CYBER · PRIVACY · DIGITAL TRUSTPowered by Falconry360 Book a working session

Home/Markets/Oman

Market pack

Oman

A national cyber security framework, a central bank regime for financial institutions, and a data protection law now supported by executive regulations. The three are usually run as separate programmes; they do not need to be.

PRIMARY AUTHORITIES
OCERT-MTCIT, Central Bank of Oman, FSA
INSTRUMENTS IN THIS PACK
6 national and sector, plus 13 international standards
CONTRACTING
Registered Omani entity, with the firm's longest delivery record in any market.

Regulatory register

What applies, to whom, and what the platform does about it. Indicative and maintained as the instruments change — applicability is confirmed per client during scoping.

Oman — national and sector regulation
Authority or instrumentWhat it isWho it applies toWhat the platform does
Ministry of Transport, Communications and Information TechnologyNational cyber security framework and information security standardsGovernment entities and designated organisationsControl mapping, maturity position and evidence maintained continuously
Oman National CERTIncident reporting and national coordination requirementsOrganisations within national scopeNotification workflow with the reporting clock built into the incident record
Central Bank of OmanCyber security, technology risk and business continuity requirementsLicensed banks and financial institutionsControl mapping, third-party registers, continuity evidence and incident reporting
Royal Decree 6 of 2022Personal Data Protection Law and its executive regulationsControllers and processors in the SultanateProcessing records, permit and consent handling, rights workflow, transfer assessment, breach notification
Financial Services AuthorityCapital markets and insurance technology and governance requirementsLicensed market and insurance participantsSector obligations tracked in the same regulatory register
Cyber Defence CentreNational cyber defence coordination and sector directivesCNI and government-linked operatorsDirectives tracked as regulatory change with impact routed to control owners
International standards operating alongside the national regimes
StandardScopeHow it is used
ISO/IEC 27001:2022 and 27002Information security management system and control setCertification readiness, live Statement of Applicability, continuous gap position
ISO/IEC 27701Privacy information managementExtends the ISMS control set with privacy-specific controls and DPO workflow
ISO/IEC 27017 and 27018Cloud security and cloud personal dataApplied where the estate is cloud-hosted or cloud-delivered
ISO 22301Business continuity managementBIA, recovery objectives, plan currency and exercise evidence
ISO/IEC 42001:2023AI management systemAI inventory, impact assessment and model governance
NIST CSF 2.0Cybersecurity frameworkUsed as the neutral spine when several national regimes apply at once
NIST SP 800-53 Rev. 5Control catalogueDepth mapping where a client's control set is US-derived
CIS Controls v8Prioritised technical control setCommon baseline for technology teams
COBIT 2019Technology governanceUsed in the Govern pillar for IT and digital governance structures
SOC 2Service organisation controlsTrust services criteria for clients who serve enterprise customers
PCI DSS 4.0Payment card securityApplied where card data is in scope
IEC 62443Industrial automation and control systemsApplied to OT estates alongside the national OT controls
Open FAIRRisk quantification taxonomyThe quantification method used throughout the Anticipate pillar

Hosting and contracting

Settle residency before tenant design. It is the item most often left until too late.

Data residency

Data classification under the national framework should drive hosting. Regional hosting is generally acceptable for private-sector workloads; government and CNI positions are confirmed case by case.

Contracting entity

Registered Omani entity, with the firm's longest delivery record in any market. Omani clients contract locally.

How Falconry360 is hosted and secured

THE OMAN PICTURE

Our longest delivery record in any market, and the one where the regulatory picture moved fastest.

Oman has gone from a light regulatory footprint to a national cyber framework, an active central bank regime and a data protection law with executive regulations — inside four years. Organisations that built their control environment before that shift are the ones we are usually asked to help.

What is different here

  • A compact market with real supervision. The Central Bank of Oman's expectations of licensed institutions are detailed and examined. The Financial Services Authority applies its own requirements to market and insurance participants.
  • The PDPL is now operational, not theoretical. Royal Decree 6 of 2022 and its executive regulations created obligations — permits, consent handling, transfer conditions, breach notification — that many organisations documented but never operationalised.
  • National coordination is active. Incident reporting obligations into the national CERT and sector directives from the Cyber Defence Centre are real reporting lines with real clocks.
  • Energy and utilities carry an OT perimeter. Distributed physical estates, vendor remote access and IT-OT convergence make the risk picture different from a purely corporate one.
  • Teams are small. A Omani security function is frequently three or four people carrying the same obligations as a team of thirty elsewhere. Automation and managed operation are not a luxury here; they are how the obligations get met at all.

What a first engagement usually looks like

Indicative. Scope, estate size and the number of regimes in play move the dates.

  • Weeks 1–3 · The real obligation set

    National framework, central bank or FSA requirements, PDPL obligations and sector directives, resolved into one list with owners — rather than four programmes run by the same four people.

  • Weeks 4–8 · Control library and evidence

    One control set covering the national framework and the sector regime, with evidence collected from source systems so the small team is not the bottleneck.

  • Weeks 9–14 · Privacy operations

    PDPL obligations turned into working routines — processing records, permit and consent handling, transfer assessment and a breach workflow with the notification clock built in.

  • Ongoing · Operated, not just implemented

    Where the team is small, we run the routine under managed services and the team keeps the decisions. This is the most common shape of engagement in the Sultanate.

Falconry holds a registered Omani entity, with the firm's longest delivery record in any market — across banking, energy and government-linked organisations.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.