Cyber security compliance in Kuwait
Kuwait's rulebook changed substantially between late 2025 and 2026. The Central Bank replaced its 2020 cybersecurity framework with a broader resilience framework, and the National Cyber Security Center issued national basic controls with an 18-month compliance window. Much of what ranks online still describes the old position. This page sets out what applies now.
- Frameworks listed6
- Issuing bodies3
- Framework pages2
- Platform languagesEnglish and Arabic
- DeploymentSaaS, private cloud or on-premises
Cybersecurity and data protection frameworks in Kuwait
Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.
National Basic Cybersecurity Controls (NCSC Decision 2/2026)
Government bodies, including civil, military and security bodies, and critical private sector operators. Issued April 2026 with 18 months to comply
Open the framework page →Cyber and Operational Resilience Framework (CORF) v1.0
All CBK-regulated entities. Issued 3 December 2025, replacing the 2020 Cybersecurity Framework
Open the framework page →National Framework for Cybersecurity Governance (NCSC Decision 35/2023)
Government bodies and the public and private institutions within NCSC's remit
National Framework for Data Classification (NCSC Decision 1/2025)
Entities within NCSC's remit
Data Privacy Protection Regulation (Resolution 26/2024)
CITRA licensees, such as telecom and ICT service providers. Replaced Resolution 42/2021
Cloud Computing Regulatory Framework
Cloud service providers and their customers in Kuwait's ICT sector
Which cybersecurity frameworks apply in Kuwait?
Two sets matter most. The National Cyber Security Center's National Basic Cybersecurity Controls apply to government bodies and critical private sector operators, and the Central Bank of Kuwait's Cyber and Operational Resilience Framework applies to every CBK-regulated entity. Around them sit NCSC's governance and data classification frameworks and CITRA's rules for its licensees.
What did the CBK change in December 2025?
CBK issued its Cyber and Operational Resilience Framework, CORF v1.0, on 3 December 2025. It supersedes the 2020 Cybersecurity Framework and widens the scope from cybersecurity to operational resilience and third-party risk.
The assessment model is precise. Each control is rated Compliant, Non-Compliant or Not Applicable on documented evidence, maturity is scored on five levels, and a Statement of Applicability goes to CBK. Entities complete an annual self-assessment and an annual independent assessment. Pages that still describe the 2020 framework as current are out of date.
When must the National Basic Cybersecurity Controls be met?
NCSC Decision 2/2026 was issued on 5 April 2026 and reported to give covered entities 18 months to comply, which points to October 2027. Scope covers government bodies, including civil, military and security bodies, and critical private sector operators. The controls follow the NIST CSF functions, Govern, Identify, Protect, Detect, Respond and Recover, with a cloud appendix.
Does Kuwait have a data protection law?
Not a comprehensive one as of September 2026. CITRA's Data Privacy Protection Regulation, Resolution 26/2024, applies to CITRA licensees only. Sources describing it as a national "Kuwait PDPL" overstate its reach. Organisations outside CITRA's licensing still carry data obligations through sector regulators such as CBK.
How GRCLens runs Kuwaiti frameworks together
NBCC and CBK CORF sit on the same shared control model as ISO/IEC 27001 and NIST CSF in GRCLens, so a bank that is also designated critical infrastructure evidences each control once for both. CORF's Compliant, Non-Compliant and Not Applicable ratings, maturity scores and Statement of Applicability are produced from the same records. The platform runs in English and Arabic and can be hosted in Kuwait or fully on-premises.
Official portals and publications
Cyber compliance in Kuwait: common questions
What replaced the CBK Cybersecurity Framework of 2020?
The Cyber and Operational Resilience Framework (CORF) v1.0, issued by the Central Bank of Kuwait on 3 December 2025. It applies to all CBK-regulated entities and adds operational resilience and third-party risk.
Who must comply with Kuwait's National Basic Cybersecurity Controls?
Government bodies, including civil, military and security bodies, and critical private sector operators, under NCSC Decision 2/2026 issued in April 2026.
What is the deadline for NCSC Decision 2/2026?
It is reported to allow 18 months from issue on 5 April 2026, which points to October 2027.
Is there a Kuwait personal data protection law?
Not a comprehensive one as of September 2026. CITRA's Data Privacy Protection Regulation (Resolution 26/2024) applies to CITRA licensees.
How does CBK assess CORF compliance?
Each control is rated Compliant, Non-Compliant or Not Applicable on evidence, maturity is scored on five levels, and entities complete an annual self-assessment and an annual independent assessment.
Sources
Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.

Run Kuwait's frameworks on one platform
See GRCLens with your own frameworks loaded.