The challenge
Organisations in the Kingdom answer to several regulators at once: the National Cybersecurity Authority (NCA) with its Essential (ECC) and Critical Systems (CSCC) controls, the Saudi Central Bank (SAMA) with its Cyber Security Framework (CSF), SDAIA and the National Data Management Office (NDMO) with the Personal Data Protection Law (PDPL), the Communications, Space and Technology Commission (CST) with its Cybersecurity Regulatory Framework (CRF), and the Capital Market Authority (CMA) with its rules for licensed entities.
Many policies are written to be signed and then forgotten. At audit it turns out the policy exists but the procedure does not, or risks are logged but nobody owns them. Real governance means defined roles, documented decisions and regular measurement.
We design one framework that meets all these regulators without duplication, and support you in operating it until it is part of how management works rather than a burden on it.
How we work
- 1
Understand and map requirements
We identify the regulators that apply to you, build a unified requirements matrix from ECC, CSCC, CCC, SAMA CSF, PDPL, CST CRF and ISO 27001, and assess the current state.
- 2
Design and document
We write the strategy, policies, procedures and standards in your teams' language, define roles and responsibilities, and build the risk methodology and register.
- 3
Operate and measure
We support approval of the documents, training of stakeholders, launch of governance committees, and definition of KPIs and periodic reporting to senior management.
What is included
Cybersecurity strategy
A multi-year strategy tied to business objectives and NCA requirements, with a roadmap and indicators.
Policies and procedures
A complete document set mapped to ECC, SAMA CSF and ISO 27001 controls, in Arabic and English where needed.
Cyber risk management
An assessment methodology, a risk register with named owners, treatment plans and a management-approved risk appetite.
Personal data protection
Records of processing, privacy impact assessments, privacy notices and data subject request procedures under PDPL and SDAIA regulations.
Sector-specific compliance
SAMA requirements for banks and insurers, CMA rules for capital market licensees, and CST requirements for telecom and technology providers.
ISO management systems
Building an information security management system (ISO 27001) and business continuity system (ISO 22301) and preparing for external audit.
vCISO
A part-time cybersecurity leader who runs the programme and represents it before management and regulators.
Audit support
Evidence preparation, responses to auditor and regulator queries, and tracking of observations to closure.
Frameworks and regulations
We align the service with the frameworks your organisation is subject to.
- NCA ECC
- NCA CSCC
- SAMA CSF
- PDPL
- CST CRF
- ISO 27001
Frequently asked questions
Do you serve government entities?
Yes. GRC, assessment and solutions services are available to government entities. Managed SOC services follow the Tier 2 licence scope and are not offered to government entities or critical national infrastructure.
Are the documents templates or custom?
We start from a control-mapped document library, then adapt it to your structure, systems and terminology, and review it with stakeholders before approval.
How do you handle overlap between regulators?
We build a unified matrix linking each control to every regulator's requirement, so a control is implemented once and cited to each.
Does this include obtaining ISO certification?
We build the system and prepare you for audit. The certificate is issued by an independent certification body based on its own audit; no consultant can guarantee it.
Can a vCISO fill our head of cybersecurity role?
Not if you are within ECC scope. Control 1-2-2 of ECC-2:2024 requires all cybersecurity positions to be filled by full-time, qualified Saudi professionals, so a part-time adviser cannot hold the position itself. A vCISO can support and mentor your appointed head of cybersecurity, run the programme alongside them and help build the internal team. Organisations outside ECC scope have more flexibility, subject to their own regulator's requirements.
What do you need from us to get started?
A senior management sponsor who approves documents and backs the programme, a coordinator on your side, and access to existing policies, the organisation chart and previous audit or assessment reports. We also need the list of licences you hold and the regulators you answer to, and time with the owners of key processes such as IT, HR, legal and procurement.
What affects the effort of a GRC engagement?
The number of regulators and frameworks that apply, the size and structure of the organisation (subsidiaries, business units, locations), and how much usable documentation already exists. Approval cycles, the number of stakeholders to interview and train, and whether you want ongoing support such as a vCISO after the documents are approved also shape the effort. We scope these with you before proposing.
Related services
Govern & comply
Compliance assessment
Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.
Govern & comply
Third-party risk & GRC platform
Vendor assessment and compliance management on a single platform.
Govern & comply
Awareness & training
Awareness programmes and phishing simulations with measurable results.
Solutions & infrastructure
Data security
Data classification, loss prevention and encryption aligned with PDPL.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

