Cyber security compliance in Oman
Oman does not have a single national cybersecurity control framework. Obligations come from the Personal Data Protection Law, sector regulators such as the Central Bank of Oman, and government security guidelines from the Ministry of Transport, Communications and Information Technology. 2026 brought two significant legal changes, and many published guides have not caught up with either.
- Frameworks listed4
- Issuing bodies4
- Framework pages2
- Platform languagesEnglish and Arabic
- DeploymentSaaS, private cloud or on-premises
Cybersecurity and data protection frameworks in Oman
Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.
Personal Data Protection Law (Royal Decree 6/2022)
Controllers and processors of personal data in Oman. Executive Regulation issued February 2024; amended by Royal Decree 68/2026
Open the framework page →Cybersecurity and Resilience Framework
Banks, finance and leasing companies, money exchange companies and payment service providers
Open the framework page →Basic Information Security Controls and Cybersecurity Governance Guideline
Government entities, published in MTCIT's guidelines library
Cybercrime Law (Royal Decree 61/2026)
Everyone. Reported in June 2026 as replacing the 2011 law
Which cybersecurity rules apply in Oman?
For most organisations, two instruments matter: the Personal Data Protection Law for anyone handling personal data, and the Central Bank of Oman's Cybersecurity and Resilience Framework for financial institutions. Government entities also work to MTCIT's security guidelines, including its Basic Information Security Controls and Cybersecurity Governance Guideline.
OCERT, the Oman National CERT within MTCIT, issues alerts and runs national programmes. It is not the regulator, although it is often described as one.
What changed in Oman's PDPL in 2026?
Royal Decree 68/2026, published in September 2026, amends the Personal Data Protection Law, covering scope, exemptions, consent and permit rules and automated processing. It builds on the Executive Regulation issued by Ministerial Decision 34/2024 in February 2024. Most published guidance predates the amendment, so check any compliance plan against the amended text.
What does the Central Bank of Oman require?
CBO lists a Cybersecurity and Resilience Framework and a cloud computing policy among its policies for licensed institutions. The framework applies to banks, finance and leasing companies, money exchange companies and payment service providers, and it organises controls across governance, risk management, technology and operations, third parties, online financial services and compliance.
Is there a national cybersecurity law in Oman?
Not a control framework of the kind Saudi Arabia or Qatar publish. A new cybercrime law, Royal Decree 61/2026, was reported in June 2026 as replacing Royal Decree 12/2011, and a national cybersecurity strategy for 2026 to 2030 was reported in August 2026. Pages still citing the 2011 cybercrime law as current are out of date.
How GRCLens runs Omani obligations together
The PDPL and the CBO framework sit on the same control model in GRCLens as ISO/IEC 27001, so a bank evidences access control, incident handling and third-party oversight once for both. The platform runs in English and Arabic and can be hosted in Oman or fully on-premises.
Official portals and publications
Cyber compliance in Oman: common questions
Has Oman's Personal Data Protection Law been amended?
Yes. Royal Decree 68/2026, published in September 2026, amends the law, including scope, exemptions, consent and permit rules and automated processing.
Who regulates personal data protection in Oman?
The Ministry of Transport, Communications and Information Technology (MTCIT), which issued the Executive Regulation by Ministerial Decision 34/2024.
Is OCERT Oman's cybersecurity regulator?
No. OCERT, the Oman National CERT, sits within MTCIT and issues alerts and runs national programmes. Obligations come from laws and sector regulators.
Which institutions does the CBO Cybersecurity and Resilience Framework cover?
Banks, finance and leasing companies, money exchange companies and payment service providers licensed by the Central Bank of Oman.
Sources
Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.

Run Oman's frameworks on one platform
See GRCLens with your own frameworks loaded.