffing, and infrastructure planning through evidence-based gap analysis
- 📈 Create a national maturity baseline via annual ranking of public and private institutions
- 👥 Strengthen evidence-based policymaking at the ICT Division and across government
- 🤝 Improve interoperability between institutions by aligning cybersecurity standards
🚀 Future Phases: AI-Based Automation
The current launch is the first phase of what officials envision as a multi-stage evolution toward fully automated cyber readiness assessment. Future phases of the system will include:
- 🧠 AI-based automated assessment engine to reduce manual audit burden
- ✅ Automated validation of submitted documents to verify institution claims
- 📊 Sector-wise benchmarking to compare institutions within banking, healthcare, telecoms, etc.
- 💻 Comparative analytics dashboards for policymakers and institutional leaders
- 🚢 Automated, risk-based recommendations and improvement roadmaps for individual institutions
⚠️ Bangladesh's Growing Cyber Threat Landscape
The framework is being introduced as Bangladesh faces growing cyber risks. As of June 2026, the country had 13.60 crore internet users — a massive digital exposure surface that makes institutional cybersecurity readiness a national priority rather than a technical afterthought.
Several major cyber incidents have highlighted these risks in stark terms:
- 💳 2016: Hackers stole millions of dollars from Bangladesh Bank in one of the world's largest cyber-enabled bank thefts
- 👥 2023: A breach of a government birth and death registration website exposed the personal data, including national ID numbers, of more than 50 million Bangladeshis
- ⚠️ July 2025: Bangladesh Bank warned banks and financial institutions to strengthen systems against possible cyber-attacks targeting critical information infrastructure, including the banking, healthcare, and public service sectors
According to the Bangladesh Cyber Threat Landscape 2024 report, published by an ICT Division unit, 188 cybersecurity incidents were reported in 2024. The actual number is likely higher, as many incidents go unreported due to reputational concerns or lack of detection capability.
📋 Strategic Context
The NRS launch takes on added significance given Bangladesh's broader digital transformation agenda and the approaching LDC graduation deadline. As the country formalises trade relationships through agreements like the recently signed Korea CEPA and Japan EPA, the volume of digital trade and cross-border data flows will increase — raising both the opportunities and the cyber risks associated with Bangladesh's integration into global digital value chains.
For export-oriented industries, the cybersecurity rating system has particular relevance. International buyers increasingly require suppliers to demonstrate cybersecurity readiness as part of their due diligence processes, and a national rating system provides a credible, government-backed credential that Bangladeshi suppliers can present to global partners. Institutions that achieve high NRS grades will have a tangible competitive advantage in winning contracts with security-conscious multinational buyers, particularly in the IT services and pharmaceuticals sectors where data integrity is mission-critical.
The success of the NRS will ultimately depend on adoption. If government agencies, banks, telecoms, and major private institutions embrace the rating system and use it to drive genuine improvements in their cybersecurity posture, Bangladesh will have taken a meaningful step toward closing the cyber resilience gap that has plagued its digital economy. If the rating system becomes a checkbox exercise — completed for compliance purposes without driving real change — the country's cyber risk exposure will continue to grow alongside its expanding digital footprint. The ICT Division's ability to enforce meaningful adoption, and to use the resulting data to drive policy, will determine which of those two futures Bangladesh inhabits.
This news was originally published by The Daily Star. For the full original report, please visit: https://www.thedailystar.net/business/economy/news/national-cybersecurity-rating-system-set-launch-4239351
📬 Get Bangladesh Trade News in your inbox
Weekly digest of export industry news, policy updates, and market analysis.
📰 Related Stories