Not Sure Which Framework Applies to You?
Tell us your country, industry and data footprint β we'll tell you which regulations are actually relevant, not just the ones we sell services against.
Whether you're closing gaps against a mandatory national framework in the GCC, preparing for an EU regulatory deadline, or pursuing an international standard, this is the map. Each page below covers who's in scope, what's required, and how Cyberox helps β verified against official regulator sources, not assumptions.
National cybersecurity authorities, central-bank frameworks and data-protection laws across our core served markets.
The National Cybersecurity Authority's Essential Cybersecurity Controls β Saudi Arabia's baseline framework for government, GRE and critical infrastructure entities.
Read moreThe Saudi Central Bank's Cyber Security Framework, mandatory for banks, insurers and finance companies.
Read moreSDAIA-administered Personal Data Protection Law requirements for organizations processing personal data in the Kingdom.
Read moreFederal Information Assurance Standards, DESC's Dubai Information Security Regulation, CBUAE requirements, and PDPL/DIFC/ADGM data protection.
Read moreNCSA cybersecurity requirements and PDPPL enforcement, plus Qatar Central Bank obligations for financial institutions.
Read moreNCSC's national cybersecurity risk-management framework and Central Bank of Bahrain requirements for the financial sector.
Read moreThe Central Bank of Kuwait's Cyber & Operational Resilience Framework, replacing the 2020 Cybersecurity Framework for banks and financial institutions.
Read moreOCERT national guidance, the Central Bank of Oman's Cyber Security & Resilience Framework, and Oman's Personal Data Protection Law.
Read moreDelivered remotely for organizations serving or based in these markets β we don't claim a European office we don't have.
Applicability assessment and compliance program for the EU's expanded cybersecurity directive covering 160,000+ entities.
Read moreDigital Operational Resilience Act readiness for financial entities and their critical ICT third-party providers.
Read morePrivacy gap assessment, connected-product security readiness, and AI governance across three distinct EU regimes.
Read moreCyber Essentials and Cyber Essentials Plus readiness against the NCSC-backed scheme's five control themes.
Read moreNot tied to a single jurisdiction β recognized globally and often layered underneath the national frameworks above.
Business continuity management aligned with ISO 22301 principles.
Learn moreNESA/DESC-aligned information security compliance support.
Learn moreCoverage still being expanded: dedicated pages for PCI DSS, NIST CSF 2.0, CIS Controls and ISO/IEC 42001 (AI Management Systems) are planned as commercial demand and content depth justify them β see our full services catalogue for current advisory support in these areas.
Tell us your country, industry and data footprint β we'll tell you which regulations are actually relevant, not just the ones we sell services against.