Country guide · Oman

Cyber security compliance in Oman

Oman does not have a single national cybersecurity control framework. Obligations come from the Personal Data Protection Law, sector regulators such as the Central Bank of Oman, and government security guidelines from the Ministry of Transport, Communications and Information Technology. 2026 brought two significant legal changes, and many published guides have not caught up with either.

At a glance
  • Frameworks listed4
  • Issuing bodies4
  • Framework pages2
  • Platform languagesEnglish and Arabic
  • DeploymentSaaS, private cloud or on-premises
OmanChecked Sep 2026
What applies

Cybersecurity and data protection frameworks in Oman

Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.

Which cybersecurity rules apply in Oman?

For most organisations, two instruments matter: the Personal Data Protection Law for anyone handling personal data, and the Central Bank of Oman's Cybersecurity and Resilience Framework for financial institutions. Government entities also work to MTCIT's security guidelines, including its Basic Information Security Controls and Cybersecurity Governance Guideline.

OCERT, the Oman National CERT within MTCIT, issues alerts and runs national programmes. It is not the regulator, although it is often described as one.

What changed in Oman's PDPL in 2026?

Royal Decree 68/2026, published in September 2026, amends the Personal Data Protection Law, covering scope, exemptions, consent and permit rules and automated processing. It builds on the Executive Regulation issued by Ministerial Decision 34/2024 in February 2024. Most published guidance predates the amendment, so check any compliance plan against the amended text.

What does the Central Bank of Oman require?

CBO lists a Cybersecurity and Resilience Framework and a cloud computing policy among its policies for licensed institutions. The framework applies to banks, finance and leasing companies, money exchange companies and payment service providers, and it organises controls across governance, risk management, technology and operations, third parties, online financial services and compliance.

Is there a national cybersecurity law in Oman?

Not a control framework of the kind Saudi Arabia or Qatar publish. A new cybercrime law, Royal Decree 61/2026, was reported in June 2026 as replacing Royal Decree 12/2011, and a national cybersecurity strategy for 2026 to 2030 was reported in August 2026. Pages still citing the 2011 cybercrime law as current are out of date.

How GRCLens runs Omani obligations together

The PDPL and the CBO framework sit on the same control model in GRCLens as ISO/IEC 27001, so a bank evidences access control, incident handling and third-party oversight once for both. The platform runs in English and Arabic and can be hosted in Oman or fully on-premises.

Questions

Cyber compliance in Oman: common questions

Has Oman's Personal Data Protection Law been amended?

Yes. Royal Decree 68/2026, published in September 2026, amends the law, including scope, exemptions, consent and permit rules and automated processing.

Who regulates personal data protection in Oman?

The Ministry of Transport, Communications and Information Technology (MTCIT), which issued the Executive Regulation by Ministerial Decision 34/2024.

Is OCERT Oman's cybersecurity regulator?

No. OCERT, the Oman National CERT, sits within MTCIT and issues alerts and runs national programmes. Obligations come from laws and sector regulators.

Which institutions does the CBO Cybersecurity and Resilience Framework cover?

Banks, finance and leasing companies, money exchange companies and payment service providers licensed by the Central Bank of Oman.

Sources

Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.

Run Oman's frameworks on one platform

See GRCLens with your own frameworks loaded.