GCC testing obligations run on different cycles. Bahrain's CBB is twice-yearly, commonly aligned to 30 September and 31 March reporting. Saudi Arabia's NCA ECC requires periodic testing (CSCC adds a six-month interval for critical systems); SAMA is maturity-driven. Card handlers under PCI DSS test at least every 12 months and after significant change. The universal rule: test at least annually, with finance and critical infrastructure on tighter semi-annual cycles — and book 6–10 weeks before each deadline to leave room for remediation and retesting. One well-scoped test can satisfy several regulators at once.
// 01 Why a calendar beats a scramble
The organisations that get caught out aren't the ones that ignore testing — they're the ones that leave it too late. A penetration test isn't instant: it takes one to three weeks of active testing plus scoping and reporting, and then you need time to fix the findings and retest before the report is due. Compress that against a fixed regulator deadline and you end up submitting a report full of open critical findings, or missing the date. Treating testing as a recurring, calendared programme — slotted against each regulator's cycle — removes the panic and produces a clean submission.
// 02 The regulator-by-regulator cycle
| Country | Regulator / Framework | Testing cycle | Detail |
|---|---|---|---|
| Bahrain | CBB | Twice-yearly | Reporting commonly ~30 Sep & 31 Mar |
| Saudi Arabia | NCA ECC | Periodic | CSCC adds 6-month interval (critical systems) |
| Saudi Arabia | SAMA CSF | Maturity-driven | Pentest + red teaming at higher levels |
| UAE | IA / NESA, DESC, ADHICS | Periodic | Sector-specific (Dubai, Abu Dhabi, health) |
| Qatar | QCB / NIA | Periodic | Central-bank & national framework |
| Kuwait | CBK | Periodic | Central-bank cyber framework |
| Oman | CBO / national | Periodic | Sector frameworks |
| Regional | PCI DSS v4.0 | 12 months + change | Segmentation 6 months (service providers) |
Dates and cycles evolve — always confirm the current requirement with your regulator or through the per-country guides linked above. Where a specific reporting date is cited (such as the CBB's), treat it as the typical alignment rather than a guarantee for every licensee.
// 03 The buying windows
Work backwards from each deadline. Because you need testing plus remediation plus retesting before the report is due, the sensible booking point is 6–10 weeks ahead:
- CBB (Bahrain): for a 30 September cycle, scope in July–August; for a 31 March cycle, scope in January–February.
- PCI DSS renewals: book two to three months before your assessment date, and after any significant change in between.
- NCA / SAMA: align to your assessment or audit schedule; critical-system operators should assume a semi-annual rhythm.
- New systems or launches: test before go-live, not after — see testing before launch.
// 04 One test, several regulators
If you operate across more than one GCC market or framework, you rarely need a separate test for each. A single engagement, scoped to cover the systems every applicable regulator cares about and reported with findings mapped to each framework, can satisfy several at once — an NCA ECC obligation and a PCI DSS requirement, for instance, from one test. The trick is to set your cadence to the strictest regulator that applies (usually the twice-yearly financial ones), then schedule the engagement so its report lands ahead of every deadline. Map your exact obligations with the requirements finder and the requirements-by-framework guide.
// 05 Frequently asked questions
When are GCC penetration testing deadlines?
Bahrain's CBB runs twice-yearly, commonly aligned to 30 September and 31 March. Saudi Arabia's NCA ECC requires periodic testing (CSCC adds a six-month interval for critical systems); SAMA is maturity-driven. PCI DSS card handlers test at least every 12 months and after significant change. Most obligations reduce to at least annual, with finance and critical infrastructure on semi-annual cycles.
How far ahead should you book?
Six to ten weeks before the deadline. Testing takes 1–3 weeks plus scoping and reporting, and you need time afterwards to remediate and retest before the report is due. Last-minute booking means submitting with open critical findings or missing the date.
Does one test cover multiple regulators?
Often — if scoped to each regulator's systems and reported with findings mapped to each framework. One annual engagement can serve an NCA ECC obligation and a PCI DSS requirement at once. Align cadence to the strictest regulator, then schedule one engagement to satisfy the others.
Which sectors have the strictest cycles?
Financial services and critical infrastructure. Banks and payment providers face central-bank frameworks (CBB, SAMA) plus PCI DSS, often driving semi-annual testing. OT and critical-infrastructure operators face additional controls like NCA OTCC. Plan these as recurring calendared programmes.