شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Regulatory compliance

Compliance guides

What Saudi Arabia’s main cybersecurity and data protection regulations require, of whom and how to prepare, based on the regulators’ own documents.

  • NCA ECC-2:2024

    Essential Cybersecurity Controls (ECC-2:2024)

    The Essential Cybersecurity Controls (ECC) are the minimum cybersecurity requirements the National Cybersecurity Authority (NCA) sets for government entities and for private organisations that own, operate or host critical national infrastructure. This guide is for security and compliance leads who need to understand their scope, structure and how to prepare.

  • SAMA CSF

    SAMA Cyber Security Framework (CSF)

    The Cyber Security Framework (SAMA CSF) sets the cybersecurity controls and the maturity level the Saudi Central Bank expects of the financial institutions it regulates. This guide is for CISOs and compliance teams in banks, finance companies and payment firms.

  • PDPL

    Personal Data Protection Law (PDPL)

    The Personal Data Protection Law (PDPL) governs how personal data about individuals in the Kingdom is collected, processed, disclosed and transferred, and its application is supervised by the Saudi Data and AI Authority (SDAIA). This guide summarises its scope and key obligations for organisations that process personal data as controllers.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.