saudi-arabia-grc

Routes Saudi Arabia compliance questions across NCA ECC, PDPL, SAMA, and CST frameworks.

869|179|Updated Mar 16, 2026
One-click install
npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: saudi-arabia-grc
Source: https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/saudi-arabia-grc/skills/saudi-arabia-grc
Command: npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Saudi Arabia's compliance landscape is fragmented across multiple regulators (NCA, SDAIA, SAMA, CST), making it hard to know which frameworks apply to your organization and how they stack. This Skill first determines applicability, then delivers framework-specific guidance.

Core Features & Use Cases

  • Applicability Routing: An intake gate and applicability matrix identify which instruments apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud CCC, SAMA CSF, CST cloud framework) based on organization type, sector, data, and cloud posture.
  • Gap Assessments & Cross-Mapping: Produces per-framework gap tables with real control references and maps Saudi requirements to ISO 27001:2022, NIST CSF 2.0, and SOC 2 for evidence reuse.
  • PDPL & Market Entry Guidance: Covers SDAIA registration, 72-hour breach notification, transfer mechanisms (SCC modules, BCRs), data residency rules, and sequenced market-entry roadmaps.
  • Use Case: A fintech expanding to Riyadh asks what applies; the Skill returns the full regulator stack (SAMA CSF maturity level 3, PDPL, CST residency rules), then a phased compliance roadmap.

Quick Start

Ask which Saudi Arabian regulations apply to your organization and request a gap assessment against the applicable frameworks.

Frequently Asked Questions about saudi-arabia-grc

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
Which Saudi Arabia cybersecurity regulations apply to my company?

Applicability depends on organization type and sector. NCA ECC-2:2024 is mandatory for government entities and CNI operators, Saudi PDPL applies to anyone processing Saudi residents' personal data, SAMA CSF binds licensed financial institutions, and the CST framework governs cloud providers. These regimes stack rather than displace each other.

How do I comply with the Saudi PDPL for personal data transfers?

Saudi PDPL transfers require a lawful mechanism: SDAIA-assessed adequacy, SDAIA Standard Contractual Clauses in four modules (C2C, C2P, P2C, P2P), Binding Common Rules, or limited derogations. Controllers must also register on SDAIA's National Data Governance Platform and report breaches within 72 hours.

What maturity level does the SAMA Cyber Security Framework require?

SAMA expects regulated entities (banks, insurers, financing companies, credit bureaus, fintechs) to operate at maturity level 3 minimum on its six-level scale, meaning structured and formalized processes. Entities conduct periodic self-assessments subject to SAMA reviews.

Does Saudi Arabia require data residency for cloud workloads?

Yes, residency is classification-driven. Government data must remain in-Kingdom with narrow exceptions, and customer data classified Levels 3-4 under the CST Cloud Computing Regulatory Framework requires in-Kingdom hosting. CSPs must register with CST in a class matching the data levels they host.

Can Saudi compliance requirements be mapped to ISO 27001 or SOC 2?

Yes, ECC domains map naturally to ISO 27001:2022 Annex A, NIST CSF 2.0, and SOC 2 TSC, letting multinationals reuse existing evidence. Saudi-specific deltas remain: in-Kingdom residency, Arabic-language governance artifacts, NCA reporting channels, and SDAIA registration.

What are the penalties for violating the Saudi PDPL?

Fines reach SAR 5,000,000 per violation and may double for repeat violations, with criminal exposure up to 2 years' imprisonment for unlawful disclosure of sensitive data. SDAIA's violation committees issued roughly 48 decisions in the first enforcement wave of 2025-26.