Frameworks & Regulations
Do we cover you? Check in ten seconds.
Filter by region. Global standards show under every region. The badge says whether the framework is in the product today, arrives through a content pack, or is coming with a market launch.
- In product
- Seen in the application's risk catalogue, control mappings or registers.
- Content pack
- Documented for industry packs. Confirm before relying on it.
- Coming
- Planned, with its quarter. Not in the product yet.
Framework coverage by region
11 frameworks
SAMA Cyber Security Framework
Saudi ArabiaIn product
NCA Essential Cybersecurity Controls (ECC-2:2024)
Saudi ArabiaIn product
Personal Data Protection Law (PDPL)
Saudi ArabiaIn product
ISO/IEC 27001
GlobalIn product
NIST CSF
GlobalIn product
PCI-DSS
GlobalIn product
Basel II event types
GlobalContent pack
SOC 2
GlobalContent pack
GDPR
GlobalContent pack
DORA
GlobalContent pack
HIPAA
GlobalContent pack
Four frameworks were loaded in the application we reviewed, with 115 applicable controls and the applicability review complete. The repository's name column does not yet render, so the four are not named here.
Regulators in Saudi Arabia
SAMA
Banks, finance companies and payment service providers
CMA
Capital market institutions and listed companies
IA
Insurers and insurance intermediaries (sole insurance regulator since 2024)
NCA
National Cybersecurity Authority
National cybersecurity controls, including the ECC
SDAIA
Personal Data Protection Law
Don't see yours?
Tell us the regulator or standard and we will confirm whether it is covered, in a pack, or neither.
Scoped to the regulators you actually answer to.
The demo opens on your jurisdiction, with the risk universe pruned to what applies to you.