العربية
Under attack? Get help nowActive incidents only
Talk to us

Ready before the auditor knocks.

For banks, payment companies and licence applicants. We find the gaps against the CBI Cyber Resilience Controls, ISO 27001 and PCI DSS, close them with you, and build the evidence your auditor will ask for.

Request a confidential consultationA named practice lead replies.
  1. Reform standards
  2. Audit cycle 1
  3. Technical audit cycle
  4. Final validation

The Central Bank has set the sequence. Reform standards, two audit cycles and a final validation follow, in that order. We prepare you for the technical audit cycle.

Which institutions the timeline applies to depends on your pathway and licence — ask us, or see Payment companies and wallets.

Dates to be confirmed against the CBI circular Last reviewed 28 September 2026

See what the audit will ask for

The frameworks we prepare you for

  1. CBI Cyber Resilience Controls

    The Central Bank wrote the checklist. We work through it with you.

    Request a confidential consultation

  2. Banking-reform technical audit

    The technical audit cycle is coming. We prepare you for it.

  3. ISO/IEC 27001

    ISO 27001, implemented in Baghdad, ready for the certification body you choose.

    Request a confidential consultation

  4. PCI DSS

    PCI DSS readiness for payment companies and merchants that accept cards.

    Request a confidential consultation

We prepare you for:
  • CBI Cyber Resilience Controls
  • ISO/IEC 27001
  • PCI DSS
  • SWIFT CSP
  • NIST CSF
  • COBIT 2019

Who signs what

What DigiFort signs

  • Gap register
  • Readiness scorecard
  • Remediation plan
  • Evidence pack
  • Mock-audit report

What a CBI-approved third party or QSA signs

  • Third-party assurance under the Booklet
  • The Report on Compliance (RoC)

We are your readiness partner ahead of the CBI-approved auditor. The firm that prepares your evidence does not sign assurance on it — that separation is yours to keep and ours to respect.

Our method

  1. IdentifyScope, gap register and readiness scorecard
  2. ProtectRemediation plan, with an owner and a date for each item
  3. DetectTest findings and a review of logging and monitoring
  4. RespondIncident-response plan, playbooks and a tabletop exercise
  5. EvidenceEvidence pack and mock-audit report

Banks: how a confidential engagement runs

Supplier registration with your procurement is usually the first step; then request the pre-qualification pack.

  1. Supplier registration
  2. NDA (yours; ours on request once available)
  3. Scoping
  4. Proposal in your tender format
  5. Gap register
  6. Remediation
  7. Evidence pack

Payment companies and applicants

A fixed-scope readiness assessment. You receive:

  • Licence-checklist mapping
  • Penetration-test scope
  • Policy-set gap
  • Incident-response-plan gap
  • Remediation plan

Fixed scope; the quote follows the scoping call.

Boundaries

This is not a certification audit and not a PCI DSS assessment; a certification body and a QSA do those parts.

FAQ

Where is our data handled?

Agreed with you in writing before the engagement starts: where each deliverable is stored, in which region, who can open it, and how it is handed back or deleted when we finish.

Can you also sign the assurance?

No; a CBI-approved firm signs assurance, and we prepare you for it.