العربية

Market · State of Qatar

Pass a Qatari audit, and know who is allowed to sign it

Qatar is the one Gulf state where the question every buyer should ask — who is actually allowed to sign this? — has a published answer. That makes scoping simpler and the sequencing stricter.

Certification runs in four phases, and readiness is only the first

Under the National Information Security Compliance Framework, certification moves through scope preparation and documentation, audit planning with an accredited auditor, the compliance audit and controls assessment by that auditor, and finally the certification decision by the NCSA's governance and assurance division.

That sequence is worth internalising, because it determines who you engage and when. Readiness work is phase one. It cannot substitute for phase three, and no amount of it changes who signs.

We are not an NCSA-accredited auditor

The NCSA accredits service providers by category, and firms announce accreditation publicly because it gates the work. We hold none, and we will not bid as though we do. What we do is the readiness half — scope definition, control assessment, evidence and remediation planning — so that when the accredited auditor arrives, the audit is short. If you need the audit itself, we will tell you on the first call and name firms that hold the accreditation.

What binds you

Reference numbers below are taken from the NCSA's own document library. Note that the NCSA and the central bank do not make every document publicly available, so this is a verified sample rather than a complete register.

NCSA

National Information Assurance Standard

NIA v2.1

Confirmed current as of July 2026. Binds government entities, critical information infrastructure operators across energy, water, telecoms, financial services, healthcare and transport, and service providers accessing information assets on behalf of mandated organisations.

Who signsAn NCSA-accredited auditor. Certificate valid three years, with a required annual maintenance audit.
NCSA

NISCF audit standard and certification policy

NCSA-NISCF-AUD-STND-V3.0NCSA-NISCF-CERT-GPNC-V1.0

The component documents that govern how an audit is conducted and how certification is granted. Together with the accreditation scheme, they make Qatar the most legible assurance regime in the Gulf — you can find out in advance exactly what will be done to you and by whom.

Who signsAudit report submitted to the NCSA; the certification decision is the NCSA's.
NCSA

National Data Classification Policy

v3.0

Three risk tiers — low, medium and high — determining the technical and administrative controls required. Mandatory for government entities and institutions, and in practice the first piece of work on any Qatari engagement, because nothing downstream can be scoped until the classification is settled.

Who signsSelf-assessed, but it gates everything else.
MCIT / NCSA

Protecting Personal Data Privacy

Law 13/2016

The first data protection law in the Gulf, effective 2017. Unusually, it has no extraterritorial application and no adequacy or standard-clause mechanism — transfers are permitted unless they breach the law or cause serious damage. Sensitive data covering health, religion, criminal records and children requires prior written permission from MCIT, which is a lead time, not a formality. Enforcement is administrative and non-public.

Who signsNo general audit regime; prior MCIT permission for sensitive categories.
QCB

Artificial Intelligence Guideline for licensed entities

4 September 2024

The most prescriptive AI rule anywhere in the GCC, and binding. Prior QCB approval is required for new or materially modified high-risk AI systems — before deployment, and before signing purchase, licensing or outsourcing agreements. Licensed entities must maintain an AI register covering every system, its risk classification, provider, human-oversight protocol and contract dates; must separate training, validation and testing datasets with bias testing; and must report serious AI incidents.

Who signsQCB itself. The register is disclosable annually on request.
QFC

Data Protection Regulations and Rules

QFC 2021

Administered by the independent QFC Data Protection Office and broadly GDPR-aligned, which makes it a significant upgrade on the 2005 regime and a different proposition from the state-level law. Applies to QFC-licensed firms as controllers and processors; biometric data is treated as special category.

Who signsQFC Data Protection Office.

The AI approval bites at procurement, not at launch

Most firms reading the QCB guideline plan for an approval before go-live. Read it again: approval is required before signing the purchase, licensing or outsourcing agreement. If you are a QCB-licensed entity selecting an AI vendor, the regulatory step sits inside your procurement timeline, not after it — and discovering that during contract negotiation is expensive. This is the single most commonly missed sequencing point in the Gulf.

Before you brief anyone

Four questions worth asking

  • Has our data been classified under the national policy, and at what tier?
  • Which accredited auditor will sign our certification, and are they engaged?
  • If we are QCB-licensed, does any system in procurement meet the high-risk definition?
  • Are we inside the QFC or outside it? The data regime differs materially.

What we could not confirm

  • Whether advisory accreditation is strictly mandatory, as opposed to strongly expected, for government and CNI work.
  • The full list of accreditation categories and their eligibility criteria, including whether a Qatari commercial registration is required.
  • The complete current register of Qatar Central Bank cyber instruments — the document index is not publicly available.

Start with a scoping call

Tell us the entity, your classification tier if you have one, and whether you are inside the QFC. Twenty minutes usually settles who needs to do what.