Framework · Central Bank of Oman

The Central Bank of Oman Cyber Security and Resilience Framework

The CBO sets one unified Cyber Security and Resilience Framework, based on international standards, for the institutions it licenses. Here is who it covers, how it is structured and how to prepare.

Last verified against official sources: 26 September 2026

The framework at a glance

Document
Cyber Security and Resilience Framework (CS&RF), referred to in the CBO's other frameworks as Circular BM 1194
Issued by
Central Bank of Oman
Applies to
All banks operating in Oman and their foreign branches, all finance and leasing companies, all money exchange companies and all payment service providers
Implementation
No later than 31 July 2024
Target maturity
Ideally maturity level 3 at a minimum, on a scale from level 0 to level 5
Public text
Published by the CBO on cbo.gov.om. Its FinTech sandbox application form links to it under General Guidelines.

Who it covers

The framework covers all banks operating in Oman and their foreign branches, all finance and leasing companies, all money exchange companies and all payment service providers. Licensed institutions were to implement it no later than 31 July 2024.

FinTech firms applying to the CBO's regulatory sandbox are also pointed to it: the sandbox application form lists it under General Guidelines.

What the framework covers

The framework groups its controls into six domains:

  • Cyber Security Governance.
  • Cyber Security Risk Management.
  • Cyber Security in Technology and Operations: asset management and classification, application security, physical security, cryptography, data leakage prevention, bring your own device (BYOD), infrastructure security, patch and change management, capacity management, access control, vulnerability management and penetration testing, threat management, human resources, incident management, event management and secure disposal.
  • Cyber Security in Third-Party Supply Chain Management: contract and vendor management, cloud computing and outsourcing.
  • Cyber Security of Online Financial Services.
  • Cyber Security Compliance and Audit.

Maturity, incident reporting and waivers

The framework includes a maturity model running from level 0 to level 5. Licensed institutions should ideally function at maturity level 3 at a minimum.

It also includes an incident reporting template, with initial, situation and closure reports to the CBO, and a waiver process for controls an institution cannot implement.

How it sits with the other rules

A CBO-licensed institution is also a controller under the Personal Data Protection Law for its customer and employee data, so the 72 hours breach rules, the data protection officer and the 2026 consent changes apply alongside the CBO's requirements.

Card payment environments also follow PCI DSS, which the card networks require by contract.

How to prepare

  1. Work from the framework as published by the CBO, and record the version you assess against.
  2. Rate your current maturity in each domain and plan the steps to reach maturity level 3 at a minimum.
  3. Map the controls to one control set shared with the Personal Data Protection Law and, where you use them, ISO/IEC 27001, NIST CSF 2.0 and PCI DSS.
  4. Set up incident handling so the initial, situation and closure reports to the CBO and the 72 hours data breach notices to the Ministry come from one incident record.
  5. Where a control cannot be implemented, document it and use the framework's waiver process rather than leaving a silent gap.
  6. Collect the evidence once and link it to every requirement it satisfies.

How AccuSights helps

We assess your controls against the framework's domains and maturity model, map them to one set with your data protection duties and card standards, and prepare the evidence. See our services.

AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the Ministry of Transport, Communications and Information Technology, the Cyber Defence Centre, OCERT, the Central Bank of Oman or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. English quotations of Omani law are translations; the Arabic text published in the Official Gazette is binding.

Sources

  1. Central Bank of Oman, Cyber Security and Resilience Framework (CS&RF) (opens in a new tab)
  2. Central Bank of Oman, FinTech Regulatory Sandbox application (opens in a new tab)
  3. ISO, ISO/IEC 27001 information security management (opens in a new tab)
  4. PCI Security Standards Council, PCI DSS (opens in a new tab)
  5. NIST, Cybersecurity Framework 2.0 (opens in a new tab)

Ten minutes to know exactly where you stand

Tell us what you do and what data you hold. We will show you what the amended Personal Data Protection Law asks of you, where the gaps usually are, and the shortest route to ready. No slides, no pitch.