Framework B.09 · Central Bank of Bahrain

CBB Cyber Security Rules - penetration testing for Bahrain financial licensees.

The Central Bank of Bahrain (CBB) requires its licensees to conduct periodic penetration testing and report on their cyber security posture. As a Bahrain-headquartered firm, this is home ground for CyberFortify: our network and web application testing produces evidence mapped to CBB reporting expectations, on the reporting cycle.

Maintainer: Central Bank of Bahrain Scope: Bahrain financial licensees Driver: CBB Rulebook cyber security requirements
Bahrain
Our home base
Twice-yearly
Common cycle
Report
Mapped to CBB
Retest
Included
CBB: Licensee Cyber Security Rules · Periodic Penetration Testing · Genuine Human-led Testing · Twice-yearly Reporting · Remediate & Retest · Report Mapped to CBB CBB: Licensee Cyber Security Rules · Periodic Penetration Testing · Genuine Human-led Testing · Twice-yearly Reporting · Remediate & Retest · Report Mapped to CBB
// Executive summary

The Central Bank of Bahrain requires its licensees to conduct periodic penetration testing as part of their cyber security obligations, and to report on it - commonly on a twice-yearly cycle. Testing must be genuine (a scan does not satisfy it), findings remediated and retested, and the report framed for the regulator. CyberFortify is headquartered in Bahrain and maps every engagement to CBB reporting expectations.

// 01 What the CBB cyber security rules are

// DefinitionCBB Cyber Security Rules

The Central Bank of Bahrain is the single regulator for Bahrain's financial sector. Its Rulebook sets the requirements licensees must meet, including a dedicated set of cyber security requirements covering governance, risk management, controls, incident reporting and - central here - regular security testing of systems.

Within those requirements, licensees are expected to conduct periodic penetration testing, remediate what is found, and report on their cyber security posture to the regulator on a recurring basis.

Bahrain's position as a regional financial hub makes the CBB the strongest testing driver in the Kingdom. The obligation is not a one-off box-tick: it is a calendared programme that licensees plan around each reporting deadline. For the full practitioner view, see our CBB penetration testing requirements guide.

// 02 What the requirement means in practice

01Core

Genuine penetration testing

Human-led testing of in-scope systems - an automated scan does not satisfy the expectation. Our manual-led approach is built for this.

02Cycle

Recurring & reported

Testing on a recurring basis, commonly twice-yearly, with reporting to the CBB aligned to fixed dates. Planned as a programme, not ad-hoc.

03Remediation

Fix & retest

Findings must be remediated and closure demonstrated. CyberFortify's retest is included to produce that evidence.

04Mapping

Report framed for CBB

The report maps findings and remediation to the regulator's expectations so it is accepted in the compliance conversation.

// 03 Who is in scope

The cyber security requirements apply across the CBB's licensee population: conventional and Islamic banks, insurance firms, investment firms, payment service providers, financing companies and other financial licensees. If you hold a CBB licence and run the systems supporting regulated activity, you have a testing obligation, scaled to your size and risk. The sectors most affected map to our industry work in banking and insurance. Card handlers also fall under PCI DSS, and personal data is governed by Bahrain's PDPL.

A CBB licensee does not just need a technically strong test - it needs a report the regulator accepts on the reporting cycle. Getting that wrong close to a deadline is expensive. We test to exactly that standard from our Bahrain base.

CyberFortify CBB-facing reporting

// 04 Timing to the reporting cycle

The defining discipline for CBB testing is timing. Because reporting recurs on a fixed cycle, and because open critical findings at reporting time are exactly what the regulator does not want to see, licensees book testing six to ten weeks ahead of each deadline - leaving room to remediate and retest before the report is due. A typical engagement runs one to three weeks of active testing (about four to six weeks in total with remediation and retest). Map the cycle alongside your other GCC obligations with the GCC compliance calendar.

// 05 Frequently asked questions

Does the CBB require penetration testing?

Yes. The CBB's cyber security requirements for licensees include conducting periodic penetration testing and reporting on it. Testing must be genuine human-led assessment, not a scan, and licensees remediate findings and report on their posture on a recurring basis, typically as a calendared programme aligned to CBB reporting.

Who has to comply?

All entities licensed and supervised by the CBB - conventional and Islamic banks, insurers, investment firms, payment service providers, financing companies and other financial licensees in Bahrain. Any organisation holding a CBB licence and running the systems supporting regulated activity is in scope, with testing expectations scaling to size and risk.

How often must licensees test?

On a recurring basis, commonly twice-yearly with reporting aligned to fixed dates, plus after significant change. Exact cadence depends on category and risk. Book six to ten weeks ahead of each deadline so findings can be remediated and retested before the report is due.

Why use a Bahrain-based provider?

A provider fluent in CBB reporting cycles and expectations scopes faster and delivers a report mapped to what the regulator checks, accepted without rework. A distant provider with no CBB context can produce a strong report that still fails the compliance conversation near a deadline. CyberFortify is headquartered in Bahrain and tests to that standard.

Ready for a CBB-aligned engagement?

We're headquartered in Bahrain. Schedule a 30-minute scoping call and we'll scope your systems, map the report to CBB reporting expectations, and deliver on your cycle - accepted first time.

Schedule scoping call → Back to CyberFortify home →