CBK CORF Assessment Toolkit

Cyber and Operational Resilience Framework Compliance Tool

⚠️ Educational Tool Disclaimer

This tool is provided for educational and informational purposes only. It is designed to help information security teams understand and assess their compliance readiness with the Central Bank of Kuwait (CBK) Cyber and Operational Resilience Framework (CORF). This tool does not constitute legal, regulatory, or professional advice. Organizations must engage qualified professionals and CBK-approved third-party assessors for official compliance assessments. The creators assume no liability for decisions made based on the information provided by this tool.

About CBK CORF

The Cyber and Operational Resilience Framework (CORF) is a comprehensive regulatory framework issued by the Central Bank of Kuwait (CBK) in December 2025. It replaces the 2020 Cybersecurity Framework and expands coverage to include cyber resilience, operational resilience, and third-party risk management for all CBK-regulated financial institutions.

Total Controls

876

Total Domains

27

Baselines

3

Key Framework Features

🎯 Resilience-First Approach

Shifts from pure compliance to a maturity-driven resilience model focused on anticipating, withstanding, recovering from, and adapting to cyber and operational disruptions.

📊 Tiered Assessment Model

Risk-based supervisory tiering determines assessment frequency and intensity based on systemic importance, operational complexity, and cyber risk exposure.

📈 Five-Level Maturity Model

Evaluates capabilities across five levels: Initial, Ad-hoc, Baseline, Advanced, and Innovative - measuring how well cybersecurity and resilience are embedded and continuously improved.

👥 Board-Level Accountability

Ultimate accountability for cyber and operational resilience sits with the Board of Directors, requiring active oversight and governance involvement.

CORF Baselines Structure

🔒 Cyber Resilience Baseline

Comprehensive cybersecurity controls covering governance, technology operations, and emerging technologies.

6
Domains
33
Sub-Domains
87
Control Areas
519
Controls

⚙️ Operational Resilience Baseline

Focus on business continuity, disaster recovery, and technology resilience capabilities.

8
Domains
17
Sub-Domains
35
Control Areas
146
Controls

🤝 Third-Party Risk Management

Comprehensive TPRM controls from governance and contracts through incident management and data protection.

13
Domains
43
Sub-Domains
78
Control Areas
211
Controls

Quick Self-Assessment

This self-assessment helps you gauge your current compliance readiness. Select your baseline and answer the questions to receive a preliminary maturity score.

Resources & Documentation

📄 Official CORF Document

Access the official CBK Cyber and Operational Resilience Framework published in December 2025.

View PDF →

🏦 Central Bank of Kuwait

Visit the official CBK website for latest circulars, guidance, and regulatory updates.

Visit CBK →

🛡️ NCSC Kuwait

National Cyber Security Center resources and sector-wide collaboration initiatives.

Visit NCSC →

📚 Implementation Guide

Best practices for implementing CORF controls and achieving compliance readiness.

Coming Soon →

🎓 Training Resources

Educational materials and training programs for security teams and board members.

Coming Soon →

🔧 Gap Analysis Tool

Detailed gap analysis templates and maturity assessment worksheets.

Coming Soon →