CST · Cybersecurity Regulation
CST Cybersecurity Regulatory Framework (CRF) Audit
An independent assessment that maps the CST Cybersecurity Regulatory Framework (CRF) — formerly CITC — to real implementation evidence and a calculated compliance score per domain, so you pass the regulator’s review with confidence and submit a defensible report for your target level.
Regulatory framework · CRF
Compliance levels
Documented trust across compliance & independent-audit projects















Overview
The CRF as a regulatory obligation for licensed providers
From CITC to CST
The Communications and Information Technology Commission (CITC, today the Communications, Space & Technology Commission — CST) issued the CRF to raise the maturity of licensed entities in the ICT and postal sector. We begin by confirming the licence, applicability, target level, critical services and technology dependencies.
An independent, defensible assessment
We map each applicable control to its current state, owner and evidence source, then calculate a compliance percentage per domain. The goal is not a file for a one-off review, but controls that work repeatedly and evidence showing the correct scope and review period — compliance that holds up before the regulator.
Business challenges
What makes CRF compliance hard
An unsettled target level
Many start without pinning down the required compliance level, measuring against controls that do not apply or missing mandatory ones.
Insufficient or fragmented evidence
Policies, technical records and operational evidence are disconnected from the controls they support, weakening the score despite the effort spent.
A governance-to-practice gap
Having a policy is not the same as operating it; an independent audit looks for evidence of repeated operation, not documents alone.
Audit scope
Full coverage of the CRF domains
We measure your compliance across the framework’s main domains and their sub-controls, according to your target level.
Cybersecurity governance
Strategy, policies, roles, risk management, awareness and compliance.
Cybersecurity defense
Asset & identity management, network and data security, cryptography and vulnerability management.
Monitoring & incident response
Event and log monitoring, cyber incident management and response.
Resilience & continuity
Business continuity, disaster recovery and resilience of critical services.
Third-party security
Assessment of vendors, service providers, contracts and external risk.
Cloud computing security
Hosting and cloud service controls, data location and environment separation.
Audit methodology
From level scoping to a report you submit to the regulator
Discover
Confirm the licence, applicability, target level, scope and business services.
Assess
Review policies, configurations, interviews and representative evidence against CRF controls.
Measure
Calculate the compliance percentage per domain and prioritise gaps by risk.
Report
A documented, independent report ready for regulator submission, with a remediation plan.
Deliverables
Documents and evidence for the regulator and the team
- Scope and target-level statement
- Independent assessment against CRF controls
- Compliance percentage per domain
- Evidence register and observations
- Prioritised gap-remediation plan
- Final report ready for regulator submission
Business value
Outcomes for leadership, compliance and the regulator
Regulator-accepted compliance
An independent, evidence-based report that passes the regulator’s review for your target level.
Clarity on gaps and priorities
A per-domain score and a prioritised remediation roadmap for informed risk decisions.
Sustainable compliance
Controls that keep working after the audit and hold up in future review cycles.
Related services
Frameworks and services that strengthen readiness
Penetration testing
Vulnerability assessment and penetration testing as part of cyber-defense requirements.
Learn more →NCA & SAMA compliance
NCA Essential Controls and the SAMA Cyber Security Framework.
Learn more →PDPL data protection
Personal data governance and data-subject rights under the Saudi law.
Learn more →FAQ
Practical answers before the audit
What is the CRF and who must comply?
A regulatory framework issued by the Communications, Space & Technology Commission (formerly CITC) requiring CST-licensed service providers in the ICT and postal sector to raise cybersecurity maturity and periodically demonstrate compliance through an independent assessment.
How do compliance levels CL1 to CL4 differ?
Entities are assigned a target compliance level based on their size and the sensitivity of their services; the number of controls and the depth of evidence increase from CL1 to CL4. We confirm your target level first, then measure compliance against it.
Is the assessment independent and accepted by the regulator?
Yes — we perform an independent assessment against the framework controls, with documented evidence and a calculated compliance percentage per domain, in a signed report ready for submission to the Commission.
How long does the audit and path to compliance take?
Timelines are scoped after an initial assessment based on the target level, current control maturity, gap size and system scope — we start from a clear baseline, then a prioritised remediation plan.
How does the CRF relate to NCA Essential Cybersecurity Controls (ECC)?
We align controls across frameworks to avoid duplication, so one control can satisfy multiple requirements where applicable — reducing effort and cost and unifying evidence.
Start from your current state
Discuss your CRF audit readiness
Share the essentials and a specialist will contact you to define the target level, scope and next step.