Central Bank of Kuwait (CBK) · Kuwait

Central Bank of Kuwait Cyber and Operational Resilience Framework compliance software

The Central Bank of Kuwait's resilience-first framework for banks and financial institutions — cyber resilience, operational resilience and third-party risk, 875 controls generated from CBK's own text.

At a glance
  • InstrumentCBK CORF v1.0, issued 3 December 2025
  • BaselinesCyber Resilience · Operational Resilience · Third-Party Risk Management
  • Controls875 across 25 assessed domains, generated from CBK's text
  • AlignmentMapped to NIST CSF, ISO/IEC 27001 and COBIT practices
CBK CORFAvailable
Overview

What CBK CORF requires

Who it applies to

  • Local banks licensed by the Central Bank of Kuwait
  • Regulated financial institutions — finance and investment companies, exchange companies, payment providers under CBK supervision
  • Group functions overseeing several CBK-regulated entities
  • Critical third parties and outsourcing providers, in support of their clients' TPRM baseline

On 3 December 2025 the Central Bank of Kuwait issued the Cyber and Operational Resilience Framework, version 1.0, for all local banks and regulated financial institutions. It replaces a control-centric regime with a resilience-first one: the question is no longer only whether a control exists but whether the institution can absorb a disruption, keep its critical services running and recover.

The framework is organised as three baselines. Cyber Resilience covers governance, risk and compliance, technology and operations, third-party and supply-chain risk, emerging technologies, payments security and operational resilience. Operational Resilience covers governance and oversight, risk and threat management, business continuity, technology resilience, incident and crisis management, and testing, training and continuous improvement. Third-Party Risk Management runs from governance and contractual terms through monitoring, exit strategy, data storage, cross-border transactions and cloud usage to inter-affiliate arrangements.

GRCLens's catalogue is generated from CBK's own 389-page framework document by an extractor that refuses to write unless the chapter structure it finds matches the framework exactly — so a revision to the text fails loudly rather than seeding a catalogue that quietly differs from what CBK published. The two Operational Resilience domains that restate the Third-Party and Cyber baselines are not duplicated.

In the platform

How GRCLens supports CBK CORF

CBK CORF runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Three baselines, one programme

Cyber, operational and third-party resilience assessed as one framework, with each control carrying its CBK section reference so an examiner can follow it back to the text.

Generated, not transcribed

The catalogue is produced from CBK's own document by code that checks the chapter structure before it writes. A revised framework cannot silently seed a different control set.

Third-party risk joined to the vendor register

The TPRM baseline's thirteen domains — governance, contracts, monitoring, BCM, incidents, data, sub-contracting, exit, storage, cross-border, cloud, inter-affiliates — draw on the vendor register the tenant already keeps.

Resilience indicators

Recovery-time results, restore-test pass rates and incident metrics are held as key risk indicators in the risk register, tied to the resilience risks they measure, so 'resilient' is a measured claim rather than an asserted one.

Questions

CBK CORF frequently asked questions

Who must comply with CBK's CORF?

All local banks and the financial institutions regulated by the Central Bank of Kuwait. CBK issued the framework on 3 December 2025 as a mandatory regulatory framework.

How large is the framework?

CBK describes 27 domains, 93 sub-domains, 200 control areas and around 876 controls across three baselines. GRCLens assesses 875 controls across 25 domains: two Operational Resilience domains restate the Third-Party and Cyber baselines and are not duplicated.

How does CORF relate to Kuwait's NBCC?

NBCC is the national minimum baseline from the National Cyber Security Centre; CORF is CBK's sector framework and far more detailed. A bank answers to both, and GRCLens assesses shared controls once for both.

Talk to us about CBK CORF

Security Solution Consultants provides CBK CORF readiness and advisory alongside the platform, so you can combine tooling with hands-on expertise.