The frameworks your clients answer to.

We build delivery around the control sets that Saudi regulators actually audit, so the evidence your client needs is a by-product of the service rather than a separate project.

National Cybersecurity Authority (NCA)

The national baseline and its extensions.

  • ECC-2:2024

    Essential Cybersecurity Controls

    The national baseline every in-scope entity is measured against.

  • CCC-2:2024

    Cloud Cybersecurity Controls

    Obligations split between the cloud provider and the tenant using it.

  • DCC-1:2022

    Data Cybersecurity Controls

    Classification-driven protection across the data lifecycle; extends the ECC.

  • CSCC-1:2019

    Critical Systems Cybersecurity Controls

    Additional controls over systems designated as critical.

  • OTCC-1:2022

    Operational Technology Cybersecurity Controls

    Controls for industrial and operational technology environments.

Saudi Central Bank (SAMA)

For institutions SAMA supervises.

  • CSF

    Cyber Security Framework

    The cybersecurity expectations placed on SAMA-supervised financial institutions.

  • BCM

    Business Continuity Framework

    Continuity and recovery obligations that sit alongside the cyber framework.

Saudi Data and AI Authority (SDAIA)

Personal data, wherever it is processed in the Kingdom.

  • PDPL

    Personal Data Protection Law

    Lawful basis, data subject rights and breach notification for personal data.

  • Implementing Regulations

    PDPL Implementing Regulations

    The operational detail behind the law, including transfer conditions.

Communications, Space and Technology Commission (CST)

For licensed telecom, cloud and ICT providers.

  • CCRF

    Cloud Computing Regulatory Framework

    Licensing classes and customer protection duties for cloud services.

  • CRF (RT08)

    Cybersecurity Regulatory Framework for ICT Service Providers

    Cybersecurity obligations for CST-licensed and registered ICT providers.

International standards

Where a client, parent company or tender asks for them.

  • ISO/IEC 27001

    Information security management

    The management system most international clients recognise.

  • ISO 22301

    Business continuity management

    Continuity planning that holds up under audit.

  • PCI DSS

    Payment card data security

    Applies wherever cardholder data is stored, processed or transmitted.

  • NIST CSF

    Cybersecurity Framework

    A common language for mapping controls across several regimes at once.

System Formation is not a regulator, and is not certified, accredited or endorsed by any authority named on this page. We deliver services designed to help our partners and clients meet these requirements.

Bring us the framework your client is audited against.

We will show you what delivery looks like against it, and where the evidence comes from.

Talk to our team