Kuwait's financial sector is now governed by the Central Bank of Kuwait Cyber & Operational Resilience Framework (CORF), launched 3 December 2025, which replaced the 2020 Cybersecurity Framework. CORF's testing controls sit in Domain 2, Sub-Domain 5.13. Under 5.13.1.2, vulnerability assessment, application security testing, penetration testing and code reviews must be conducted periodically or on significant change. The headline addition is 5.13.2.7: red teaming exercises at least once a year, using real-world tactics and threat intelligence, by a dedicated team, without the blue team's prior knowledge. For IoT and OT, 5.14.2.3 requires quarterly vulnerability assessments and annual penetration testing. Compliance is verified by an annual independent CORF audit by a CBK-approved firm. It applies to all CBK regulated entities.
// 01 Who regulates cybersecurity in Kuwait?
For the financial sector, the Central Bank of Kuwait (CBK) is the authority, and its framework is the one that carries specific penetration testing obligations. At the national level, CITRA (the Communication and Information Technology Regulatory Authority) and the National Cyber Security Center issue Kuwait's National Cybersecurity Framework for government and critical national infrastructure, plus a Cloud Computing Regulatory Framework governing data residency. If you are a bank or financial institution, CBK is your primary regulator; if you are a government entity or critical-infrastructure operator, the CITRA/NCSC framework applies.
// 02 The CBK CORF (2025): a new framework
The most important thing to know about Kuwait right now is that the rules recently changed. On 3 December 2025, the CBK launched the Cyber & Operational Resilience Framework (CORF), a 389-page, threat-led framework that supersedes the 2020 Cybersecurity Framework (CSF). If you are working from the old CSF, or from a guide that references it, you are working from a superseded document.
CORF's Cyber Resilience Baselines comprise 6 domains, 33 sub-domains, 87 control areas and 519 controls. Security testing lives in Domain 2 (Technology & Operations), Sub-Domain 5.13, "Cybersecurity Testing and Threat Management." The shift from CSF to CORF is not just a renumbering — CORF is broader, threat-led, and introduces requirements the 2020 framework did not have, most notably mandatory red teaming.
// 03 What CORF requires for testing
Three controls carry the testing mandate, and together they define a layered programme — periodic penetration testing, annual red teaming, and a specific IoT/OT cadence.
5.13.1.2 (penetration testing & VA): vulnerability assessment including "application security testing, penetration testing, and code reviews … shall be conducted on periodic basis or whenever significant changes occur." No fixed interval — risk-based.
5.13.2.7 (red teaming — new): "Red teaming exercises shall be conducted at least once a year or as required based on changes to the threat landscape, critical systems, or regulatory requirements." Red teams must use real-world tactics and threat intelligence (5.13.2.5–6), be a dedicated qualified team (5.13.2.8), and run without prior knowledge of the blue and monitoring teams (5.13.2.9).
5.14.2.3 (IoT / OT): "IoT/OT devices and their associated networks shall be subject to security assessments, including quarterly vulnerability assessments and annual penetration testing."
The red-teaming requirement is the standout. Kuwait now joins the small group of Gulf regimes — alongside Saudi Arabia's SAMA FEER framework — that explicitly mandate intelligence-led adversarial simulation, not just penetration testing. The "no prior knowledge of the blue team" condition means these are genuine, covert exercises testing detection and response, which is a materially more demanding engagement than a standard scoped penetration test. We cover this style of work in our red teaming service.
// 04 Who must comply, and how it's checked
CORF applies to all CBK Regulated Entities — Kuwaiti banks, foreign banks operating in Kuwait, finance companies, exchange companies, investment companies, and entities subject to the payment regulations. Compliance is not self-attested: it is verified through an annual independent CORF audit performed by a CBK-approved third-party firm, with the depth risk-tiered to the entity's profile. That external-audit mechanism means your testing evidence needs to withstand independent scrutiny — a well-structured, control-mapped penetration test and a properly-run red team are what an auditor will look for.
| CORF requirement | Control | Cadence |
|---|---|---|
| Penetration testing & VA | 5.13.1.2 | Periodic / on change |
| Red teaming | 5.13.2.7 | At least annually |
| IoT / OT vulnerability assessment | 5.14.2.3 | Quarterly |
| IoT / OT penetration testing | 5.14.2.3 | Annually |
| Compliance verification | — | Annual independent audit |
// 05 The CITRA / NCSC national layer
Outside the financial sector, CITRA and the National Cyber Security Center run Kuwait's National Cybersecurity Framework for government entities and critical national infrastructure, aligned to ISO 27001 and NIST CSF, alongside a Cloud Computing Regulatory Framework that requires higher-tier workloads to be hosted in Kuwait or CITRA-approved sovereign facilities. The specific penetration testing controls within the national framework are not fully public, so we describe the obligation functionally: government and critical-infrastructure entities should expect to evidence regular security testing as part of their national-framework compliance, in addition to any sector rules. A financial institution that also operates critical infrastructure may answer to both CBK and the national framework.
// 06 Frequently asked questions
Does the CBK require penetration testing?
Yes. CORF control 5.13.1.2 requires periodic penetration testing, application security testing, VA and code reviews. CORF (Dec 2025) replaced the 2020 CSF.
Does Kuwait require red teaming?
Yes — new in CORF. Control 5.13.2.7 requires red teaming at least once a year, covert, using real-world tactics and threat intelligence.
How often for IoT/OT?
Control 5.14.2.3 requires quarterly vulnerability assessments and annual penetration testing for IoT/OT devices and networks.
Who must comply?
All CBK regulated entities — banks, finance, exchange, investment and payment entities — verified by an annual independent CORF audit.
// 07 Sources
- Central Bank of Kuwait, Cyber & Operational Resilience Framework (CORF) v1.0, launched 3 December 2025 — Sub-Domain 5.13 and controls 5.13.1.2, 5.13.2.7 and 5.14.2.3 (quoted). Supersedes the CBK Cybersecurity Framework (CSF) v1.0, 2020.
- CITRA / National Cyber Security Center National Cybersecurity Framework and Cloud Computing Regulatory Framework.
Control references reflect the CBK CORF v1.0 (2025) as published. CORF is newly issued; confirm the current control text and your compliance timeline with the CBK before relying on this for a regulatory submission.