HomeFrameworksBahrain NCSC Baseline
National Cybersecurity Centre (NCSC), Ministry of Interior · Bahrain

NCSC Baseline Cybersecurity Controls (Kingdom of Bahrain) compliance software

Bahrain's national cybersecurity baseline — 81 controls across 7 domains, mandatory for CNI entities and encouraged for every other public or private organisation in the Kingdom.

At a glance
  • Issuing authorityNational Cybersecurity Centre (NCSC), Ministry of Interior
  • InstrumentNCSC-CP-D22-0001 — Baseline Cybersecurity Controls
  • Structure7 domains, 17 subdomains, 81 controls
  • CadencesVulnerability assessment quarterly · penetration test annually · audit plan annually
Bahrain NCSC BaselineAvailable
Overview

What Bahrain NCSC Baseline requires

Who it applies to

  • Entities designated Critical National Infrastructure under Royal Decree 17/2025 — mandatory
  • Public and private organisations in Bahrain adopting the baseline voluntarily
  • Third parties and cloud providers named in an in-scope entity's contracts
  • Organisations preparing for NCSC-coordinated external audit

The Baseline Cybersecurity Controls (NCSC-CP-D22-0001) are issued by Bahrain's National Cybersecurity Centre, part of the Ministry of Interior. They are mandatory for every public or private entity in the Kingdom's designated Critical National Infrastructure sectors — gas, electricity and oil, financial services, ICT, healthcare, government services, critical industry and transportation — under Royal Decree 17/2025, and the NCSC encourages adoption by every other organisation as good practice.

The controls span seven domains: Cybersecurity Governance, Training and Awareness, Cybersecurity Defense, Log Management and Cybersecurity Incident, Third-Party and Cloud Cybersecurity, Cybersecurity for Operational Technology and IoT, and Internal and External Audit. Cadences are explicit rather than left to interpretation: vulnerability assessment at least every three months, penetration testing annually with scope approved by senior management, and an audit plan reviewed at least annually with external audit coordinated with NCSC and the sector regulator.

Incident notification runs to NCSC and the sector regulator for any medium- or high-classified incident, confirmed or suspected, and the twelve-field incident report to management covers root cause, indicators of compromise and remediation cost. GRCLens carries the controls as NCSC published them, so an entity's evidence trail cites the same clause the regulator would.

In the platform

How GRCLens supports Bahrain NCSC Baseline

Bahrain NCSC Baseline runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

81 controls, NCSC's own domains

Governance, Training and Awareness, Defense, Log Management and Incident, Third-Party and Cloud, OT/IoT, and Audit — assessed with status, owner and evidence per control.

Incident-notification readiness

The controls behind notifying NCSC and the sector regulator for a medium- or high-classified incident, and the twelve-field management report, are tracked as their own indicator.

Testing cadence tracked

Quarterly vulnerability assessment and annual penetration testing are due-dated controls, not one-off checkboxes, so a lapsed cadence shows as a finding before an auditor asks.

CNI applicability flagged

Mandatory-for-CNI controls are marked as such, so an organisation outside the CNI sectors can see which controls it is adopting voluntarily.

Questions

Bahrain NCSC Baseline frequently asked questions

Who must comply with the NCSC Baseline Cybersecurity Controls?

Every public or private entity Bahrain designates as Critical National Infrastructure — gas, electricity and oil, financial services, ICT, healthcare, government services, critical industry and transportation — under Royal Decree 17/2025. NCSC encourages every other organisation in the Kingdom to adopt the same baseline.

How quickly must an incident be reported to NCSC?

The controls require notifying NCSC and the sector regulator for any medium- or high-classified incident, confirmed or suspected, but set no fixed deadline, format or channel — classification itself follows NCSC and sector guidance.

Is there an Arabic edition of the controls?

NCSC's Arabic landing page links the same English PDF; there is no separate Arabic edition of the control text itself. GRCLens's assessment interface and guidance are bilingual regardless.

Talk to us about Bahrain NCSC Baseline

Security Solution Consultants provides Bahrain NCSC compliance advisory alongside the platform, so you can combine tooling with hands-on expertise.