92 controls - BM 1194
| Ref | Requirement | Evidence Collected | Score | Priority |
|---|
56 controls - BM 1185
| Ref | Requirement | Evidence Collected | Score | Priority |
|---|
Before using this tool, please read and accept the following notices required under the laws of the Sultanate of Oman.
This tool is for self-assessment guidance only. It does not constitute regulatory advice, legal opinion, or a guarantee of CBO compliance. All results must be validated by a qualified compliance professional before submission to or reliance upon by the Central Bank of Oman.
This is an independent open-source tool. It is not affiliated with, endorsed by, approved by, or connected to the Central Bank of Oman (CBO) or any government authority of the Sultanate of Oman in any way.
This tool stores all assessment data locally in your browser only using localStorage. No data is transmitted to any server, third party, or external system. Your assessment data never leaves your device.
Regulatory framework requirements referenced in this tool are sourced from CBO publications BM 1194 and BM 1185. All regulatory content remains the intellectual property of the Central Bank of Oman. This tool is an independent interpretation for self-assessment purposes only.
Effective date: 1 January 2026 · Sultanate of Oman
By using this tool you agree to these Terms of Use in full. If you do not agree, do not use this tool.
The CBO Gap Evaluator is an independent open-source self-assessment tool. It is designed to help organisations understand their readiness against CBO regulatory frameworks. It does not constitute legal advice, regulatory advice, audit opinion, or a certification of compliance.
This tool has no affiliation with, is not endorsed by, and is not approved by the Central Bank of Oman, the Government of the Sultanate of Oman, or any regulatory authority. Use of CBO framework references is for educational and self-assessment purposes only.
To the fullest extent permitted by Omani law, Dawood Al Nasseri shall not be liable for any direct, indirect, incidental, or consequential loss arising from use of or reliance upon this tool, including but not limited to regulatory penalties, audit findings, or business losses.
This tool is provided "as is" without warranty of any kind. The author makes no warranty that the tool is complete, accurate, current, or fit for any particular regulatory purpose.
This tool is © 2026 Dawood Al Nasseri. It is released as open-source with attribution required. CBO framework content remains the intellectual property of the Central Bank of Oman.
These Terms are governed by the laws of the Sultanate of Oman. Any disputes shall be subject to the exclusive jurisdiction of the courts of the Sultanate of Oman.
Dawood Al Nasseri · +968 79260013 · dawood.nasseri@outlook.com
Effective date: 1 January 2026 · Compliant with Oman PDPL (Royal Decree 6/2022)
Dawood Al Nasseri, Sultanate of Oman. Contact: +968 79260013 · dawood.nasseri@outlook.com
This tool collects no personal data on any server. All data you enter (organisation name, assessor name, scores, evidence notes) is stored exclusively in your browser's localStorage on your own device.
When you export an Excel report, the file is generated entirely in your browser and saved directly to your device. No copy is sent to any server.
This tool loads fonts from Google Fonts and the SheetJS library from cdnjs.cloudflare.com. These are standard CDN requests and do not transmit your assessment data.
For privacy queries: Dawood Al Nasseri · +968 79260013 · dawood.nasseri@outlook.com
Sultanate of Oman - Central Bank of Oman Regulatory Frameworks
The 92 controls and 6 domain structure in the BM 1194 tab are sourced from the Central Bank of Oman's Cyber Security and Resilience Framework (BM 1194). All regulatory requirements, domain definitions, and control references remain the intellectual property of the Central Bank of Oman.
The 56 controls and 10 domain structure in the BM 1185 tab are sourced from the Central Bank of Oman's Cloud Services Assessment Framework (BM 1185). All regulatory requirements, domain definitions, and control references remain the intellectual property of the Central Bank of Oman.
The self-assessment interface, scoring engine, dashboard, grading system, and Excel export are original work by Dawood Al Nasseri and are released as open-source software under a permissive licence requiring attribution.
Any redistribution or publication of this tool must retain the following attribution: "CBO Gap Evaluator - Original tool by Dawood Al Nasseri (+968 79260013 · dawood.nasseri@outlook.com). Framework content sourced from Central Bank of Oman publications BM 1194 and BM 1185."
This guide explains how to complete a full self-assessment against CBO frameworks BM 1194 (Cyber Security & Resilience) and BM 1185 (Cloud Services Assessment), from setup to the final Excel report. All data stays in your browser only - nothing is sent to any server.
On first use, read and accept the legal notice, then enter your organisation name, institution type, assessor name, and assessment year. You can reopen this setup at any time by clicking the logo in the top-left corner.
Use the two tabs in the top bar to switch between BM 1194 (92 controls, 6 domains) and BM 1185 (56 controls, 10 domains). Your scores in each framework are kept separately.
The sidebar on the left lists every domain with a live readiness percentage. Click a domain to show only its controls, or choose "All" from the Domain filter to see everything. You can also filter by status or priority.
For every control, pick a score from the dropdown in the Score column. BM 1194 uses a 0-3 compliance scale; BM 1185 uses a 0-4 maturity scale (see the tables below). Choose N/A only when a control genuinely does not apply to your organisation.
