Compliance Assessment Services
A compliance assessment is not a box-ticking exercise. Done properly, it is an accurate measurement of your organization's security posture against a specific regulatory or standards framework — and a roadmap for closing the gaps that matter most.
CISO Consulting delivers structured, evidence-based compliance assessments aligned to every major framework applicable to Saudi organizations. Our assessments are conducted by practitioners who have assessed dozens of Saudi financial institutions, government entities, and private sector organizations — not junior analysts working from a checklist.
Assessment Frameworks We Cover
SAMA Cyber Security Framework (CSF)
Mandatory for all Saudi Central Bank-regulated financial institutions — banks, insurance companies, payment providers, and fintech platforms. Our SAMA CSF assessment maps your controls across all four domains: Cybersecurity Leadership, Cybersecurity Risk Management, Cybersecurity Operations, and Third-Party Cybersecurity. We produce a scored self-assessment report in the format SAMA expects, along with a prioritized remediation plan.
NCA Essential Cybersecurity Controls (ECC-2:2024)
Updated in October 2024, ECC-2 covers 108 controls across four domains: Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience, and Third-Party & Cloud Security. The December 2024 NCA Regulations now give the NCA enforcement authority — with fines up to SAR 25 million for non-compliance. Our ECC-2 assessment uses the official NCA toolkit methodology and produces a compliance score by domain, a control-level gap analysis, and a 90-day remediation roadmap.
Personal Data Protection Law (PDPL)
Saudi Arabia's PDPL is now fully enforced. Our PDPL readiness assessment covers data inventory and mapping, lawful basis for processing, consent management, data subject rights procedures, breach notification processes, and data protection by design. We assess against the full regulation and its implementing regulations — not a simplified checklist.
ISO 27001:2022
For organizations seeking formal certification, our ISO 27001 gap assessment measures your Information Security Management System (ISMS) against all Annex A controls and the mandatory clauses of the standard. We identify your readiness for certification and build a realistic implementation plan.
PCI DSS v4.0
For organizations that process, store, or transmit payment card data. Our PCI DSS assessment covers all 12 requirements and produces a Report on Compliance (RoC) equivalent gap analysis, Compensating Controls guidance, and a scoping review to minimize your cardholder data environment.
NIST Cybersecurity Framework (CSF 2.0)
A maturity-based assessment across the six NIST CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, and Recover. Often used as the foundation for a broader security program review alongside Saudi-specific regulatory requirements.
Our Assessment Methodology
- Scoping: Define the assessment boundary, applicable systems, and business units
- Evidence collection: Document review, staff interviews, technical configuration reviews
- Control testing: Validate that documented controls are actually implemented and effective
- Gap scoring: Rate each control as Compliant, Partially Compliant, or Non-Compliant with evidence
- Risk prioritization: Rank gaps by regulatory exposure, exploitability, and remediation effort
- Reporting: Executive summary for the board, detailed technical report for the security team, and a remediation roadmap with ownership assignments
What You Receive
- Scored compliance assessment report (executive + technical)
- Control-level gap register with evidence references
- Prioritized remediation roadmap (30 / 60 / 90 day)
- Board-ready compliance posture summary
- Re-assessment after remediation (included in annual programs)
Ongoing vs. Point-in-Time
Regulatory requirements do not stand still. Our annual compliance program includes an initial assessment, two interim reviews, and a final pre-audit assessment — ensuring your compliance posture is current when the auditor arrives, not just when we first visited.