العربية

Service · Readiness

Assessed against the instrument that binds you. Not a generic checklist.

Most readiness reports in this region are an ISO 27001 gap analysis with the local acronym changed. That is not what a Gulf regulator asks for, and it is not what a Gulf board is signing off. The first job is establishing which of the thirty-eight instruments in our register actually reaches you — and which of them does not.

Scope is decided by delivery, not by headquarters

A group headquartered in Dubai with a Riyadh operation is not governed by UAE rules in Riyadh. Which instrument applies is decided by where the service is delivered, what sector it sits in, and — in the free zones — which jurisdiction the entity is registered in. DIFC and ADGM run their own data protection regimes entirely separate from the federal one, and Abu Dhabi health data is carved out from both.

So the assessment starts by ruling things out. A private manufacturer in Oman is not caught by a national cyber control set, because Oman does not have one for the private sector — whatever a vendor's matrix claims. A Kuwaiti company outside CBK licensing is not caught by the Cyber and Operational Resilience Framework. Being told plainly what does not apply is usually worth more than another control list, because it is the part nobody else will tell you.

Then we assess against what is left, using the issuing authority's own language — control references, maturity levels and evidence expectations as the regulator words them, so the output can be handed to an assessor rather than translated first.

The baseline in each market

Where an ordinary private entity starts, before sector rules are layered on. Each country page carries the full register.

Saudi Arabia

Essential Cybersecurity Controls, and the private-sector set above it

ECC-2:2024NCINCC-1:2025

ECC-2:2024 is the baseline every other NCA control set builds on, binding government entities, their contractors, and private owners and operators of critical national infrastructure. For ordinary private business the more significant development is NCINCC-1:2025: entities over 250 staff or SAR 200m revenue face 65 essential controls across 22 sub-components, including an independent cyber security function with periodic review and audit oversight. Smaller entities face 26 controls across 13 sub-components.

Who signsThe NCA's own assessment programme, run through the Haseen national portal, with a public commitment to over 7,000 assessments of national entities. No compliance deadline has been published for NCINCC-1:2025, and its reference number is not yet locatable on the NCA's own site.
United Arab Emirates

Information Assurance Regulation

IAR v1.1

Six management control families and nine technical families across four priority tiers. It binds all federal government entities and everything identified as critical under the CIIP Policy; for everyone else adoption is highly recommended rather than mandated, which in practice means it is what a government customer will assess you against. Emirate-level regimes — DESC in Dubai, ADHICS in Abu Dhabi health — sit on top and are mandatory in their own right.

Who signsPeriodic reporting with no fixed cadence in the document. Widely quoted control counts and an "IAS v2.0" circulate in consultancy material and do not come from the regulator — the current instrument is IAR v1.1.
Qatar

National Information Assurance Standard

NIA v2.1Data Classification v3.0

The clearest certification path in the Gulf, and the one where readiness work has the most obvious destination. Four phases: scope and documentation, audit planning with an accredited auditor, compliance audit and controls assessment by that auditor, then the certification decision by the NCSA. Data classification under the v3.0 policy is the practical starting point for any Qatari assessment.

Who signsAn NCSA-accredited auditor, not us. The certificate runs three years with an annual maintenance audit. We prepare you for that audit and sit on your side of it.
Bahrain and Kuwait

Financial-sector frameworks

CBB RM-9CBK CORF v1.0

Both markets are governed at the baseline by their central banks rather than by a national cyber authority. Bahrain's CBB rulebook is the most prescriptive mandated-external-assessor rule verified anywhere in the GCC. Kuwait's CORF v1.0, in force since December 2025, replaced the 2020 framework with 876 controls across 27 domains on a five-level maturity scale, and requires full compliance before an entity can claim baseline or above.

Who signsBahrain: tested each June, reported to the CBB by 30 September, with the external penetration tester changed at least every two years. Kuwait: annual for tier 1, 18-monthly for tier 2, two-yearly for tier 3, plus annual self-assessment.

What you receive

Four documents. The third is the one that gets used.

01

Applicability determination

Which instruments reach you, which do not, and why — with the reference and the authority for each. Written so it can be attached to a board paper or handed to counsel without rework.

Named instrumentsNamed authorities
02

Control-level gap assessment

Assessed in the regulator's own control references and maturity language, with evidence noted where it exists and named where it does not. No generic maturity score that means nothing to the people who will audit you.

Regulator's references
03

Remediation plan, sequenced

Ordered by regulatory exposure rather than by ease, with an honest view of what your own team can do and what needs a supplier. Costed in effort, not in our day rates, because we are not bidding for the work.

OwnerEffortDependency
04

Board summary

Two pages a non-technical board can act on: what we owe, where we stand, what happens if nothing changes, and the decisions that need taking this quarter. Bilingual where the board needs it.

EN / AR

Where we are not the right supplier, and will say so first

Certification against the Qatari standard must be audited by an NCSA-accredited auditor; we are not one, and we name the firms that are. Penetration testing and incident response for Dubai government and critical infrastructure is gated to Cyber Force certified firms. Cyber security services delivered into Saudi Arabia require Haseen registration, and the draft licensing framework consulted on in early 2026 would go considerably further — a Saudi legal entity, 75% Saudi ownership for government and critical-infrastructure work, and full in-Kingdom data residency. Its enactment status could not be confirmed as of September 2026. We will tell you where that line falls for your engagement before you commit, not after.

Saudi Arabia: NCA ECC-2:2024

Read our ECC-2:2024 guide

Start with a scoping call

Tell us the countries you deliver in, the sector, and whether a customer or a regulator has already asked you a question. Twenty minutes is usually enough to know whether there is a real engagement here.