In the Evidence field, note the documents or proof supporting your score (e.g. policy name, audit report, screenshot reference). Set a priority (High / Medium / Low) for controls that need remediation - this drives the Gaps & Actions sheet in the export.
Click Save to store your work in the browser. Click Export Excel to download a three-sheet report: Dashboard (grade and summary), Controls Detail (every control with scores and evidence), and Gaps & Actions (only the controls below full compliance, with recommended actions).
| Score | Meaning |
|---|---|
| 3 | Fully Compliant - control implemented and evidenced |
| 2 | Largely Compliant - minor gaps remain |
| 1 | Partially Compliant - significant work required |
| 0 | Non-Compliant - control not implemented |
| N/A | Not applicable to your organisation |
| Score | Meaning |
|---|---|
| 4 | Optimized - continuously improved and measured |
| 3 | Defined - documented and consistently applied |
| 2 | Developing - in progress, not yet consistent |
| 1 | Initial - ad-hoc or informal |
| 0 | Non-existent - no capability in place |
| N/A | Not applicable to your organisation |
يشرح هذا الدليل كيفية إجراء تقييم ذاتي كامل وفق إطاري البنك المركزي العماني BM 1194 (الأمن السيبراني والمرونة) وBM 1185 (تقييم الخدمات السحابية)، بدءاً من الإعداد وحتى تقرير إكسل النهائي. جميع البيانات تبقى في متصفحك فقط - لا يتم إرسال أي شيء إلى أي خادم.
عند الاستخدام الأول، اقرأ الإشعار القانوني واقبله، ثم أدخل اسم المؤسسة ونوعها واسم المقيّم وسنة التقييم. يمكنك إعادة فتح شاشة الإعداد في أي وقت بالنقر على الشعار في أعلى الصفحة.
استخدم التبويبين في الشريط العلوي للتنقل بين BM 1194 (92 ضابطاً في 6 مجالات) وBM 1185 (56 ضابطاً في 10 مجالات). تُحفظ نتائج كل إطار بشكل منفصل.
تعرض القائمة الجانبية جميع المجالات مع نسبة الجاهزية لكل مجال بشكل مباشر. انقر على أي مجال لعرض ضوابطه فقط، أو اختر "الكل" من فلتر المجال لعرض جميع الضوابط. يمكنك أيضاً التصفية حسب الحالة أو الأولوية.
لكل ضابط، اختر درجة من القائمة المنسدلة في عمود الدرجة. يستخدم إطار BM 1194 مقياس امتثال من 0 إلى 3، بينما يستخدم إطار BM 1185 مقياس نضج من 0 إلى 4 (انظر الجدولين أدناه). اختر "لا ينطبق" فقط عندما لا ينطبق الضابط فعلياً على مؤسستك.
في حقل الأدلة، دوّن المستندات أو الإثباتات الداعمة للدرجة (مثل اسم السياسة أو تقرير التدقيق أو مرجع لقطة الشاشة). حدّد الأولوية (عالية / متوسطة / منخفضة) للضوابط التي تحتاج إلى معالجة - وهذا ما يُبنى عليه جدول الفجوات والإجراءات في التقرير المصدَّر.
انقر على "حفظ" لتخزين عملك في المتصفح. انقر على "تصدير إكسل" لتنزيل تقرير من ثلاث أوراق: لوحة المعلومات (التقدير والملخص)، وتفاصيل الضوابط (جميع الضوابط مع الدرجات والأدلة)، والفجوات والإجراءات (الضوابط غير المكتملة فقط مع الإجراءات الموصى بها).
| الدرجة | المعنى |
|---|---|
| 3 | ممتثل بالكامل - الضابط مطبّق وموثّق بالأدلة |
| 2 | ممتثل إلى حد كبير - فجوات بسيطة متبقية |
| 1 | ممتثل جزئياً - يتطلب عملاً كبيراً |
| 0 | غير ممتثل - الضابط غير مطبّق |
| N/A | لا ينطبق على مؤسستك |
| الدرجة | المعنى |
|---|---|
| 4 | مُحسَّن - يخضع للتحسين والقياس المستمر |
| 3 | مُعرَّف - موثّق ومطبّق باتساق |
| 2 | قيد التطوير - جارٍ العمل عليه وغير متسق بعد |
| 1 | أولي - غير رسمي أو حسب الحاجة |
| 0 | غير موجود - لا توجد قدرة قائمة |
| N/A | لا ينطبق على مؤسستك |
Open-source self-assessment tool for Central Bank of Oman regulatory frameworks.
BM 1194 - Cyber Security & Resilience | BM 1185 - Cloud Services Assessment
© 2026 Dawood Al Nasseri · +968 79260013 · dawood.nasseri@outlook.com · Open-source with attribution · Skip setup
⚠ Disclaimer: This tool is for self-assessment guidance only. Not affiliated with or endorsed by the Central Bank of Oman. Results must be validated by a qualified compliance professional.
| Ref | Requirement | Evidence Collected | Score | Priority |
|---|
| Ref | Requirement | Evidence Collected | Score | Priority |
|---|