SAK Get your exposure reportFree report
SAK Technologies · compliance hub

Frameworks we cover

What each framework is, who it binds, the control domains and the evidence a regulator or certification body asks for — all mapped natively in GRCorb, with Arabic and English reporting.

Mandatory

NCA ECC

The Essential Cybersecurity Controls (ECC-2:2024), their four domains, and how compliance is assessed for Saudi entities.

ECC-2:2024 · 108 controls
Financial

SAMA CSF

The Saudi Central Bank framework, its maturity model, and what level 3 looks like in evidence.

4 domains · maturity 0–5
Legal

PDPL

Saudi personal data protection duties: lawful basis, cross-border transfer, breach notification and the DPO role.

SDAIA enforced
Supply chain

Aramco CCC / SACS-002

Third-party cybersecurity certification for Aramco suppliers, and the assessment path for SMEs.

CCC certification
Data

NDMO standards

National data management and governance standards across fifteen domains.

SDAIA · NDMO
Commercial

ISO/IEC 27001:2022

Annex A's 93 controls in four themes, the 2024 climate-change amendment, and what a Stage 1 audit actually checks.

93 controls · 4 themes
Highest demand

Essential Eight

The ASD mitigation strategies and the three maturity levels, with what ML2 evidence looks like in practice.

ML1 · ML2 · ML3
Legal

Privacy Act & NDB

Notifiable data breach duties, the serious-harm test, and penalties now reaching AU$50m or 30% of domestic turnover.

13 APPs · OAIC
Critical infra

SOCI Act 2018

Risk management programs, reporting timeframes and the asset classes captured by the 2024 amendments.

RMP · annual report
Financial

APRA CPS 234 & CPS 230

Information security capability, third-party risk and operational resilience for APRA-regulated entities.

Penalties to AU$31.3m
Government

IRAP & the ISM

Assessment against the Information Security Manual for organisations handling government data.

OFFICIAL · PROTECTED
Regulatory coverage

Built for your regulator, not translated for it

Your obligations are mapped natively in GRCorb — NCA ECC, SAMA CSF and PDPL in the Gulf, Essential Eight, the ISM, SOCI and the Privacy Act in Australia, plus ISO 27001, SOC 2 and PCI DSS globally — with the evidence each assessor actually asks for.

FrameworkWho it bindsObligations mappedPlatform coverage
NCA ECCAll Saudi government entities and critical national infrastructureECC-2:2024 · 4 domains · 108 controlsFull
SAMA Cyber Security FrameworkBanks, insurers and financial institutions regulated by SAMA4 domains · maturity levels 0–5Full
PDPLAny entity processing personal data of individuals in KSAConsent · transfer · DPOFull
Aramco CCC (SACS-002)Third parties connecting to or serving Saudi AramcoSupplier certificationIn build
NDMO data standardsEntities handling national data under SDAIA governance15 domainsIn build
ISO/IEC 27001:2022Voluntary — commonly contractually required93 controlsFull
Essential Eight (ML1–ML3)Federal agencies mandatory; strongly recommended for all8 strategies · 3 levelsFull
ISM / IRAPSuppliers handling Australian Government data1,100+ controlsFull
SOCI Act 2018Designated critical infrastructure operatorsRMP + reportingFull
Privacy Act 1988 & NDBTurnover above AU$3m, all health providers13 APPsFull
APRA CPS 234 / CPS 230Banks, insurers, superannuation fundsInfo security + op riskIn build
Worked example

NCA ECC-2:2024 — an example assessment viewEssential Eight maturity level 2 — an example assessment view

An illustration of how GRCorb presents a control assessment — control by control, with the evidence an assessor will ask for. Statuses shown are examples, not a client's results.

Control areaReferenceEvidence an assessor asks forStatus
Cybersecurity governanceECC 1-1Approved strategy, governance structure and evidence of periodic review by the authorising officialEvidenced
Asset managementECC 2-1Complete asset inventory with ownership and classification, reconciled against external discoveryPartial
Identity & access managementECC 2-2MFA for privileged and remote access, access review records, joiner-mover-leaver evidenceEvidenced
Vulnerability managementECC 2-10Scan cadence, remediation SLAs by severity and evidence of closure for critical findingsPartial
Third-party cybersecurityECC 4-1Supplier register, contractual security requirements and periodic supplier assessmentsGap
Certifying or facing an assessment?

Find out where you stand before the assessor does

Tell us the framework and the deadline. We will come back with a readiness conversation grounded in your actual external exposure — not a generic gap template.

Talk to us about readiness