A free, offline workbook for the Central Bank of Kuwait Cyber and Operational Resilience Framework. Declare what applies, mark every control, set your maturity, and let it roll the scores up the way CBK specifies. Your data never leaves the browser.
Issued in December 2025, the CORF is CBK's resilience first successor to the 2020 Cybersecurity Framework. It is mandatory for every entity CBK regulates, from local and foreign banks to exchange, finance, and e payment companies. Its requirements live in three control baselines.
Six domains covering governance, technology and operations, third party risk, emerging technology, payments, and operational resilience. The largest baseline at 519 controls.
Eight domains for continuity, recovery, and crisis management, so critical services survive disruption. 146 controls.
Thirteen domains for the full life of a vendor relationship, from due diligence and contracts to exit and cross border data. 211 controls.
Every control is rated Compliant, Non compliant, or Not applicable against a test of design and a test of effectiveness. Separately, each sub domain gets a maturity level from one to five. Compliance tells you what is in place; maturity tells you how deeply it is embedded.
Before assessing, an entity files a Statement of Applicability declaring which domains and sub domains apply. CBK also profiles each entity's inherent risk across eleven dimensions to place it in a supervisory tier that sets how often it is assessed.
Open the workbook and work top to bottom through the tabs. Everything saves in your browser as you go.
Go through each domain and sub domain and mark it Applicable or Not applicable, adding a justification wherever it does not apply. This mirrors the CORF Statement of Applicability. Anything you mark Not applicable drops out of every score, so your results reflect only what your entity actually does.
Pick a sub domain from the tree on the left. For each control, choose Compliant, Non compliant, or N/A, and drop the supporting evidence into the note beside it. The tree shows your progress and colours each sub domain by how compliant it is, so you always know what is left.
At the top of each sub domain, choose a maturity level from one to five with a short rationale. The workbook enforces the CORF rule for you: you cannot select Baseline or higher until every applicable control in that sub domain is compliant. Until then, levels three, four, and five stay locked.
The dashboard aggregates everything: overall compliance and maturity, a compliance bar for every domain, and a maturity radar for each baseline. It is the view that shows where your posture is strong and where the gaps concentrate.
Every control you marked Non compliant becomes a gap. Give each one a priority, an owner, a target date, and a status, and track it to closed. Download the plan as CSV to share with management. This is the remediation step the CORF lifecycle asks for.
Export your assessment to a JSON file to keep it safe, move it to another machine, or hand it to a colleague or assessor. Import brings it back. You can also print the whole thing to a clean PDF for your records.
The workbook computes scores exactly the way the CORF describes, so what you see matches how CBK reads an assessment.
A sub domain's compliance is the share of its applicable controls marked compliant. Not applicable controls are left out of the sum. Domain compliance is the average across its sub domains, and the overall score is the average across domains.
You set a level from one to five for each sub domain. Domain maturity is the average of its sub domains, and overall maturity is the average across domains. The scale is progressive, so higher levels require demonstrable achievement of the ones below.
Reactive, informal, undocumented.
Partial, inconsistent, siloed.
Documented, risk based, measured.
Automated, integrated, proactive.
Anticipatory, intelligence led, real time.
The workbook is a single HTML file that runs entirely in your browser. There is no server, no account, and no telemetry. Nothing you type is ever transmitted anywhere. Save it locally and use it on an air gapped machine if you like. For a bank handling a regulatory self assessment, that matters.
Open the workbook and begin with the Applicability tab.
This workbook is an independent, open source aid built to help entities work through the CBK Cyber and Operational Resilience Framework. It encodes the assessment methodology described in the framework (control level compliance, sub domain maturity, and the roll up from sub domain to domain to overall). It is not affiliated with, endorsed by, or produced by the Central Bank of Kuwait, and it is not the official CORF toolkit nor a substitute for a CBK approved assessor. The control catalog is extracted programmatically from the published CORF v1.0 document; 874 of the 876 controls are captured and it should be validated against the source before formal use. Always refer to the official CORF documents for authoritative requirements.