Skip to content
AuditGRC

GCC regulatory frameworks

The frameworks that actually drive GRC, risk and audit software decisions in the region. Each hub covers the structure, who is in scope, how compliance is assessed, and what that means for tooling — with the source we verified it against stated on the page.

Frameworks covered

NCA ECC

Saudi Arabia National Cybersecurity Authority

Saudi Arabia's minimum national cybersecurity requirements. Four domains, 28 subdomains, 108 controls.

5 linked resources

SAMA CSF

Saudi Arabia Saudi Arabian Monetary Authority

The Saudi financial sector framework. Four domains, 32 subdomains, assessed on a six-level maturity model.

4 linked resources

NCEMA 7000

United Arab Emirates National Emergency Crisis and Disaster Management Authority

The UAE's national business continuity standard. Follows ISO 22301's clause structure, with material divergences.

3 linked resources

PDPPL

Qatar National Cyber Governance and Assurance Affairs

Qatar's personal data protection law. Controller obligations, consent rules, and a 72-hour breach notification deadline.

3 linked resources

Not yet covered — and why

We publish a framework hub once we can verify its structure against the issuing body's own document. These are on the list but not yet published, because repeating figures we cannot stand behind is exactly the failure mode this site exists to correct.

  • NESA / UAE Information Assurance Standard (Signals Intelligence Agency (formerly NESA), United Arab Emirates) — Published secondary sources give contradictory domain counts, and the standard has moved to IAS v2.x under a renamed authority. We will publish once we can verify the structure against the primary document rather than repeat figures we cannot stand behind.
  • Dubai ISR (Information Security Regulation) (Dubai Electronic Security Center, United Arab Emirates) — Structure not yet verified against the published regulation.
  • ADHICS (Department of Health, Abu Dhabi, United Arab Emirates) — Structure not yet verified against the published standard.

If you have access to a current primary document for any of these and want it covered, tell us at hello@auditgrc.com.