Blog · N.20 · Local Hub

GCC cybersecurity compliance calendar: testing deadlines by regulator

Across the GCC, a missed testing deadline isn't a paperwork problem — it's a regulatory finding. Every regulator runs on its own cycle, and the organisations that stay clean treat penetration testing as a calendared programme, booked months ahead, not a scramble before a submission date.

CBBNCA & SAMAUAEPCI DSSDeadlines
Plan Ahead: CBB = Twice-yearly (~30 Sep / 31 Mar) · NCA = Periodic (CSCC 6-month) · SAMA = Maturity-driven · PCI = 12 Months + Change · Book 6–10 Weeks Early Plan Ahead: CBB = Twice-yearly (~30 Sep / 31 Mar) · NCA = Periodic (CSCC 6-month) · SAMA = Maturity-driven · PCI = 12 Months + Change · Book 6–10 Weeks Early
// TL;DR

GCC testing obligations run on different cycles. Bahrain's CBB is twice-yearly, commonly aligned to 30 September and 31 March reporting. Saudi Arabia's NCA ECC requires periodic testing (CSCC adds a six-month interval for critical systems); SAMA is maturity-driven. Card handlers under PCI DSS test at least every 12 months and after significant change. The universal rule: test at least annually, with finance and critical infrastructure on tighter semi-annual cycles — and book 6–10 weeks before each deadline to leave room for remediation and retesting. One well-scoped test can satisfy several regulators at once.

// 01 Why a calendar beats a scramble

The organisations that get caught out aren't the ones that ignore testing — they're the ones that leave it too late. A penetration test isn't instant: it takes one to three weeks of active testing plus scoping and reporting, and then you need time to fix the findings and retest before the report is due. Compress that against a fixed regulator deadline and you end up submitting a report full of open critical findings, or missing the date. Treating testing as a recurring, calendared programme — slotted against each regulator's cycle — removes the panic and produces a clean submission.

// 02 The regulator-by-regulator cycle

CountryRegulator / FrameworkTesting cycleDetail
BahrainCBBTwice-yearlyReporting commonly ~30 Sep & 31 Mar
Saudi ArabiaNCA ECCPeriodicCSCC adds 6-month interval (critical systems)
Saudi ArabiaSAMA CSFMaturity-drivenPentest + red teaming at higher levels
UAEIA / NESA, DESC, ADHICSPeriodicSector-specific (Dubai, Abu Dhabi, health)
QatarQCB / NIAPeriodicCentral-bank & national framework
KuwaitCBKPeriodicCentral-bank cyber framework
OmanCBO / nationalPeriodicSector frameworks
RegionalPCI DSS v4.012 months + changeSegmentation 6 months (service providers)

Dates and cycles evolve — always confirm the current requirement with your regulator or through the per-country guides linked above. Where a specific reporting date is cited (such as the CBB's), treat it as the typical alignment rather than a guarantee for every licensee.

// 03 The buying windows

Work backwards from each deadline. Because you need testing plus remediation plus retesting before the report is due, the sensible booking point is 6–10 weeks ahead:

// 04 One test, several regulators

If you operate across more than one GCC market or framework, you rarely need a separate test for each. A single engagement, scoped to cover the systems every applicable regulator cares about and reported with findings mapped to each framework, can satisfy several at once — an NCA ECC obligation and a PCI DSS requirement, for instance, from one test. The trick is to set your cadence to the strictest regulator that applies (usually the twice-yearly financial ones), then schedule the engagement so its report lands ahead of every deadline. Map your exact obligations with the requirements finder and the requirements-by-framework guide.

// 05 Frequently asked questions

When are GCC penetration testing deadlines?

Bahrain's CBB runs twice-yearly, commonly aligned to 30 September and 31 March. Saudi Arabia's NCA ECC requires periodic testing (CSCC adds a six-month interval for critical systems); SAMA is maturity-driven. PCI DSS card handlers test at least every 12 months and after significant change. Most obligations reduce to at least annual, with finance and critical infrastructure on semi-annual cycles.

How far ahead should you book?

Six to ten weeks before the deadline. Testing takes 1–3 weeks plus scoping and reporting, and you need time afterwards to remediate and retest before the report is due. Last-minute booking means submitting with open critical findings or missing the date.

Does one test cover multiple regulators?

Often — if scoped to each regulator's systems and reported with findings mapped to each framework. One annual engagement can serve an NCA ECC obligation and a PCI DSS requirement at once. Align cadence to the strictest regulator, then schedule one engagement to satisfy the others.

Which sectors have the strictest cycles?

Financial services and critical infrastructure. Banks and payment providers face central-bank frameworks (CBB, SAMA) plus PCI DSS, often driving semi-annual testing. OT and critical-infrastructure operators face additional controls like NCA OTCC. Plan these as recurring calendared programmes.

// 06 Per-country guides

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Plans recurring testing programmes for GCC organisations — scheduling engagements against each regulator's cycle so reports land clean and on time.

Never miss a deadline again

Tell us which GCC regulators you answer to and we'll build a testing schedule around their cycles — one engagement mapped to every framework, booked early enough to remediate and retest before each report is due.

Plan your calendar → Check requirements →