Central Bank of Kuwait · CORF v1.0

Assess your bank against the CORF, without a spreadsheet

A free, offline workbook for the Central Bank of Kuwait Cyber and Operational Resilience Framework. Declare what applies, mark every control, set your maturity, and let it roll the scores up the way CBK specifies. Your data never leaves the browser.

Open the workbook See how it works
No sign up. No server. One HTML file you can run offline.
3control baselines
876controls
93sub domains
5maturity levels
What you are assessing

The CORF, in brief

Issued in December 2025, the CORF is CBK's resilience first successor to the 2020 Cybersecurity Framework. It is mandatory for every entity CBK regulates, from local and foreign banks to exchange, finance, and e payment companies. Its requirements live in three control baselines.

CRB Cyber Resilience

Six domains covering governance, technology and operations, third party risk, emerging technology, payments, and operational resilience. The largest baseline at 519 controls.

ORB Operational Resilience

Eight domains for continuity, recovery, and crisis management, so critical services survive disruption. 146 controls.

TPRM Third Party Risk

Thirteen domains for the full life of a vendor relationship, from due diligence and contracts to exit and cross border data. 211 controls.

Two layers of assessment

Every control is rated Compliant, Non compliant, or Not applicable against a test of design and a test of effectiveness. Separately, each sub domain gets a maturity level from one to five. Compliance tells you what is in place; maturity tells you how deeply it is embedded.

Applicability and tiering

Before assessing, an entity files a Statement of Applicability declaring which domains and sub domains apply. CBK also profiles each entity's inherent risk across eleven dimensions to place it in a supervisory tier that sets how often it is assessed.

Using the workbook

Six steps, start to finish

Open the workbook and work top to bottom through the tabs. Everything saves in your browser as you go.

1

Set what applies (Applicability tab)

Go through each domain and sub domain and mark it Applicable or Not applicable, adding a justification wherever it does not apply. This mirrors the CORF Statement of Applicability. Anything you mark Not applicable drops out of every score, so your results reflect only what your entity actually does.

2

Assess each control (Assess tab)

Pick a sub domain from the tree on the left. For each control, choose Compliant, Non compliant, or N/A, and drop the supporting evidence into the note beside it. The tree shows your progress and colours each sub domain by how compliant it is, so you always know what is left.

3

Set the maturity level (Assess tab)

At the top of each sub domain, choose a maturity level from one to five with a short rationale. The workbook enforces the CORF rule for you: you cannot select Baseline or higher until every applicable control in that sub domain is compliant. Until then, levels three, four, and five stay locked.

4

Read the roll up (Dashboard tab)

The dashboard aggregates everything: overall compliance and maturity, a compliance bar for every domain, and a maturity radar for each baseline. It is the view that shows where your posture is strong and where the gaps concentrate.

5

Plan the remediation (Gaps tab)

Every control you marked Non compliant becomes a gap. Give each one a priority, an owner, a target date, and a status, and track it to closed. Download the plan as CSV to share with management. This is the remediation step the CORF lifecycle asks for.

6

Export and back up (Data tab)

Export your assessment to a JSON file to keep it safe, move it to another machine, or hand it to a colleague or assessor. Import brings it back. You can also print the whole thing to a clean PDF for your records.

How the numbers work

Compliance and maturity, rolled up

The workbook computes scores exactly the way the CORF describes, so what you see matches how CBK reads an assessment.

Compliance

A sub domain's compliance is the share of its applicable controls marked compliant. Not applicable controls are left out of the sum. Domain compliance is the average across its sub domains, and the overall score is the average across domains.

ControlC / NC / NA
Sub domainpercent compliant
Domainaverage
Overallaverage

Maturity

You set a level from one to five for each sub domain. Domain maturity is the average of its sub domains, and overall maturity is the average across domains. The scale is progressive, so higher levels require demonstrable achievement of the ones below.

1

Initial

2

Ad hoc

3

Baseline

4

Advanced

5

Innovative

The gate that keeps scores honest. A sub domain cannot be rated Baseline (level 3) or higher until it is fully compliant with every applicable control. The workbook locks those levels until you get there, so maturity is grounded in practice rather than aspiration. It is the single rule people most often miss in a spreadsheet.
1

Initial

Reactive, informal, undocumented.

2

Ad hoc

Partial, inconsistent, siloed.

3

Baseline

Documented, risk based, measured.

4

Advanced

Automated, integrated, proactive.

5

Innovative

Anticipatory, intelligence led, real time.

Your data stays with you

The workbook is a single HTML file that runs entirely in your browser. There is no server, no account, and no telemetry. Nothing you type is ever transmitted anywhere. Save it locally and use it on an air gapped machine if you like. For a bank handling a regulatory self assessment, that matters.

Ready to start?

Open the workbook and begin with the Applicability tab.

Open the workbook Download the control catalog (JSON)

This workbook is an independent, open source aid built to help entities work through the CBK Cyber and Operational Resilience Framework. It encodes the assessment methodology described in the framework (control level compliance, sub domain maturity, and the roll up from sub domain to domain to overall). It is not affiliated with, endorsed by, or produced by the Central Bank of Kuwait, and it is not the official CORF toolkit nor a substitute for a CBK approved assessor. The control catalog is extracted programmatically from the published CORF v1.0 document; 874 of the 876 controls are captured and it should be validated against the source before formal use. Always refer to the official CORF documents for authoritative requirements.