The frameworks we help you meet

Saudi and international cybersecurity, privacy and resilience requirements — what each one asks of you, and how we get you there.

Frameworks
10
Issuing bodies
7
Mandatory for regulated entities
8
In our readiness check
3

Saudi regulation6

SAMACybersecurity SAMA CSF SAMA Cyber Security Framework SAMA’s Cyber Security Framework for the institutions it regulates, assessed on a maturity scale. Leadership and governanceRisk management and complianceOperations and technology+1 more Mandatory 8–12 weeks NCACybersecurity NCA ECC-2:2024 NCA Essential Cybersecurity Controls The Essential Cybersecurity Controls — the baseline the National Cybersecurity Authority sets for national entities. Cybersecurity governanceCybersecurity defenseCybersecurity resilience+1 more Mandatory 6–10 weeks SDAIAData privacy PDPL Personal Data Protection Law The Personal Data Protection Law and its regulations, overseen by SDAIA. Lawful basis and consentData-subject rightsSecurity and breach notification+1 more Mandatory 6–8 weeks SAMABusiness continuity SAMA BCM SAMA Business Continuity Management Framework SAMA’s Business Continuity Management framework for keeping critical services running through disruption. Governance and policyBusiness impact analysisContinuity and recovery plans+1 more Mandatory 8–12 weeks SAMABusiness continuity SAMA CRFR Cyber Resilience Fundamental Requirements SAMA's fundamental requirements for cyber resilience: the baseline capabilities regulated institutions are expected to have in place to withstand, respond to and recover from cyber incidents. Cyber resilience governance and oversightIdentification of critical services and assetsProtection and detection capabilities+2 more Mandatory 6–10 weeks for the assessment NCACloud security NCA CCC NCA Cloud Cybersecurity Controls The Cloud Cybersecurity Controls — NCA’s requirements for cloud service providers and the organizations that use them. GovernanceDefenseResilience+1 more Mandatory 4–8 weeks

International standard2

Industry scheme2

Trust

Built around the regulators you answer to

SAMA
Saudi Central BankCSF · BCM
NCA
National Cybersecurity AuthorityECC · CCC · CRFR
SDAIA
Data & AI AuthorityPDPL
SWIFT
Customer Security ProgrammeCSCF
7regulatory frameworks
Readiness self-check

How ready are you? Find out in two minutes

Answer a few questions for your framework. You get a score, your biggest gaps and — if you want it — a detailed assessment from our team.

Ready to talk about your compliance?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Regulatory updates in your inbox

SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.

We confirm by e-mail; unsubscribe any time.

Schedule a Free Assessment