- Frameworks
- 10
- Issuing bodies
- 7
- Mandatory for regulated entities
- 8
- In our readiness check
- 3
Saudi regulation6
SAMA CSF
SAMA Cyber Security Framework
SAMA’s Cyber Security Framework for the institutions it regulates, assessed on a maturity scale.
Leadership and governanceRisk management and complianceOperations and technology+1 more
Mandatory
8–12 weeks
NCA ECC-2:2024
NCA Essential Cybersecurity Controls
The Essential Cybersecurity Controls — the baseline the National Cybersecurity Authority sets for national entities.
Cybersecurity governanceCybersecurity defenseCybersecurity resilience+1 more
Mandatory
6–10 weeks
PDPL
Personal Data Protection Law
The Personal Data Protection Law and its regulations, overseen by SDAIA.
Lawful basis and consentData-subject rightsSecurity and breach notification+1 more
Mandatory
6–8 weeks
SAMA BCM
SAMA Business Continuity Management Framework
SAMA’s Business Continuity Management framework for keeping critical services running through disruption.
Governance and policyBusiness impact analysisContinuity and recovery plans+1 more
Mandatory
8–12 weeks
SAMA CRFR
Cyber Resilience Fundamental Requirements
SAMA's fundamental requirements for cyber resilience: the baseline capabilities regulated institutions are expected to have in place to withstand, respond to and recover from cyber incidents.
Cyber resilience governance and oversightIdentification of critical services and assetsProtection and detection capabilities+2 more
Mandatory
6–10 weeks for the assessment
NCA CCC
NCA Cloud Cybersecurity Controls
The Cloud Cybersecurity Controls — NCA’s requirements for cloud service providers and the organizations that use them.
GovernanceDefenseResilience+1 more
Mandatory
4–8 weeks
International standard2
ISO/IEC 27001:2022
ISO/IEC 27001 Information Security Management
The international standard for an information security management system (ISMS): how an organization sets, runs, measures and improves its information security, with certification by an accredited body.
Voluntary
NIST CSF 2.0
NIST Cybersecurity Framework
A widely used framework for managing cybersecurity risk, organized around six functions: Govern, Identify, Protect, Detect, Respond and Recover.
Voluntary
Industry scheme2
SWIFT CSCF
SWIFT Customer Security Controls Framework
The Customer Security Controls Framework behind SWIFT’s yearly attestation.
Secure your environmentKnow and limit accessDetect and respond
Mandatory
3–6 weeks
PCI DSS v4.0
Payment Card Industry Data Security Standard
The security standard for any organization that stores, processes or transmits payment card data, maintained by the PCI Security Standards Council.
Mandatory
| Framework | Issued by | Kind | Origin | Status | Typical first engagement | What it covers | Self-check |
|---|---|---|---|---|---|---|---|
| SAMA CSFSAMA Cyber Security Framework | SAMA | Cybersecurity | Saudi regulation | Mandatory | 8–12 weeks | 4 areas | |
| NCA ECC-2:2024NCA Essential Cybersecurity Controls | NCA | Cybersecurity | Saudi regulation | Mandatory | 6–10 weeks | 4 areas | |
| PDPLPersonal Data Protection Law | SDAIA | Data privacy | Saudi regulation | Mandatory | 6–8 weeks | 4 areas | |
| SAMA BCMSAMA Business Continuity Management Framework | SAMA | Business continuity | Saudi regulation | Mandatory | 8–12 weeks | 4 areas | — |
| SAMA CRFRCyber Resilience Fundamental Requirements | SAMA | Business continuity | Saudi regulation | Mandatory | 6–10 weeks for the assessment | 5 areas | — |
| NCA CCCNCA Cloud Cybersecurity Controls | NCA | Cloud security | Saudi regulation | Mandatory | 4–8 weeks | 4 areas | — |
| SWIFT CSCFSWIFT Customer Security Controls Framework | SWIFT | Payments | Industry scheme | Mandatory | 3–6 weeks | 3 areas | — |
| ISO/IEC 27001:2022ISO/IEC 27001 Information Security Management | ISO/IEC | Management systems | International standard | Voluntary | — | — | — |
| PCI DSS v4.0Payment Card Industry Data Security Standard | PCI SSC | Payments | Industry scheme | Mandatory | — | — | — |
| NIST CSF 2.0NIST Cybersecurity Framework | NIST | Cybersecurity | International standard | Voluntary | — | — | — |
No framework matches these filters.
Trust
Built around the regulators you answer to
SAMA
Saudi Central BankCSF · BCM
NCA
National Cybersecurity AuthorityECC · CCC · CRFR
SDAIA
Data & AI AuthorityPDPL
SWIFT
Customer Security ProgrammeCSCF
7regulatory frameworks
Readiness self-check
How ready are you? Find out in two minutes
Answer a few questions for your framework. You get a score, your biggest gaps and — if you want it — a detailed assessment from our team.
Ready to talk about your compliance?
Tell us where you stand. We will show you the shortest path to what your regulator expects.
