العربية

Market · State of Kuwait

Find out whether the Central Bank regulates you, first

Kuwait has one of the most demanding financial-sector cyber frameworks in the Gulf and no comprehensive data protection law at all. Which of those two facts applies to you decides everything about the engagement.

What binds you

Reference numbers are taken from the Central Bank's own published framework. Note the direction of travel in Kuwait has not been uniformly forward — see the repeal below.

CBK

Cyber and Operational Resilience Framework

CORF v1.0 · 3 December 2025

Replaces the CBK Cybersecurity Framework of February 2020 and binds every CBK-regulated entity — Kuwaiti and foreign banks, finance companies, exchange companies, electronic payment operators, credit information companies and open banking providers. Three baselines covering cyber resilience, operational resilience and third-party risk, across 27 domains, 93 sub-domains and 876 controls, on a five-level maturity scale. Full compliance with applicable controls is required before an entity can claim baseline level or above.

Who signsCBK-approved independent assessors. Tier 1 annually, Tier 2 every 18 months, Tier 3 two-yearly, plus annual self-assessment submitted in prescribed formats with compliance percentages and maturity levels.
CITRA

Data Privacy Protection Regulation

Amended by Decision 26/2024

The 2024 amendment narrowed the regulation so that it now applies only to CITRA-licensed telecommunications and internet providers. If you are not a licensee, it does not reach you. Obligations for those it does cover run to consent, transparency, security, transfer notices and breach notification.

Who signsCITRA inspects licensees and refers suspected criminal violations onward.
CAIT

Electronic Transactions Law

Law 20/2014

With no general data protection statute, this is the baseline for anyone handling electronic records: consent before collection and processing, accuracy, and security safeguards. Overseen by the Central Agency for Information Technology. It is thin, and it is what there is.

Who signsNo assessment regime.

The data classification policy was repealed

In February 2024 Kuwait repealed its data classification policy, eliminating the tiered sensitivity framework. Storage and transfer now rest primarily on the consent provisions of the Electronic Transactions Law. This is a reversal, not an advance, and it is frequently mis-stated in vendor material that still cites the classification tiers as current. If a proposal scopes work around Kuwaiti data classification levels, that proposal is out of date.

We could not confirm a CITRA national cyber framework exists

Searches for a published, named CITRA cyber security framework returned only vendor pages and NIST material — no primary source. Kuwait's verified binding cyber framework is the CBK's, and it is banking-only. We would rather tell you we could not find something than describe an instrument we have not read. If you hold a copy of one, we would genuinely like to see it.

Two very different engagements

If you are CBK-regulated

  • Establish your tier first — it sets the assessment cadence and therefore the budget.
  • Readiness against the three baselines, ahead of the CBK-approved assessor rather than instead of them.
  • The 876 controls are not all applicable; scoping them down is most of the value.
  • Third-party risk is a full baseline in its own right here, not a chapter.

If you are not

  • There is no general framework to certify against, and we will not invent one.
  • The useful work is contractual and operational: what you promise customers, and whether you can keep it.
  • ISO/IEC 27001 remains a reasonable voluntary anchor — sold as good practice, not as Kuwaiti compliance.
  • Watch for a general data protection law. Kuwait is the last GCC state without one.

Start with a scoping call

The first question is simply whether the Central Bank regulates you. Everything else follows from the answer.