NBCC Kuwait: What Security Leaders Need to Know About the New Cybersecurity Baseline

For years, cybersecurity in Kuwait meant different rules for different sectors. Banks answered to one regulator, government bodies to another, and everyone else largely set their own bar. That changed in 2026.
Kuwait’s National Basic Cybersecurity Controls, known as the NBCC, is now the country’s first unified cybersecurity baseline. Issued by the National Cyber Security Center under Decision No. 2 of 2026, it applies to government authorities, military and security bodies, and private sector entities connected to the NCSC’s mandate. For any CISO or compliance officer operating in Kuwait, understanding this framework is no longer optional homework. It is a compliance deadline with a clock already running.
What is NBCC Kuwait?
The National Basic Cybersecurity Controls, or NBCC, set the minimum cybersecurity controls expected from covered entities in Kuwait. The controls were adopted by the National Cyber Security Center, which was established as the competent national authority for cybersecurity under Amiri Decree No. 37 of 2022.
The purpose is to create a consistent national cybersecurity baseline. This includes stronger cyber readiness, protection of government and private-sector cybersecurity assets, clearer accountability, risk management, compliance oversight, and enforceable measurement at the national level.
The important point is that NBCC should be treated as a baseline, not a full maturity target. Organizations may still need stronger controls based on their sector, data sensitivity, cloud usage, third-party exposure, and operational risk.
Who Actually Falls Under the NBCC
The scope is broader than government alone, but it is not automatically every private company in the country. Organizations fall into three practical categories.
Entities directly designated by the NCSC, or those operating critical infrastructure, sit squarely inside the mandatory scope. Companies that supply cloud services, managed IT, or data processing to a covered entity are often indirectly affected, since NBCC requirements tend to flow into their client’s procurement contracts and audits. Everyone else is encouraged to adopt the controls voluntarily to build a stronger security baseline, even without a legal obligation to do so.
Because the boundary depends on the NCSC’s designation powers, a documented scope assessment is the safer starting point rather than an assumption in either direction.
Foreign SaaS and cloud vendors deserve a specific mention here. A vendor based outside Kuwait does not automatically become directly regulated just because a Kuwaiti client uses its service. That client can still push NBCC requirements downstream through procurement questionnaires and contract terms, asking about data residency, subprocessors, encryption, and incident notification. A foreign provider that answers vaguely, pointing only to a general ISO certificate, may leave its Kuwaiti customer unable to complete its own compliance review. Vendor due diligence is quickly becoming part of how the NBCC gets enforced in practice, even for companies that never interact with the NCSC directly.
The Six Control Domains
The NBCC is structured around the same six functions used in the NIST Cybersecurity Framework, giving organizations already working toward NIST or ISO 27001 a real head start.
Govern requires a named cybersecurity owner at manager level or above, along with approved policies and a documented exception process for anything that cannot be met as written.
Identify calls for full inventories of hardware, software, cloud services, data, and user accounts. You cannot protect an asset the organization does not know it has.
Protect covers the technical basics: secure configuration, patching, access control, multi-factor authentication, malware protection, and tested backups.
Detect requires audit logging on critical systems, with logs retained for at least 90 days in live form and 12 months in total.
Respond demands a documented incident plan, named response leads, and clear routes for notifying the NCSC when an incident qualifies.
Recover requires recovery arrangements that are actually tested, not just written down and filed away.
A cloud security appendix sits alongside these six domains, covering provider authorization, encryption, data residency, and contractual protections for organizations using cloud infrastructure.
Requirements That Are Easy to Underestimate
A few parts of the NBCC catch organizations off guard. Personal email accounts and unapproved messaging tools are explicitly restricted for business communication, which means a review of everyday habits like using personal Gmail on a work laptop. Data classification is expected to influence real controls, not just sit in a spreadsheet with labels nobody acts on. Annual self-assessment records must be kept for at least three years, and dormant user accounts should be disabled after 90 days where technically supported.
None of these are exotic requirements. They are simply the kind of operational discipline that tends to get skipped when cybersecurity is treated as a documentation exercise instead of a living program.
The evidence problem
One of the biggest NBCC challenges will be evidence. Covered entities must complete at least one annual self-assessment using NCSC-approved templates, keep compliance evidence, make records available when requested, and achieve full compliance within 18 months unless a documented exception is granted.
This means organizations need a repeatable way to collect and maintain proof. A policy stored in a folder is not enough. Teams need control owners, review logs, screenshots, tickets, risk records, vendor assessments, patch records, backup tests, incident reports, exception approvals, and remediation updates.
This is where a GRC platform becomes important. Complyan Audit and Compliance Management supports gap assessments, compliance documentation, evidenc
Does ISO 27001 Cover This Already?
Not automatically. ISO 27001 addresses many of the same areas: governance, risk assessment, access control, supplier security, and incident management. But it does not verify Kuwait-specific items such as NCSC reporting routes, the 18-month evidence retention rule, or approval requirements for storing sensitive data outside the country.
The efficient path is building one control library and mapping it across NBCC, ISO 27001, and NIST CSF at the same time, rather than running separate compliance programs that duplicate the same evidence collection twice.
Why an 18-Month Deadline Is Shorter Than It Looks
Covered entities have 18 months from publication to reach full compliance, which sounds generous until the work is broken down. Building accurate asset inventories, renegotiating cloud contracts, formalizing incident response, and generating a full year of consistent evidence all take time that cannot be compressed into the final weeks before an audit.
Organizations already using a structured compliance platform have a real advantage here. A tool such as Complyan’s Kuwait cybersecurity guidance helps map existing controls against local requirements instead of starting from a blank page, which matters when several NBCC obligations overlap with what banks in Kuwait already track under the Central Bank of Kuwait’s cybersecurity framework.
Common Mistakes to Avoid
Several patterns show up again and again as organizations work through NBCC readiness.
- Treating it as a paperwork exercise. Policies matter, but the NBCC expects evidence of controls actually operating, not just existing on paper.
- Assuming automatic coverage from ISO 27001. Certification helps, but it does not replace a Kuwait-specific gap assessment.
- Waiting too long to review supplier and cloud contracts. Large providers can take months to accommodate new clauses, so early conversations matter.
- Collecting evidence only right before an audit. Reconstructed records are weaker than evidence generated naturally through daily operations.
Building a Program That Holds Up
The NBCC is not asking for the highest possible level of security maturity. It is asking for a demonstrable baseline: named accountability, real inventories, working controls, and evidence that can survive a regulator’s request. Organizations that centralize this work in a single GRC platform, such as Complyan, tend to move through the 18-month window with far less duplicated effort than those tracking everything across spreadsheets and email threads.
Kuwait’s cybersecurity regulation is only going to get more structured from here. Getting the fundamentals of the NBCC right now puts an organization in a stronger position for whatever comes next.
Governance and Policy Management