The challenge
The NCA Essential Cybersecurity Controls (ECC) devote a whole domain to third-party and cloud cybersecurity, and the SAMA Cyber Security Framework (CSF) requires vendors to be assessed before contracting and throughout the relationship. The Personal Data Protection Law (PDPL) makes you accountable for what processors do on your behalf.
In practice these requirements are handled in scattered spreadsheets and emailed questionnaires that get lost between departments. Nobody knows how many vendors reach your data, when each was last assessed, or where the compliance evidence is when the auditor asks.
A single GRC platform links controls to risks to evidence to vendors, so management gets one picture and the auditor gets a traceable record.
How we work
- 1
Programme design
We tier vendors by criticality and access type (data, systems, sites), and define questionnaires, contractual controls and assessment cycle per tier.
- 2
Platform configuration
We configure the GRC platform with ECC, CSCC, CCC, SAMA CSF, PDPL and ISO 27001, link controls to risks and policies, and import the vendor register and existing evidence.
- 3
Operate and monitor
We run the vendor assessment cycle, track remediation plans and publish management dashboards, with periodic programme reviews.
What is included
Vendor tiering
A tiering methodology based on business impact and access to personal data and critical systems.
Pre-contract due diligence
Control-mapped questionnaires, review of certificates and reports, and external security posture assessment of the vendor.
Contractual controls
Ready-to-use cybersecurity and data protection clauses for contracts and PDPL data processing agreements.
Continuous monitoring
Tracking of posture changes at critical vendors, periodic reassessment and monitoring of their disclosed incidents.
Control and evidence management
A unified control register across frameworks, with evidence, review dates and owners, audit-ready at any time.
Risk and policy management
A risk register, treatment and acceptance workflows, and policy publication with acknowledgement tracking.
Dashboards and reporting
Dashboards for management and the risk committee showing compliance status, overdue vendors and open risks.
Frameworks and regulations
We align the service with the frameworks your organisation is subject to.
- NCA ECC
- SAMA CSF
- PDPL
- ISO 27001
- NIST CSF
Frequently asked questions
Which GRC platform do you use?
We work with established market platforms and with one you may already own. The choice depends on organisation size, applicable frameworks and budget, and we help you compare.
Is the programme run by our team or yours?
Both are available: we build the programme and hand it to your team with training, or run it on your behalf as a managed service.
What about vendors who refuse to be assessed?
The programme sets a minimum per tier. A refusal is recorded as a risk escalated to management for an acceptance or alternative decision.
Is the platform hosted inside the Kingdom?
We prefer in-Kingdom or on-premises hosting to meet data residency requirements, and set out each platform's options before selection.
What affects the cost and effort of a third-party risk programme?
The number of vendors and how they split across criticality tiers, and how deeply each tier is assessed, from a questionnaire to evidence review or an on-site visit. The number of frameworks configured on the platform, the platform's licensing and hosting option, and whether we run the programme for you or hand it to your team also matter. We set this out in a written proposal after reviewing your vendor list.
Which Saudi regulations require third-party risk management?
The NCA Essential Cybersecurity Controls (ECC) require cybersecurity clauses in third-party contracts, including confidentiality, secure deletion of your data at the end of the service and incident communication procedures, and, for outsourcing and managed services, a cybersecurity risk assessment before signing. The SAMA Cyber Security Framework (CSF) expects the financial institutions it regulates to address cyber security requirements before contract signing and to monitor compliance throughout the contract. Under the Personal Data Protection Law (PDPL), a controller must choose processors that provide the necessary guarantees and verify their compliance, without losing its own responsibility.
What do you need from us to get started?
Your current vendor list with contract owners, and an indication of which vendors reach personal data, critical systems or your premises. Existing questionnaires, contract templates and policies help us reuse what already works, and we need to know which frameworks apply to you. A sponsor in procurement or risk keeps decisions moving.
Related services
Govern & comply
GRC advisory
Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.
Govern & comply
Compliance assessment
Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.
Assess & test
Cloud security assessment
Review of cloud configuration, identity and data against recommended practice.
Solutions & infrastructure
Data security
Data classification, loss prevention and encryption aligned with PDPL.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

