GCC regulatory frameworks
The frameworks that actually drive GRC, risk and audit software decisions in the region. Each hub covers the structure, who is in scope, how compliance is assessed, and what that means for tooling — with the source we verified it against stated on the page.
Frameworks covered
NCA ECC
Saudi Arabia National Cybersecurity AuthoritySaudi Arabia's minimum national cybersecurity requirements. Four domains, 28 subdomains, 108 controls.
5 linked resources
SAMA CSF
Saudi Arabia Saudi Arabian Monetary AuthorityThe Saudi financial sector framework. Four domains, 32 subdomains, assessed on a six-level maturity model.
4 linked resources
NCEMA 7000
United Arab Emirates National Emergency Crisis and Disaster Management AuthorityThe UAE's national business continuity standard. Follows ISO 22301's clause structure, with material divergences.
3 linked resources
PDPPL
Qatar National Cyber Governance and Assurance AffairsQatar's personal data protection law. Controller obligations, consent rules, and a 72-hour breach notification deadline.
3 linked resources
Not yet covered — and why
We publish a framework hub once we can verify its structure against the issuing body's own document. These are on the list but not yet published, because repeating figures we cannot stand behind is exactly the failure mode this site exists to correct.
- NESA / UAE Information Assurance Standard (Signals Intelligence Agency (formerly NESA), United Arab Emirates) — Published secondary sources give contradictory domain counts, and the standard has moved to IAS v2.x under a renamed authority. We will publish once we can verify the structure against the primary document rather than repeat figures we cannot stand behind.
- Dubai ISR (Information Security Regulation) (Dubai Electronic Security Center, United Arab Emirates) — Structure not yet verified against the published regulation.
- ADHICS (Department of Health, Abu Dhabi, United Arab Emirates) — Structure not yet verified against the published standard.
If you have access to a current primary document for any of these and want it covered, tell us at hello@auditgrc.com.