GRC Consulting Services

NIST CSF consultancy and central bank compliance

Apply the NIST Cybersecurity Framework and central bank cybersecurity mandates to the customer's environment with controls, evidence, and reporting.

About the service

Service Description

NIST CSF consultancy is a structured program to assess, design, and operationalise a cybersecurity program against the NIST Cybersecurity Framework, with explicit mapping to the regulatory expectations of the CBB and other GCC central banks.

Why this service matters

The business case

Central banks in the GCC now expect regulated entities to demonstrate NIST CSF-aligned cybersecurity programs, with documented evidence. A structured program gives the board, the regulator, and the customer the assurance they need.

What is delivered

Service deliverables

Each engagement produces a working set of artefacts that the customer can hand to auditors, regulators, internal stakeholders, and partners. The exact list is calibrated to the scope.

  • NIST CSF function and category assessment
  • Central bank cybersecurity mandate mapping and evidence collection
  • Remediation tracking and regulator-ready reporting

Delivery method

Axpert Service Delivery Model

Current-state assessment against NIST CSF 2.0, target-state design aligned to CBB and SAMA expectations, control implementation, evidence collection, and regulator-ready reporting.

Methodology alignment

Standards and frameworks

  • NIST CSF 2.0
  • NIST SP 800-53
  • NIST SP 800-171
  • CBB Cyber Risk Management
  • SAMA CSF
  • NESA

Next step

Ready to scope NIST CSF consultancy and central bank compliance?

Use the contact or requirement form to tell AxpertCyber the standards, regions, and stakeholders involved, and the right engagement model can be proposed.