Market pack
Bahrain
A cloud-first public sector, a detailed central bank rulebook, and one of the region's earliest personal data protection laws. Compact market, high regulatory density.
- PRIMARY AUTHORITIES
- National Cyber Security Centre, CBB, PDPA
- INSTRUMENTS IN THIS PACK
- 4 national and sector, plus 13 international standards
- CONTRACTING
- Served from our registered Gulf entities. A local entity will follow a client requirement.
Regulatory register
What applies, to whom, and what the platform does about it. Indicative and maintained as the instruments change — applicability is confirmed per client during scoping.
| Authority or instrument | What it is | Who it applies to | What the platform does |
|---|---|---|---|
| National Cyber Security Centre | National cyber security strategy, standards and directives | Government entities and designated critical sectors | Control mapping, maturity position and evidence maintained against the national control set |
| Central Bank of Bahrain | CBB Rulebook — operational risk, cyber security, business continuity and outsourcing modules | Licensed banks, insurers, investment firms and payment providers | Rulebook obligations mapped to the unified control set, with outsourcing and continuity registers and incident reporting workflow |
| Law No. 30 of 2018 | Personal Data Protection Law | Controllers and processors in the Kingdom | Processing records, notification and permit tracking, rights handling, transfer assessment, breach workflow |
| Information and eGovernment Authority | Government information security and cloud standards | Public sector entities and their suppliers | Standards mapped alongside the national control set |
| Standard | Scope | How it is used |
|---|---|---|
| ISO/IEC 27001:2022 and 27002 | Information security management system and control set | Certification readiness, live Statement of Applicability, continuous gap position |
| ISO/IEC 27701 | Privacy information management | Extends the ISMS control set with privacy-specific controls and DPO workflow |
| ISO/IEC 27017 and 27018 | Cloud security and cloud personal data | Applied where the estate is cloud-hosted or cloud-delivered |
| ISO 22301 | Business continuity management | BIA, recovery objectives, plan currency and exercise evidence |
| ISO/IEC 42001:2023 | AI management system | AI inventory, impact assessment and model governance |
| NIST CSF 2.0 | Cybersecurity framework | Used as the neutral spine when several national regimes apply at once |
| NIST SP 800-53 Rev. 5 | Control catalogue | Depth mapping where a client's control set is US-derived |
| CIS Controls v8 | Prioritised technical control set | Common baseline for technology teams |
| COBIT 2019 | Technology governance | Used in the Govern pillar for IT and digital governance structures |
| SOC 2 | Service organisation controls | Trust services criteria for clients who serve enterprise customers |
| PCI DSS 4.0 | Payment card security | Applied where card data is in scope |
| IEC 62443 | Industrial automation and control systems | Applied to OT estates alongside the national OT controls |
| Open FAIR | Risk quantification taxonomy | The quantification method used throughout the Anticipate pillar |
Hosting and contracting
Settle residency before tenant design. It is the item most often left until too late.
Data residency
The national cloud-first position makes regional hosting workable for most workloads. CBB-licensed firms should test the position against the outsourcing module before tenant design.
Contracting entity
Served from our registered Gulf entities. A local entity will follow a client requirement, not precede it.