Cybersecurity Regulatory Framework (CRF) — Second Version compliance software
Assess and evidence CST's Cybersecurity Regulatory Framework across 215 controls, six domains and the CL1–CL3 progression, with reporting built for the annual CST self-assessment.
What CST CRF requires
The Cybersecurity Regulatory Framework (CRF) is issued by the Communications, Space & Technology Commission (CST), formerly CITC, the regulator of Saudi Arabia's ICT, telecom, postal and space sectors. It is binding on CST-licensed service providers, not an optional best-practice standard, and GRCLens implements the Second Version published in October 2023.
CRF organises 215 controls across six domains — Governance, Asset Management, Cybersecurity Risk Management, Logical Security, Physical Security, and Third-Party Security — and assigns each to one of three progressive compliance levels: CL1 foundational (116 controls), CL2 advanced (62), and CL3 continuous monitoring and improvement (37). The levels are cumulative, so CL3 compliance means satisfying all 215.
The framework applies to licensees that are not designated Critical National Infrastructure; CNI operators fall under NCA ECC instead. Many licensees carry both obligations. Every CRF control ships with its own cross-references to NCA ECC, NCA CSCC, ISO 27002, ISO 27011/ITU-T X.1051, NIST and SANS CIS, so an organisation that has already completed ECC can reuse that evidence rather than starting again.
Who it applies to
- Telecom operators and MVNOs licensed by CST
- Internet service providers
- Hosting and data centre operators
- Postal and courier companies
- IT service providers holding a CST licence or registration
At a glance
- Issuing authority: Communications, Space & Technology Commission (CST)
- Version: Second Version, October 2023
- Domains: Governance, Asset Management, Risk Management, Logical Security, Physical Security, Third-Party Security
- Controls: 215 across 36 categories
- Compliance levels: CL1 (116), CL2 (62), CL3 (37) — cumulative
- Assessment basis: Annual CST self-assessment; independent audit at CL2 and CL3
How GRCLens supports CST CRF
CST CRF runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Compliance level tracking
Filter and report by CL1, CL2 or CL3 to see exactly what is in scope for your assigned level, and track progression as the programme matures.
Evidence reuse across ECC
CRF's own control mappings to NCA ECC and NCA CSCC are built in, so evidence collected for ECC is surfaced against the matching CRF control instead of being gathered twice.
Six-domain coverage
All 215 controls are individually assessable with status, owner, evidence and AI review — from cybersecurity strategy through to outsourcing and cloud services.
Self-assessment reporting
Produce the evidence pack and status reporting required for the annual CST self-assessment, and for the independent audit that CL2 and CL3 licensees must arrange.
CST CRF frequently asked questions
Who must comply with CST CRF?
Organisations licensed or registered by CST in the ICT sector — telecom operators, internet service providers, MVNOs, hosting and data centre operators, postal and courier companies, and IT service providers. There is no size or revenue exemption; the compliance level varies with scale and risk, but the obligation does not.
How does CRF relate to NCA ECC?
They are complementary, not alternatives. ECC is the national baseline for government entities and Critical National Infrastructure operators. CRF is CST's sector-specific framework for licensed ICT service providers that are not designated CNI. Licensees that are also CNI must satisfy both.
What are CL1, CL2 and CL3?
Three progressive compliance levels. CL1 covers foundational controls, CL2 adds formal risk management and deeper technical and third-party controls, and CL3 focuses on continuous monitoring and improvement of the CL1 and CL2 controls. They are cumulative — reaching CL3 requires all preceding levels.
Which version does GRCLens implement?
The Second Version, issued October 2023, which supersedes the original June 2020 release.
Can GRCLens be hosted in the Kingdom?
Yes. The platform can be deployed on-premises or in a Saudi region, which is the usual arrangement where data residency or licence conditions apply.
One platform, many obligations
Talk to us about CST CRF
Security Solution Consultants provides CST CRF readiness and advisory alongside the platform, so you can combine tooling with hands-on expertise.
Contact us