Framework · Central Bank of Oman
The Central Bank of Oman Cyber Security and Resilience Framework
The CBO sets one unified Cyber Security and Resilience Framework, based on international standards, for the institutions it licenses. Here is who it covers, how it is structured and how to prepare.
Last verified against official sources: 26 September 2026
The framework at a glance
- Document
- Cyber Security and Resilience Framework (CS&RF), referred to in the CBO's other frameworks as Circular BM 1194
- Issued by
- Central Bank of Oman
- Applies to
- All banks operating in Oman and their foreign branches, all finance and leasing companies, all money exchange companies and all payment service providers
- Implementation
- No later than 31 July 2024
- Target maturity
- Ideally maturity level 3 at a minimum, on a scale from level 0 to level 5
- Public text
- Published by the CBO on cbo.gov.om. Its FinTech sandbox application form links to it under General Guidelines.
Who it covers
The framework covers all banks operating in Oman and their foreign branches, all finance and leasing companies, all money exchange companies and all payment service providers. Licensed institutions were to implement it no later than 31 July 2024.
FinTech firms applying to the CBO's regulatory sandbox are also pointed to it: the sandbox application form lists it under General Guidelines.
What the framework covers
The framework groups its controls into six domains:
- Cyber Security Governance.
- Cyber Security Risk Management.
- Cyber Security in Technology and Operations: asset management and classification, application security, physical security, cryptography, data leakage prevention, bring your own device (BYOD), infrastructure security, patch and change management, capacity management, access control, vulnerability management and penetration testing, threat management, human resources, incident management, event management and secure disposal.
- Cyber Security in Third-Party Supply Chain Management: contract and vendor management, cloud computing and outsourcing.
- Cyber Security of Online Financial Services.
- Cyber Security Compliance and Audit.
Maturity, incident reporting and waivers
The framework includes a maturity model running from level 0 to level 5. Licensed institutions should ideally function at maturity level 3 at a minimum.
It also includes an incident reporting template, with initial, situation and closure reports to the CBO, and a waiver process for controls an institution cannot implement.
How it sits with the other rules
A CBO-licensed institution is also a controller under the Personal Data Protection Law for its customer and employee data, so the 72 hours breach rules, the data protection officer and the 2026 consent changes apply alongside the CBO's requirements.
Card payment environments also follow PCI DSS, which the card networks require by contract.
How to prepare
- Work from the framework as published by the CBO, and record the version you assess against.
- Rate your current maturity in each domain and plan the steps to reach maturity level 3 at a minimum.
- Map the controls to one control set shared with the Personal Data Protection Law and, where you use them, ISO/IEC 27001, NIST CSF 2.0 and PCI DSS.
- Set up incident handling so the initial, situation and closure reports to the CBO and the 72 hours data breach notices to the Ministry come from one incident record.
- Where a control cannot be implemented, document it and use the framework's waiver process rather than leaving a silent gap.
- Collect the evidence once and link it to every requirement it satisfies.
How AccuSights helps
We assess your controls against the framework's domains and maturity model, map them to one set with your data protection duties and card standards, and prepare the evidence. See our services.
AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the Ministry of Transport, Communications and Information Technology, the Cyber Defence Centre, OCERT, the Central Bank of Oman or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. English quotations of Omani law are translations; the Arabic text published in the Official Gazette is binding.
Sources
- Central Bank of Oman, Cyber Security and Resilience Framework (CS&RF) (opens in a new tab)
- Central Bank of Oman, FinTech Regulatory Sandbox application (opens in a new tab)
- ISO, ISO/IEC 27001 information security management (opens in a new tab)
- PCI Security Standards Council, PCI DSS (opens in a new tab)
- NIST, Cybersecurity Framework 2.0 (opens in a new tab)