Compliance
Helps organizations comply with the laws, regulations, and industry standards that apply to information security and data protection, across both international and regional frameworks.

The standards we work against.
International
- Information Security & Data Protection (ISO 27001, PCI-DSS)
- Cybersecurity Framework (NIST CSF)
- Business Continuity Management (ISO 22301)
- Data Protection & Privacy (GDPR, ISO 27701)
- IT Governance (COBIT)
Regional
- Financial sector standards (CBJ, SAMA CSF, SAMA BCM, SAMA CTI)
- National Cybersecurity Regulations (NCA)
- Data Governance (NDMO)
- Saudi Aramco Cybersecurity Standards
Seven phases to compliance.
Assessment
A gap analysis or compliance assessment identifies non-compliance issues and vulnerabilities.
Action Planning
Tasks, timelines, and responsibilities are outlined for reaching compliance.
Policies & Procedures
Documentation is developed to meet the target framework's requirements.
Governance Development
Governance materials are created and aligned with the relevant standard.
Training
Training and awareness programs build employee understanding of the new controls.
Ongoing Support
Compliance is maintained through continued monitoring and testing.
Certification
Certification services demonstrate the standard has been achieved, where applicable.
What you receive.
Where this connects.
Information Security Management
The ISO 27001 management system most compliance programs are built on top of.
Business Continuity Management
ISO 22301, where the requirement is availability rather than confidentiality.
GRC Platform (ExceedGRC)
Runs the gap and risk assessments against ISO 27001, NCA ECC, and SAMA CSF as a platform rather than a spreadsheet.
Common questions.
Which frameworks do you work against?
Internationally, ISO 27001, PCI-DSS, NIST CSF, ISO 22301, GDPR, ISO 27701, and COBIT. Regionally, CBJ, the SAMA standards, NCA, NDMO, and Saudi Aramco cybersecurity standards.
Where does the engagement start?
With a gap analysis or compliance assessment that identifies non-compliance issues and vulnerabilities, delivered as a gap analysis report before any remediation work is planned.
Do you write the documentation for us?
Yes. Policies and procedures are developed to meet the target framework's requirements, and governance materials are created and aligned with the relevant standard.
Does support continue once we are compliant?
Yes. Compliance is maintained through continued monitoring and testing, and certification services demonstrate the standard has been achieved where certification applies.