Skip to content
World Watch/Bahrain/Cybersecurity

Cybersecurity ยท Bahrain

Cybersecurity law & regulation in Bahrain (2026)

Sectoral rulesCountry index 79 ยท B+

Bahrain shaded by its cybersecurity status

Cybersecurity in Bahrain: sectoral rules.

FrameworkNational Cyber Security Center (NCSC) established under Royal Decree No. 65 of 2020 with responsibilities defined by Royal Order No. 17 of 2025; supported by Law No. 60 of 2014 on IT Crimes, CNI Cybersecurity Controls, CBB Rulebook cybersecurity requirements for financial firms, and PDPL (Law No. 30 of 2018) breach-notification duties

Bahrain does not have a single horizontal NIS2-style cybersecurity statute, but operates a layered regime built around the National Cyber Security Center (NCSC) โ€” whose mandate was formally defined by Royal Order No. 17 of 2025 โ€” plus sector-specific mandatory controls for Critical National Infrastructure (CNI) and the financial sector, and criminal offences under the 2014 IT Crimes Law. Mandatory cyber-incident reporting to the NCSC applies to CNI entities; broad private-sector incident reporting to the NCSC remains voluntary, while personal-data breach notification (72 hours) is mandatory under the PDPL and Order No. 43 of 2022.

Key points

NCSC as central authority

Royal Order No. 17 of 2025 (issued 10 July 2025) defines the NCSC's mandate to develop cybersecurity legislation, issue mandatory policies, publish specifications/frameworks, run the national incident response framework, and oversee protection of National Critical Sectors. It operates under the Supreme Defence Council.

Critical National Infrastructure controls

The NCSC has issued CNI Cybersecurity Controls covering GEO (Gas/Electricity/Oil), Financial Services, ICT, Healthcare, Government Services, Critical Industry and Transportation, addressing cloud security, network security, third-party risk, data protection and incident reporting for designated CNI entities.

National Cyber Security Strategy 2025-2028

Bahrain's second national cyber strategy (2025-2028) provides the current policy framework for protecting digital infrastructure, strengthening cyber leadership and building a trusted digital environment, building on the 2020-2024 strategy.

Financial-sector cyber rules (CBB)

The Central Bank of Bahrain Rulebook (Volumes 1, 2, 5) sets mandatory cybersecurity requirements for licensed banks, insurers and other financial institutions, including risk-management controls, mandatory multi-factor authentication for remote/admin/customer/critical systems, vulnerability and patch management, and incident-reporting to the CBB.

Personal-data breach notification (72 hours)

Under the Personal Data Protection Law (Law No. 30 of 2018) and Order No. 43 of 2022 (Article 4), controllers must notify Bahrain's Personal Data Protection Authority within 72 hours of becoming aware of a personal-data breach, and must inform affected data subjects where the breach is likely to pose a high risk to their rights.

Cybercrime criminal law

Law No. 60 of 2014 on Information Technology Crimes criminalises illegal access, data/system interference, illegal interception, misuse of devices, IT-enabled fraud and content-related offences, with penalties up to 10 years' imprisonment and BD 300,000 fines for the most serious offences.

CNI reporting mandatory, private-sector voluntary

Critical National Infrastructure entities are required to report cyber incidents to the NCSC, while other private-sector organisations are not currently subject to a mandatory NCSC incident-reporting obligation and may report voluntarily via the NCSC's incident-reporting channel.

Timeline - major decisions & events

Jul 17, 2025guidance
CBB issues consolidated Cyber Security Requirements for financial licensees

The Central Bank of Bahrain published updated Cyber Security Requirements in its Rulebook, consolidating board-level oversight, risk assessment, penetration testing and incident-reporting duties across banking, insurance and capital-market firms. It standardizes the cyber obligations applying to Bahrain's regulated financial sector.

Central Bank of Bahrain Rulebook โ†—
Jul 10, 2025lawofficial
Royal Order No. 17 of 2025 defines and strengthens the National Cybersecurity Center's powers

King Hamad issued Royal Order No. 17 of 2025 giving the National Cybersecurity Center (NCC) legislative, policy and technical authority, proposing cyber laws, issuing mandatory policies and standards, coordinating threat-sharing, and overseeing critical sectors under the Supreme Defence Council. It clarified the mandate left undefined when the NCC was created.

Library of Congress (Global Legal Monitor) โ†—
Jun 1, 2023guidanceofficial
NCSC publishes National Risk Management Framework for Critical National Infrastructure

The National Cyber Security Center issued a National Risk Management Framework and CNI cybersecurity controls covering seven critical sectors (energy, financial services, ICT, healthcare, government, critical industry, transport). It set the baseline technical controls operators of critical infrastructure must adopt.

National Cyber Security Center โ†—
Mar 1, 2023guidanceofficial
CBB adds cybersecurity control guidelines to the Crypto-Asset Module

The Central Bank of Bahrain amended its Crypto-Asset (CRA) Module to introduce cybersecurity control guidelines aimed at protecting clients' digital assets. It extended formal cyber obligations to crypto-asset service providers operating in Bahrain.

Central Bank of Bahrain โ†—
Mar 17, 2022guidanceofficial
Personal Data Protection Authority operationalized with 10 supplementing resolutions

Bahrain stood up the Personal Data Protection Authority (PDPA) and issued ten ministerial resolutions implementing the PDPL, covering security measures, breach handling and cross-border transfers. It marked the start of active enforcement of the data-protection and data-security regime.

Personal Data Protection Authority โ†—
Jan 1, 2020lawofficial
National Cyber Security Center established by Royal Decree No. 65 of 2020

Royal Decree No. 65 of 2020 created the National Cybersecurity Center as the central national authority for cybersecurity, though it left detailed responsibilities to be defined later (by Royal Order No. 17 of 2025). It centralized national cyber governance for the first time.

National Cyber Security Center โ†—
Jan 1, 2020guidanceofficial
Bahrain launches National Cyber Security Strategy 2020-2024

Bahrain published a five-pillar national strategy spanning resilient cyber defenses, governance and standards, public awareness, partnerships, and workforce development. It established the policy roadmap and CNI-sector approach underpinning today's framework.

National Cyber Security Center โ†—
Dec 1, 2019guidanceofficial
CBB introduces mandatory cyber security risk-management requirements for banks

The Central Bank of Bahrain added cybersecurity chapters to its Operational Risk and Risk Management modules, mandating board accountability, periodic control assessments, biannual penetration testing, cyber insurance and staff training. It created the financial sector's binding cyber obligations.

Central Bank of Bahrain โ†—
Jul 12, 2018lawofficial
Personal Data Protection Law No. 30 of 2018 enacted

Bahrain enacted its first comprehensive data-protection statute, governing collection, processing, storage and transfer of personal data and mandating safeguards against unauthorized access, loss or disclosure. It laid the legal foundation for data-security obligations nationwide.

Ministry of Justice (Legislation Portal) โ†—
Jan 1, 2014lawofficial
Law No. 60 of 2014 on Information Technology Crimes

Bahrain enacted its cybercrime law criminalizing illegal access, data and system interference, illegal interception, misuse of devices and content offences, with fines up to BHD 100,000. It remains the core criminal framework backing cybersecurity enforcement.

ILO NATLEX โ†—

Bahrain - other topics

Cybersecurity in other countries

Last verified 8/4/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ†’