Blog · C.34 · Compliance Guide

Kuwait penetration testing requirements — the new CBK CORF

Kuwait's financial-sector cyber rules changed in December 2025. The Central Bank of Kuwait's Cyber & Operational Resilience Framework (CORF) replaced the 2020 framework and added something new: mandatory annual red teaming. Here is what CORF requires of penetration testing, in its own words.

KuwaitCBK CORFRed TeamingIoT / OTBanking
Kuwait CBK CORF: Periodic Pen Testing (5.13.1.2) · Annual Red Teaming (5.13.2.7) · IoT/OT Annual Pen Test + Quarterly VA (5.14.2.3) · Annual Independent Audit Kuwait CBK CORF: Periodic Pen Testing (5.13.1.2) · Annual Red Teaming (5.13.2.7) · IoT/OT Annual Pen Test + Quarterly VA (5.14.2.3) · Annual Independent Audit
// TL;DR

Kuwait's financial sector is now governed by the Central Bank of Kuwait Cyber & Operational Resilience Framework (CORF), launched 3 December 2025, which replaced the 2020 Cybersecurity Framework. CORF's testing controls sit in Domain 2, Sub-Domain 5.13. Under 5.13.1.2, vulnerability assessment, application security testing, penetration testing and code reviews must be conducted periodically or on significant change. The headline addition is 5.13.2.7: red teaming exercises at least once a year, using real-world tactics and threat intelligence, by a dedicated team, without the blue team's prior knowledge. For IoT and OT, 5.14.2.3 requires quarterly vulnerability assessments and annual penetration testing. Compliance is verified by an annual independent CORF audit by a CBK-approved firm. It applies to all CBK regulated entities.

// 01 Who regulates cybersecurity in Kuwait?

For the financial sector, the Central Bank of Kuwait (CBK) is the authority, and its framework is the one that carries specific penetration testing obligations. At the national level, CITRA (the Communication and Information Technology Regulatory Authority) and the National Cyber Security Center issue Kuwait's National Cybersecurity Framework for government and critical national infrastructure, plus a Cloud Computing Regulatory Framework governing data residency. If you are a bank or financial institution, CBK is your primary regulator; if you are a government entity or critical-infrastructure operator, the CITRA/NCSC framework applies.

// 02 The CBK CORF (2025): a new framework

The most important thing to know about Kuwait right now is that the rules recently changed. On 3 December 2025, the CBK launched the Cyber & Operational Resilience Framework (CORF), a 389-page, threat-led framework that supersedes the 2020 Cybersecurity Framework (CSF). If you are working from the old CSF, or from a guide that references it, you are working from a superseded document.

CORF's Cyber Resilience Baselines comprise 6 domains, 33 sub-domains, 87 control areas and 519 controls. Security testing lives in Domain 2 (Technology & Operations), Sub-Domain 5.13, "Cybersecurity Testing and Threat Management." The shift from CSF to CORF is not just a renumbering — CORF is broader, threat-led, and introduces requirements the 2020 framework did not have, most notably mandatory red teaming.

// 03 What CORF requires for testing

Three controls carry the testing mandate, and together they define a layered programme — periodic penetration testing, annual red teaming, and a specific IoT/OT cadence.

// CORF Sub-Domain 5.13 & 5.14The testing controls

5.13.1.2 (penetration testing & VA): vulnerability assessment including "application security testing, penetration testing, and code reviews … shall be conducted on periodic basis or whenever significant changes occur." No fixed interval — risk-based.

5.13.2.7 (red teaming — new): "Red teaming exercises shall be conducted at least once a year or as required based on changes to the threat landscape, critical systems, or regulatory requirements." Red teams must use real-world tactics and threat intelligence (5.13.2.5–6), be a dedicated qualified team (5.13.2.8), and run without prior knowledge of the blue and monitoring teams (5.13.2.9).

5.14.2.3 (IoT / OT): "IoT/OT devices and their associated networks shall be subject to security assessments, including quarterly vulnerability assessments and annual penetration testing."

The red-teaming requirement is the standout. Kuwait now joins the small group of Gulf regimes — alongside Saudi Arabia's SAMA FEER framework — that explicitly mandate intelligence-led adversarial simulation, not just penetration testing. The "no prior knowledge of the blue team" condition means these are genuine, covert exercises testing detection and response, which is a materially more demanding engagement than a standard scoped penetration test. We cover this style of work in our red teaming service.

// 04 Who must comply, and how it's checked

CORF applies to all CBK Regulated Entities — Kuwaiti banks, foreign banks operating in Kuwait, finance companies, exchange companies, investment companies, and entities subject to the payment regulations. Compliance is not self-attested: it is verified through an annual independent CORF audit performed by a CBK-approved third-party firm, with the depth risk-tiered to the entity's profile. That external-audit mechanism means your testing evidence needs to withstand independent scrutiny — a well-structured, control-mapped penetration test and a properly-run red team are what an auditor will look for.

CORF requirementControlCadence
Penetration testing & VA5.13.1.2Periodic / on change
Red teaming5.13.2.7At least annually
IoT / OT vulnerability assessment5.14.2.3Quarterly
IoT / OT penetration testing5.14.2.3Annually
Compliance verificationAnnual independent audit

// 05 The CITRA / NCSC national layer

Outside the financial sector, CITRA and the National Cyber Security Center run Kuwait's National Cybersecurity Framework for government entities and critical national infrastructure, aligned to ISO 27001 and NIST CSF, alongside a Cloud Computing Regulatory Framework that requires higher-tier workloads to be hosted in Kuwait or CITRA-approved sovereign facilities. The specific penetration testing controls within the national framework are not fully public, so we describe the obligation functionally: government and critical-infrastructure entities should expect to evidence regular security testing as part of their national-framework compliance, in addition to any sector rules. A financial institution that also operates critical infrastructure may answer to both CBK and the national framework.

// 06 Frequently asked questions

Does the CBK require penetration testing?

Yes. CORF control 5.13.1.2 requires periodic penetration testing, application security testing, VA and code reviews. CORF (Dec 2025) replaced the 2020 CSF.

Does Kuwait require red teaming?

Yes — new in CORF. Control 5.13.2.7 requires red teaming at least once a year, covert, using real-world tactics and threat intelligence.

How often for IoT/OT?

Control 5.14.2.3 requires quarterly vulnerability assessments and annual penetration testing for IoT/OT devices and networks.

Who must comply?

All CBK regulated entities — banks, finance, exchange, investment and payment entities — verified by an annual independent CORF audit.

// 07 Sources

Control references reflect the CBK CORF v1.0 (2025) as published. CORF is newly issued; confirm the current control text and your compliance timeline with the CBK before relying on this for a regulatory submission.

AH

Ankur H.

Security & Compliance Specialist, CyberFortify

Maps technical findings to the frameworks GCC regulators assess — the CBK CORF, QCB, SAMA, NCA ECC, CBB and the UAE frameworks — including the intelligence-led red teaming CORF now requires.

Kuwaiti entity adapting to CORF?

CyberFortify delivers the periodic penetration testing and annual intelligence-led red teaming the CBK CORF requires — covert, threat-led, and reported to withstand your annual independent CORF audit.

Schedule scoping call → Red teaming →