The National Fundamental Cybersecurity Controls are an essential step to protect national interests, public services, economic stability, and the safety of citizens and residents in the State of Kuwait. They were issued by the National Cyber Security Center (NCSC), established by Amiri Decree No. 37 of 2022.
What the baseline is
- Aligned with recognized international frameworks, particularly CIS Controls v8.1 - Implementation Group 1 (IG1) and the NIST Cybersecurity Framework (CSF).
- Referenced to the National Data Classification Framework (Decision No. 1 of 2025).
- Risk-oriented and practical, designed for entities with limited cybersecurity resources.
- A starting point, not an end state; entities can later build on it with more advanced controls.
Objectives
- Establish a national baseline of realistic, implementable minimum controls for a common level of cybersecurity hygiene.
- Align with international best practice such as CIS Controls v8.1 and NIST CSF, adapted to Kuwait's regulatory context.
- Promote accountability and risk management through clear responsibilities, data classification, and service-provider management.
- Enable measurable compliance through periodic self-assessment against the baseline.
Control structure
The baseline controls are grouped by the NIST CSF functions:
- GOV - Govern: establish and monitor the entity's cybersecurity risk management strategy and policies.
- ID - Identify: determine current cybersecurity risk to the entity.
- PR - Protect: prevent or reduce cybersecurity risks.
- DE - Detect: find and analyze possible attacks and compromise.
- RS - Respond: take action on detected incidents.
- RC - Recover: restore affected assets and operations.
Appendix A - Cloud minimum security controls
This appendix applies to all entities using public cloud services (SaaS, PaaS, IaaS) and complements the national baseline with cloud-specific handling:
- Shared responsibility: the Cloud Service Provider secures the infrastructure while the entity secures its data and configuration.
- Identity as the perimeter: in the cloud, identity (who you are) matters more than the network (where you are).
- Distinguishing customer content from operational metadata to ensure technical feasibility.
The full document is available through official publication channels. Our office supports entities with applying and evidencing compliance with these requirements.