What problem does it solve?
Saudi Arabia's compliance landscape is fragmented across multiple regulators (NCA, SDAIA, SAMA, CST), making it hard to know which frameworks apply to your organization and how they stack. This Skill first determines applicability, then delivers framework-specific guidance.
Core Features & Use Cases
- Applicability Routing: An intake gate and applicability matrix identify which instruments apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud CCC, SAMA CSF, CST cloud framework) based on organization type, sector, data, and cloud posture.
- Gap Assessments & Cross-Mapping: Produces per-framework gap tables with real control references and maps Saudi requirements to ISO 27001:2022, NIST CSF 2.0, and SOC 2 for evidence reuse.
- PDPL & Market Entry Guidance: Covers SDAIA registration, 72-hour breach notification, transfer mechanisms (SCC modules, BCRs), data residency rules, and sequenced market-entry roadmaps.
- Use Case: A fintech expanding to Riyadh asks what applies; the Skill returns the full regulator stack (SAMA CSF maturity level 3, PDPL, CST residency rules), then a phased compliance roadmap.
Quick Start
Ask which Saudi Arabian regulations apply to your organization and request a gap assessment against the applicable frameworks.