Cybersecurity ยท Bahrain
Cybersecurity law & regulation in Bahrain (2026)
Bahrain shaded by its cybersecurity status
Cybersecurity in Bahrain: sectoral rules.
FrameworkNational Cyber Security Center (NCSC) established under Royal Decree No. 65 of 2020 with responsibilities defined by Royal Order No. 17 of 2025; supported by Law No. 60 of 2014 on IT Crimes, CNI Cybersecurity Controls, CBB Rulebook cybersecurity requirements for financial firms, and PDPL (Law No. 30 of 2018) breach-notification duties
Bahrain does not have a single horizontal NIS2-style cybersecurity statute, but operates a layered regime built around the National Cyber Security Center (NCSC) โ whose mandate was formally defined by Royal Order No. 17 of 2025 โ plus sector-specific mandatory controls for Critical National Infrastructure (CNI) and the financial sector, and criminal offences under the 2014 IT Crimes Law. Mandatory cyber-incident reporting to the NCSC applies to CNI entities; broad private-sector incident reporting to the NCSC remains voluntary, while personal-data breach notification (72 hours) is mandatory under the PDPL and Order No. 43 of 2022.
Key points
Royal Order No. 17 of 2025 (issued 10 July 2025) defines the NCSC's mandate to develop cybersecurity legislation, issue mandatory policies, publish specifications/frameworks, run the national incident response framework, and oversee protection of National Critical Sectors. It operates under the Supreme Defence Council.
The NCSC has issued CNI Cybersecurity Controls covering GEO (Gas/Electricity/Oil), Financial Services, ICT, Healthcare, Government Services, Critical Industry and Transportation, addressing cloud security, network security, third-party risk, data protection and incident reporting for designated CNI entities.
Bahrain's second national cyber strategy (2025-2028) provides the current policy framework for protecting digital infrastructure, strengthening cyber leadership and building a trusted digital environment, building on the 2020-2024 strategy.
The Central Bank of Bahrain Rulebook (Volumes 1, 2, 5) sets mandatory cybersecurity requirements for licensed banks, insurers and other financial institutions, including risk-management controls, mandatory multi-factor authentication for remote/admin/customer/critical systems, vulnerability and patch management, and incident-reporting to the CBB.
Under the Personal Data Protection Law (Law No. 30 of 2018) and Order No. 43 of 2022 (Article 4), controllers must notify Bahrain's Personal Data Protection Authority within 72 hours of becoming aware of a personal-data breach, and must inform affected data subjects where the breach is likely to pose a high risk to their rights.
Law No. 60 of 2014 on Information Technology Crimes criminalises illegal access, data/system interference, illegal interception, misuse of devices, IT-enabled fraud and content-related offences, with penalties up to 10 years' imprisonment and BD 300,000 fines for the most serious offences.
Critical National Infrastructure entities are required to report cyber incidents to the NCSC, while other private-sector organisations are not currently subject to a mandatory NCSC incident-reporting obligation and may report voluntarily via the NCSC's incident-reporting channel.
Timeline - major decisions & events
The Central Bank of Bahrain published updated Cyber Security Requirements in its Rulebook, consolidating board-level oversight, risk assessment, penetration testing and incident-reporting duties across banking, insurance and capital-market firms. It standardizes the cyber obligations applying to Bahrain's regulated financial sector.
Central Bank of Bahrain Rulebook โKing Hamad issued Royal Order No. 17 of 2025 giving the National Cybersecurity Center (NCC) legislative, policy and technical authority, proposing cyber laws, issuing mandatory policies and standards, coordinating threat-sharing, and overseeing critical sectors under the Supreme Defence Council. It clarified the mandate left undefined when the NCC was created.
Library of Congress (Global Legal Monitor) โThe National Cyber Security Center issued a National Risk Management Framework and CNI cybersecurity controls covering seven critical sectors (energy, financial services, ICT, healthcare, government, critical industry, transport). It set the baseline technical controls operators of critical infrastructure must adopt.
National Cyber Security Center โThe Central Bank of Bahrain amended its Crypto-Asset (CRA) Module to introduce cybersecurity control guidelines aimed at protecting clients' digital assets. It extended formal cyber obligations to crypto-asset service providers operating in Bahrain.
Central Bank of Bahrain โBahrain stood up the Personal Data Protection Authority (PDPA) and issued ten ministerial resolutions implementing the PDPL, covering security measures, breach handling and cross-border transfers. It marked the start of active enforcement of the data-protection and data-security regime.
Personal Data Protection Authority โRoyal Decree No. 65 of 2020 created the National Cybersecurity Center as the central national authority for cybersecurity, though it left detailed responsibilities to be defined later (by Royal Order No. 17 of 2025). It centralized national cyber governance for the first time.
National Cyber Security Center โBahrain published a five-pillar national strategy spanning resilient cyber defenses, governance and standards, public awareness, partnerships, and workforce development. It established the policy roadmap and CNI-sector approach underpinning today's framework.
National Cyber Security Center โThe Central Bank of Bahrain added cybersecurity chapters to its Operational Risk and Risk Management modules, mandating board accountability, periodic control assessments, biannual penetration testing, cyber insurance and staff training. It created the financial sector's binding cyber obligations.
Central Bank of Bahrain โBahrain enacted its first comprehensive data-protection statute, governing collection, processing, storage and transfer of personal data and mandating safeguards against unauthorized access, loss or disclosure. It laid the legal foundation for data-security obligations nationwide.
Ministry of Justice (Legislation Portal) โBahrain enacted its cybercrime law criminalizing illegal access, data and system interference, illegal interception, misuse of devices and content offences, with fines up to BHD 100,000. It remains the core criminal framework backing cybersecurity enforcement.
ILO NATLEX โBahrain - other topics
Cybersecurity in other countries
Last verified 8/4/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