Country guide · Kuwait

Cyber security compliance in Kuwait

Kuwait's rulebook changed substantially between late 2025 and 2026. The Central Bank replaced its 2020 cybersecurity framework with a broader resilience framework, and the National Cyber Security Center issued national basic controls with an 18-month compliance window. Much of what ranks online still describes the old position. This page sets out what applies now.

At a glance
  • Frameworks listed6
  • Issuing bodies3
  • Framework pages2
  • Platform languagesEnglish and Arabic
  • DeploymentSaaS, private cloud or on-premises
KuwaitChecked Sep 2026
What applies

Cybersecurity and data protection frameworks in Kuwait

Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.

National Cyber Security Center (NCSC)

National Basic Cybersecurity Controls (NCSC Decision 2/2026)

Government bodies, including civil, military and security bodies, and critical private sector operators. Issued April 2026 with 18 months to comply

Open the framework page →
Central Bank of Kuwait (CBK)

Cyber and Operational Resilience Framework (CORF) v1.0

All CBK-regulated entities. Issued 3 December 2025, replacing the 2020 Cybersecurity Framework

Open the framework page →
National Cyber Security Center (NCSC)

National Framework for Cybersecurity Governance (NCSC Decision 35/2023)

Government bodies and the public and private institutions within NCSC's remit

National Cyber Security Center (NCSC)

National Framework for Data Classification (NCSC Decision 1/2025)

Entities within NCSC's remit

CITRA

Data Privacy Protection Regulation (Resolution 26/2024)

CITRA licensees, such as telecom and ICT service providers. Replaced Resolution 42/2021

CITRA

Cloud Computing Regulatory Framework

Cloud service providers and their customers in Kuwait's ICT sector

Which cybersecurity frameworks apply in Kuwait?

Two sets matter most. The National Cyber Security Center's National Basic Cybersecurity Controls apply to government bodies and critical private sector operators, and the Central Bank of Kuwait's Cyber and Operational Resilience Framework applies to every CBK-regulated entity. Around them sit NCSC's governance and data classification frameworks and CITRA's rules for its licensees.

What did the CBK change in December 2025?

CBK issued its Cyber and Operational Resilience Framework, CORF v1.0, on 3 December 2025. It supersedes the 2020 Cybersecurity Framework and widens the scope from cybersecurity to operational resilience and third-party risk.

The assessment model is precise. Each control is rated Compliant, Non-Compliant or Not Applicable on documented evidence, maturity is scored on five levels, and a Statement of Applicability goes to CBK. Entities complete an annual self-assessment and an annual independent assessment. Pages that still describe the 2020 framework as current are out of date.

When must the National Basic Cybersecurity Controls be met?

NCSC Decision 2/2026 was issued on 5 April 2026 and reported to give covered entities 18 months to comply, which points to October 2027. Scope covers government bodies, including civil, military and security bodies, and critical private sector operators. The controls follow the NIST CSF functions, Govern, Identify, Protect, Detect, Respond and Recover, with a cloud appendix.

Does Kuwait have a data protection law?

Not a comprehensive one as of September 2026. CITRA's Data Privacy Protection Regulation, Resolution 26/2024, applies to CITRA licensees only. Sources describing it as a national "Kuwait PDPL" overstate its reach. Organisations outside CITRA's licensing still carry data obligations through sector regulators such as CBK.

How GRCLens runs Kuwaiti frameworks together

NBCC and CBK CORF sit on the same shared control model as ISO/IEC 27001 and NIST CSF in GRCLens, so a bank that is also designated critical infrastructure evidences each control once for both. CORF's Compliant, Non-Compliant and Not Applicable ratings, maturity scores and Statement of Applicability are produced from the same records. The platform runs in English and Arabic and can be hosted in Kuwait or fully on-premises.

Questions

Cyber compliance in Kuwait: common questions

What replaced the CBK Cybersecurity Framework of 2020?

The Cyber and Operational Resilience Framework (CORF) v1.0, issued by the Central Bank of Kuwait on 3 December 2025. It applies to all CBK-regulated entities and adds operational resilience and third-party risk.

Who must comply with Kuwait's National Basic Cybersecurity Controls?

Government bodies, including civil, military and security bodies, and critical private sector operators, under NCSC Decision 2/2026 issued in April 2026.

What is the deadline for NCSC Decision 2/2026?

It is reported to allow 18 months from issue on 5 April 2026, which points to October 2027.

Is there a Kuwait personal data protection law?

Not a comprehensive one as of September 2026. CITRA's Data Privacy Protection Regulation (Resolution 26/2024) applies to CITRA licensees.

How does CBK assess CORF compliance?

Each control is rated Compliant, Non-Compliant or Not Applicable on evidence, maturity is scored on five levels, and entities complete an annual self-assessment and an annual independent assessment.

Sources

Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.

Run Kuwait's frameworks on one platform

See GRCLens with your own frameworks loaded.