CST Cybersecurity Regulatory Framework

CST CRF

What it is

The Cybersecurity Regulatory Framework (CRF) — CST’s requirements for licensed service providers in the information and communications technology sector, set at three compliance levels.

What it covers

  1. 01Governance
  2. 02Asset management
  3. 03Risk management
  4. 04Logical security
  5. 05Physical security
  6. 06Third-party security

How we help

  • Compliance level confirmation
  • CRF gap assessment
  • Policy and control uplift
  • Audit readiness

In depth

The CRF sets its controls at three compliance levels — CL1, CL2 and CL3. The level rises with a provider’s size, how critical its services are and its risk; the domains stay the same, while the depth, formality and monitoring required grow with each level.

We confirm the level that applies to you, assess each domain at that depth, and get your evidence ready for the compliance audit.

Related services

Other frameworks we work with

Ready to meet CST CRF?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Trust

Built around the regulators you answer to

SAMA
Saudi Central BankCSF · BCM · CRFR
NCA
National Cybersecurity AuthorityECC-2:2024 · CSCC · CCC
SDAIA
Saudi Data & AI AuthorityPDPL
CMA
Capital Market AuthorityCSG
CST
Communications, Space & Technology CommissionCRF
14regulatory frameworks

Ready to talk about your compliance?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Regulatory updates in your inbox

SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.

We confirm by e-mail; unsubscribe any time.

Schedule a Free Assessment