Frameworks

All Saudi regulatory & sector frameworks

Seven frameworks, one platform. Built for NCA · SAMA · PDPL · CBAHI · compliance audits across the Kingdom.

Framework 01

SAMA CSF (Financial)

SAMA-CSF

SAMA Cybersecurity Framework

Compliance · Saudi Central Bank (SAMA)
Framework 02

NCA ECC (Cybersecurity)

NCA-ECC

NCA Essential Cybersecurity Controls

Compliance · National Cybersecurity Authority (NCA)
Framework 03

SDAIA Personal Data Protection Law

SDAIA-PDPL

SDAIA PDPL (نظام حماية البيانات الشخصية)

Compliance · Saudi Data & AI Authority (SDAIA)
Framework 04

SAMA IT Governance Framework

SAMA-IT-GOVERNANCE

SAMA IT Governance Framework (الدليل التنظيمي لحوكمة تقنية المعلومات)

Compliance · Saudi Central Bank (SAMA)
Framework 05

PCI DSS v4.0.1

PCI-DSS-V4.0.1

Payment Card Industry Data Security Standard version 4.0.1. A global security standard designed to protect cardholder data and reduce payment card fraud through technical and operational controls across six domains and twelve core requirements.

Compliance · PCI Security Standards Council
Framework 06

ISO 27001:2022

ISO-27001:2022

ISO/IEC 27001:2022 – Information security, cybersecurity and privacy protection. Specifies the requirements for establishing, implementing, maintaining and continually improving an ISMS. Includes mandatory Clauses 4–10 and 93 Annex A controls across four themes: Organizational (5.1–5.37), People (6.1–6.8), Physical (7.1–7.14), Technological (8.1–8.34).

Compliance · International Organization for Standardization (ISO)
Framework 07

CBAHI National Standards for Ambulatory Care Centers

CBAHI-CLINIC

CBAHI National Standards for Ambulatory Care Centers – First Edition 2019, Effective 1 January 2020. 11 chapters, 133 standards, 594 sub-standards (7 core).

Compliance · Central Board for Accreditation of Healthcare Institutions

How it works

One audit, multiple frameworks.

Upload evidence once. The overlap engine automatically maps your documents across frameworks — NCA ↔ SAMA ↔ PDPL ↔ CBAHI. Satisfy multiple regulatory requirements in a single structured session.