Help

Questions, answered

How we work, the frameworks we cover, how your information is protected, and how the portal works — in plain words.

Engagements and pricing 4

How does an engagement with CISO Consulting start?

It starts with a short, confidential conversation. We sign a non-disclosure agreement before any information is exchanged, then send a tailored scoping questionnaire. From your answers we prepare a fixed-scope proposal with phases, deliverables, timeline and price.

You can also build an indicative scope yourself on the scope builder and send it with your enquiry.

Was this helpful?
How long does a typical engagement take?

It depends on the framework and your starting point. As a guide, a first maturity assessment takes 6–12 weeks, and a remediation program typically runs 3–9 months. Each framework page shows the typical duration of a first engagement.

Was this helpful?
How do you price your services?

Most engagements are priced as a fixed scope, so you know the cost before work begins. Ongoing services, such as a virtual CISO, are priced as a monthly retainer. Every proposal lists its phases, deliverables and payment milestones, and prices are in Saudi riyals including VAT where it applies.

Was this helpful?
Can you work on site, or only remotely?

Both. Discovery workshops, interviews and evidence reviews are often on site in Riyadh and across the Kingdom; analysis and documentation are done remotely. Where your policies require it, all work with sensitive evidence stays inside your environment.

Was this helpful?

Frameworks and regulators 3

Which frameworks and regulations do you cover?

We cover Saudi regulation — SAMA Cyber Security Framework, NCA Essential Cybersecurity Controls, the Personal Data Protection Law, SAMA Business Continuity Management and NCA Cloud Cybersecurity Controls — and international standards such as ISO/IEC 27001, PCI DSS, NIST CSF and SWIFT CSCF. See each one on the frameworks page.

Was this helpful?
Which framework applies to my organization?

It depends on your sector and the regulator that supervises you. Banks and other SAMA-regulated institutions follow the SAMA Cyber Security Framework; government entities and critical national infrastructure follow NCA's controls; any organization processing personal data in the Kingdom is subject to the Personal Data Protection Law. The scope builder helps you see which apply.

Was this helpful?
Do you help us prepare for a regulator's review or audit?

Yes. We assess you against the regulator's own criteria, close gaps ahead of the review, and prepare an evidence pack organized control by control, so your team can answer reviewers' questions with confidence.

Was this helpful?

Confidentiality and data 3

How do you protect our confidential information?

A non-disclosure agreement is signed before anything is shared. Documents are exchanged only through our secure client portal, never by personal e-mail, and every action is logged. Access is limited to the people working on your engagement, and we keep your data only as long as the engagement and the law require.

Was this helpful?
Where is our data stored?

Your data is stored and processed in line with the Personal Data Protection Law and your regulator's requirements. The details of hosting, encryption and retention are on our Trust Center, and we confirm them in writing in your agreement.

Was this helpful?
Do you sign our NDA, or do we sign yours?

Either. We provide a standard mutual NDA that you can sign online in minutes; if your organization requires its own, send it to us and our team reviews it.

Was this helpful?

The client portal 3

What can we do in the client portal?

Everything about your engagement in one place: sign agreements, answer questionnaires online or in Excel, exchange documents securely, follow project progress and findings, approve proposals, and view and pay invoices. You can add colleagues and decide what each one can see.

Was this helpful?
How do we get access to the portal?

We send an invitation to your contact person. They open the link, confirm a one-time code sent to their e-mail and choose a password. From there they can invite colleagues. Sign-in is protected with two-step verification.

Was this helpful?
Can we answer the questionnaire in Excel instead of online?

Yes. Every questionnaire comes with an Excel workbook in your language. Fill it in and reply to the e-mail, or upload it in the portal; we check every answer and tell you exactly what, if anything, needs fixing.

Was this helpful?

Partners and experts 2

How can my company become a partner?

Apply on the partners page. After a short review we send a non-disclosure agreement; once it is signed, your partner portal opens for the partner agreement, opportunities and payments.

Was this helpful?
I am an independent expert. Can I work with you?

Yes. Apply on the experts page with your experience and certifications. If your profile fits our engagements, we contact you, sign an NDA and agree the terms of each assignment.

Was this helpful?
Trust

Built around the regulators you answer to

SAMA
Saudi Central BankCSF · BCM
NCA
National Cybersecurity AuthorityECC · CCC · CRFR
SDAIA
Data & AI AuthorityPDPL
SWIFT
Customer Security ProgrammeCSCF
7regulatory frameworks

Ready to talk about your compliance?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Regulatory updates in your inbox

SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.

We confirm by e-mail; unsubscribe any time.

Schedule a Free Assessment