Oman requires penetration testing through two models. The Central Bank of Oman Cyber Security & Resilience Framework (CS&RF), issued September 2023, requires financial institutions to conduct vulnerability assessment and penetration testing, and lets the CBO require a qualified third-party assessor — the requirement sits in the framework's Technology & Operations domain (one of six). An honest caveat: the CBO's published control document is a scanned image without machine-readable text, so we do not quote a specific control number or mandated frequency — we describe the obligation functionally. For government, Oman runs a provider-accreditation model: MTCIT's Security Assessment Services Standard governs who may perform penetration testing and how for government entities and critical infrastructure, and OCERT also conducts assessments. CBO applies to banks, financing companies, exchange companies and payment providers.
// 01 Who regulates cybersecurity in Oman?
Two authorities matter. The Central Bank of Oman (CBO) regulates the financial sector and issues the framework that carries VAPT obligations for banks and financial institutions. At the government and national level, the Ministry of Transport, Communications and Information Technology (MTCIT) — formerly the ITA — sets information-security standards, and OCERT, Oman's national CERT, conducts and coordinates security assessments for government and critical national infrastructure. Oman's approach is distinctive in one respect: for government testing, it regulates the providers as much as the entities, through an accreditation model we describe below.
// 02 The CBO Cyber Security & Resilience Framework
The CBO issued its Cyber Security & Resilience Framework (CS&RF) in September 2023, with a reported compliance deadline in 2024. It is structured across six control domains: Governance; Compliance & Audit; Technology & Operations; Third-Party / Supply Chain Management; Online Financial Services; and Risk Management. Penetration testing and vulnerability assessment fall within the Technology & Operations domain: the framework requires security and VAPT reporting for IT systems and cybersecurity infrastructure, and empowers the CBO to require a licensed institution to appoint a qualified third-party assessor to perform vulnerability assessment and penetration testing.
Here we owe you honesty rather than false precision. The CBO's published CS&RF document is a scanned image with no machine-readable text layer, which means we cannot responsibly quote a specific control number or a mandated testing frequency the way we can for Qatar's QCB or Kuwait's CORF. What is well established is that the framework requires VAPT within the Technology & Operations domain and enables the CBO to mandate third-party testing. For the exact cadence and control reference, an Omani financial institution should confirm directly with the CBO or an accredited assessor — and be wary of any guide that quotes a precise CBO control number, since that text is not publicly extractable.
// 03 The MTCIT provider-accreditation model
For government and critical infrastructure, Oman takes a different and quite deliberate approach: it regulates who is allowed to test. MTCIT's Security Assessment Services Standard (effective 2019) establishes a unified framework under which accredited IT service providers deliver penetration testing and vulnerability assessment for Omani government entities and critical national infrastructure — covering provider eligibility and licensing, engagement scope, execution, reporting, and closure.
Regulated providers
Only accredited providers may deliver government security assessments; MTCIT has accredited a set of firms for this work.
Defined engagement
The standard defines how tests are scoped, executed, reported and closed — a consistent process across providers.
National assessments
OCERT conducts and coordinates VAPT and verification testing for government and CNI organisations.
Management framework
MTCIT's Information Security Management Framework helps government entities manage IT risk more broadly.
The practical implication is that Oman's government-sector regime emphasises the quality and consistency of the testing provider as much as the frequency — a model closer to the UK's accreditation-led approach than to a fixed calendar mandate. Rather than a single "test every N months" rule, the question is whether a qualified, accredited provider conducted a properly-scoped assessment.
// 04 Who must comply
| Framework | Applies to | Testing requirement |
|---|---|---|
| CBO CS&RF (2023) | Banks, financing & leasing, exchange, payment providers | VAPT required (Technology & Operations) |
| MTCIT Security Assessment Services Standard | Government entities & CNI | Accredited-provider testing |
| OCERT assessments | Government & CNI | National VAPT / verification |
// 05 Frequently asked questions
Does Oman require penetration testing for banks?
Yes. The CBO CS&RF (2023) requires VAPT within its Technology & Operations domain, and the CBO may require a qualified third-party assessor.
Who must comply with the CBO CS&RF?
Banks, financing and leasing companies, money exchange companies and payment service providers, across six control domains.
How does government testing work?
Through MTCIT's provider-accreditation model — accredited firms deliver penetration testing for government and CNI — plus OCERT assessments.
What's the exact frequency?
The CBO control document is a scanned image without extractable text, so we don't assert a specific frequency or control number. Confirm with the CBO or an accredited assessor.
// 06 Sources
- Central Bank of Oman, Cyber Security & Resilience Framework (CS&RF), September 2023 — six control domains including Technology & Operations. Note: the published PDF is a scanned image without a machine-readable text layer, so specific control numbers/frequencies are not quoted.
- MTCIT Security Assessment Services Standard v1.0 (effective 2019); MTCIT Information Security Management Framework; OCERT (Oman National CERT).
This guide describes Oman's requirements functionally because the CBO CS&RF control text is not publicly machine-readable. Confirm exact obligations with the CBO, MTCIT or an accredited assessor before relying on this for compliance.