The frameworks your clients answer to.
We build delivery around the control sets that Saudi regulators actually audit, so the evidence your client needs is a by-product of the service rather than a separate project.
National Cybersecurity Authority (NCA)
The national baseline and its extensions.
ECC-2:2024
Essential Cybersecurity Controls
The national baseline every in-scope entity is measured against.
CCC-2:2024
Cloud Cybersecurity Controls
Obligations split between the cloud provider and the tenant using it.
DCC-1:2022
Data Cybersecurity Controls
Classification-driven protection across the data lifecycle; extends the ECC.
CSCC-1:2019
Critical Systems Cybersecurity Controls
Additional controls over systems designated as critical.
OTCC-1:2022
Operational Technology Cybersecurity Controls
Controls for industrial and operational technology environments.
Saudi Central Bank (SAMA)
For institutions SAMA supervises.
CSF
Cyber Security Framework
The cybersecurity expectations placed on SAMA-supervised financial institutions.
BCM
Business Continuity Framework
Continuity and recovery obligations that sit alongside the cyber framework.
Saudi Data and AI Authority (SDAIA)
Personal data, wherever it is processed in the Kingdom.
PDPL
Personal Data Protection Law
Lawful basis, data subject rights and breach notification for personal data.
Implementing Regulations
PDPL Implementing Regulations
The operational detail behind the law, including transfer conditions.
Communications, Space and Technology Commission (CST)
For licensed telecom, cloud and ICT providers.
CCRF
Cloud Computing Regulatory Framework
Licensing classes and customer protection duties for cloud services.
CRF (RT08)
Cybersecurity Regulatory Framework for ICT Service Providers
Cybersecurity obligations for CST-licensed and registered ICT providers.
International standards
Where a client, parent company or tender asks for them.
ISO/IEC 27001
Information security management
The management system most international clients recognise.
ISO 22301
Business continuity management
Continuity planning that holds up under audit.
PCI DSS
Payment card data security
Applies wherever cardholder data is stored, processed or transmitted.
NIST CSF
Cybersecurity Framework
A common language for mapping controls across several regimes at once.
System Formation is not a regulator, and is not certified, accredited or endorsed by any authority named on this page. We deliver services designed to help our partners and clients meet these requirements.
Bring us the framework your client is audited against.
We will show you what delivery looks like against it, and where the evidence comes from.