HKMA Cyber Resilience Assessment Framework (C-RAF)
What is HKMA Cyber Resilience Assessment Framework (C-RAF)?
HKMA Cyber Resilience Assessment Framework (C-RAF) is the Hong Kong Monetary Authority (HKMA) MANDATORY cybersecurity assessment + supervisory framework for all Authorised Institutions (AIs) in Hong Kong + part of the broader HKMA CYBERSECURITY FORTIFICATION INITIATIVE (CFI) launched 2016. KEY HISTORY: (a) CFI announced May 2016; (b) C-RAF v1.0 issued December 2016; (c) C-RAF v2.0 issued 6 May 2020 (Circular 20200506e1a1) - major revision incorporating lessons learned + international best practice + iCAST framework; (d) ongoing 2024-2025 enhancements + supervisory communications + threat-landscape evolution. It comprises 11 controls organised across 7 domains, and applies in Hong Kong.
How HKMA Cyber Resilience Assessment Framework (C-RAF) maps to other frameworks
All 11 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 7 domains HKMA Cyber Resilience Assessment Framework (C-RAF) groups its controls into
Where HKMA Cyber Resilience Assessment Framework (C-RAF) overlaps with the standards you already hold
What HKMA Cyber Resilience Assessment Framework (C-RAF) means in your sector
What HKMA Cyber Resilience Assessment Framework (C-RAF) means for your job
Questions people ask about HKMA Cyber Resilience Assessment Framework (C-RAF)
What is HKMA Cyber Resilience Assessment Framework?
How many controls does HKMA Cyber Resilience Assessment Framework have?
Where does HKMA Cyber Resilience Assessment Framework apply?
What frameworks does HKMA Cyber Resilience Assessment Framework map to?
How do I get started with HKMA Cyber Resilience Assessment Framework compliance?
Query HKMA Cyber Resilience Assessment Framework (C-RAF) programmatically
HKMA Cyber Resilience Assessment Framework (C-RAF), its 11 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
HKMA Cyber Resilience Assessment Framework (C-RAF) API reference and MCP config →What HKMA Cyber Resilience Assessment Framework (C-RAF) requires, control by control
Each page carries the requirement text for one HKMA Cyber Resilience Assessment Framework (C-RAF) control and what an assessor expects to see as evidence.
- HKMA-CRAF-DOMAIN1-2-GOVERNANCE-IDENTIFICATION HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment
- HKMA-CRAF-DOMAIN3-4-PROTECTION-DETECTION HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel
- HKMA-CRAF-DOMAIN5-6-RESPONSE-RECOVERY-SITAWARENESS HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing
How ready are you for HKMA Cyber Resilience Assessment Framework (C-RAF)?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.