CST Cybersecurity Regulatory Framework
CST CRF
What it is
The Cybersecurity Regulatory Framework (CRF) — CST’s requirements for licensed service providers in the information and communications technology sector, set at three compliance levels.
What it covers
- 01Governance
- 02Asset management
- 03Risk management
- 04Logical security
- 05Physical security
- 06Third-party security
How we help
- Compliance level confirmation
- CRF gap assessment
- Policy and control uplift
- Audit readiness
In depth
The CRF sets its controls at three compliance levels — CL1, CL2 and CL3. The level rises with a provider’s size, how critical its services are and its risk; the domains stay the same, while the depth, formality and monitoring required grow with each level.
We confirm the level that applies to you, assess each domain at that depth, and get your evidence ready for the compliance audit.
Related services
Other frameworks we work with
Ready to meet CST CRF?
Tell us where you stand. We will show you the shortest path to what your regulator expects.
Built around the regulators you answer to
Ready to talk about your compliance?
Tell us where you stand. We will show you the shortest path to what your regulator expects.
