Market pack
Kuwait
A regulator-issued cyber security framework and a separate data privacy regulation, applied across a market where central bank expectations set the pace for the private sector.
- PRIMARY AUTHORITIES
- CITRA, Central Bank of Kuwait
- INSTRUMENTS IN THIS PACK
- 5 national and sector, plus 13 international standards
- CONTRACTING
- Served from our registered Gulf entities. A local entity will follow a client requirement.
Regulatory register
What applies, to whom, and what the platform does about it. Indicative and maintained as the instruments change — applicability is confirmed per client during scoping.
| Authority or instrument | What it is | Who it applies to | What the platform does |
|---|---|---|---|
| CITRA | Cyber Security Framework | Government entities, telecom operators and organisations within CITRA scope | Control mapping, compliance position and evidence per control |
| CITRA | Data Privacy Protection Regulation | Telecom and IT service providers, and organisations handling personal data within scope | Processing records, consent handling, rights workflow, transfer and breach provisions |
| CITRA | Cloud computing regulatory framework and data classification rules | Cloud tenants and providers | Classification-driven hosting position and provider responsibility split |
| Central Bank of Kuwait | Cyber security framework, technology risk and business continuity instructions | Licensed banks and financial institutions | Control mapping, continuity evidence, outsourcing registers and incident reporting |
| Capital Markets Authority | Technology and operational requirements for licensed persons | Licensed capital markets participants | Sector obligations tracked in the same regulatory register |
| Standard | Scope | How it is used |
|---|---|---|
| ISO/IEC 27001:2022 and 27002 | Information security management system and control set | Certification readiness, live Statement of Applicability, continuous gap position |
| ISO/IEC 27701 | Privacy information management | Extends the ISMS control set with privacy-specific controls and DPO workflow |
| ISO/IEC 27017 and 27018 | Cloud security and cloud personal data | Applied where the estate is cloud-hosted or cloud-delivered |
| ISO 22301 | Business continuity management | BIA, recovery objectives, plan currency and exercise evidence |
| ISO/IEC 42001:2023 | AI management system | AI inventory, impact assessment and model governance |
| NIST CSF 2.0 | Cybersecurity framework | Used as the neutral spine when several national regimes apply at once |
| NIST SP 800-53 Rev. 5 | Control catalogue | Depth mapping where a client's control set is US-derived |
| CIS Controls v8 | Prioritised technical control set | Common baseline for technology teams |
| COBIT 2019 | Technology governance | Used in the Govern pillar for IT and digital governance structures |
| SOC 2 | Service organisation controls | Trust services criteria for clients who serve enterprise customers |
| PCI DSS 4.0 | Payment card security | Applied where card data is in scope |
| IEC 62443 | Industrial automation and control systems | Applied to OT estates alongside the national OT controls |
| Open FAIR | Risk quantification taxonomy | The quantification method used throughout the Anticipate pillar |
Hosting and contracting
Settle residency before tenant design. It is the item most often left until too late.
Data residency
CITRA classification and cloud rules determine where data can sit. Confirm classification before tenant design; it is the item most often left until too late.
Contracting entity
Served from our registered Gulf entities. A local entity will follow a client requirement, not precede it.