CST · Cybersecurity Regulation

CST Cybersecurity Regulatory Framework (CRF) Audit

An independent assessment that maps the CST Cybersecurity Regulatory Framework (CRF) — formerly CITC — to real implementation evidence and a calculated compliance score per domain, so you pass the regulator’s review with confidence and submit a defensible report for your target level.

Target-level scoping Independent evidence review Report ready for the regulator

Regulatory framework · CRF

Compliance levels

Target level CL1 – CL4
Assessment Independent
Output Score + report

Documented trust across compliance & independent-audit projects

CL1–4
CRF compliance levels
100%
Independent, evidence-based
18+
Specialized cyber services
24/7
Continuous response

Overview

The CRF as a regulatory obligation for licensed providers

From CITC to CST

The Communications and Information Technology Commission (CITC, today the Communications, Space & Technology Commission — CST) issued the CRF to raise the maturity of licensed entities in the ICT and postal sector. We begin by confirming the licence, applicability, target level, critical services and technology dependencies.

An independent, defensible assessment

We map each applicable control to its current state, owner and evidence source, then calculate a compliance percentage per domain. The goal is not a file for a one-off review, but controls that work repeatedly and evidence showing the correct scope and review period — compliance that holds up before the regulator.

Business challenges

What makes CRF compliance hard

01

An unsettled target level

Many start without pinning down the required compliance level, measuring against controls that do not apply or missing mandatory ones.

02

Insufficient or fragmented evidence

Policies, technical records and operational evidence are disconnected from the controls they support, weakening the score despite the effort spent.

03

A governance-to-practice gap

Having a policy is not the same as operating it; an independent audit looks for evidence of repeated operation, not documents alone.

Audit scope

Full coverage of the CRF domains

We measure your compliance across the framework’s main domains and their sub-controls, according to your target level.

Cybersecurity governance

Strategy, policies, roles, risk management, awareness and compliance.

Cybersecurity defense

Asset & identity management, network and data security, cryptography and vulnerability management.

Monitoring & incident response

Event and log monitoring, cyber incident management and response.

Resilience & continuity

Business continuity, disaster recovery and resilience of critical services.

Third-party security

Assessment of vendors, service providers, contracts and external risk.

Cloud computing security

Hosting and cloud service controls, data location and environment separation.

Audit methodology

From level scoping to a report you submit to the regulator

01

Discover

Confirm the licence, applicability, target level, scope and business services.

02

Assess

Review policies, configurations, interviews and representative evidence against CRF controls.

03

Measure

Calculate the compliance percentage per domain and prioritise gaps by risk.

04

Report

A documented, independent report ready for regulator submission, with a remediation plan.

Deliverables

Documents and evidence for the regulator and the team

  • Scope and target-level statement
  • Independent assessment against CRF controls
  • Compliance percentage per domain
  • Evidence register and observations
  • Prioritised gap-remediation plan
  • Final report ready for regulator submission

Business value

Outcomes for leadership, compliance and the regulator

Regulator-accepted compliance

An independent, evidence-based report that passes the regulator’s review for your target level.

Clarity on gaps and priorities

A per-domain score and a prioritised remediation roadmap for informed risk decisions.

Sustainable compliance

Controls that keep working after the audit and hold up in future review cycles.

FAQ

Practical answers before the audit

What is the CRF and who must comply?

A regulatory framework issued by the Communications, Space & Technology Commission (formerly CITC) requiring CST-licensed service providers in the ICT and postal sector to raise cybersecurity maturity and periodically demonstrate compliance through an independent assessment.

How do compliance levels CL1 to CL4 differ?

Entities are assigned a target compliance level based on their size and the sensitivity of their services; the number of controls and the depth of evidence increase from CL1 to CL4. We confirm your target level first, then measure compliance against it.

Is the assessment independent and accepted by the regulator?

Yes — we perform an independent assessment against the framework controls, with documented evidence and a calculated compliance percentage per domain, in a signed report ready for submission to the Commission.

How long does the audit and path to compliance take?

Timelines are scoped after an initial assessment based on the target level, current control maturity, gap size and system scope — we start from a clear baseline, then a prioritised remediation plan.

How does the CRF relate to NCA Essential Cybersecurity Controls (ECC)?

We align controls across frameworks to avoid duplication, so one control can satisfy multiple requirements where applicable — reducing effort and cost and unifying evidence.

Start from your current state

Discuss your CRF audit readiness

Share the essentials and a specialist will contact you to define the target level, scope and next step.

01Initial needs review
02Target-level definition
03A practical next step

Your information will only be used to respond to this request.