Market pack
Qatar
A national assurance standard with a defined classification model, a central bank technology regime, and a separate data protection law for the QFC. Three regimes, one control set.
- PRIMARY AUTHORITIES
- NCSA, Qatar Central Bank, QFC
- INSTRUMENTS IN THIS PACK
- 6 national and sector, plus 13 international standards
- CONTRACTING
- Registered Qatari entity. Qatari clients contract locally.
Regulatory register
What applies, to whom, and what the platform does about it. Indicative and maintained as the instruments change — applicability is confirmed per client during scoping.
| Authority or instrument | What it is | Who it applies to | What the platform does |
|---|---|---|---|
| National Cyber Security Agency | National Information Assurance Standard and Policy | Government entities and organisations within NCSA scope | Classification-driven control mapping, compliance position and evidence per control |
| National Cyber Security Agency | Critical Information Infrastructure Protection programme | Designated CII operators | Additional control overlay, incident notification workflow and sector reporting |
| National Cyber Security Agency | National Cyber Security Framework and cloud security policy | Public sector and regulated organisations | Cloud responsibility split and control evidence mapped to the same library |
| Qatar Central Bank | Technology risk, information security, cloud and business continuity circulars | Banks, insurers and payment service providers | Control mapping, outsourcing and cloud registers, resilience testing and incident reporting |
| Law No. 13 of 2016 | Personal Data Privacy Protection Law | Controllers and processors in the State of Qatar | Processing records, consent and lawful basis, rights handling, breach notification |
| QFC Regulatory Authority | QFC Data Protection Regulations and Rules 2021 | QFC-registered entities | Separate privacy pack with its own accountability, assessment and transfer provisions |
| Standard | Scope | How it is used |
|---|---|---|
| ISO/IEC 27001:2022 and 27002 | Information security management system and control set | Certification readiness, live Statement of Applicability, continuous gap position |
| ISO/IEC 27701 | Privacy information management | Extends the ISMS control set with privacy-specific controls and DPO workflow |
| ISO/IEC 27017 and 27018 | Cloud security and cloud personal data | Applied where the estate is cloud-hosted or cloud-delivered |
| ISO 22301 | Business continuity management | BIA, recovery objectives, plan currency and exercise evidence |
| ISO/IEC 42001:2023 | AI management system | AI inventory, impact assessment and model governance |
| NIST CSF 2.0 | Cybersecurity framework | Used as the neutral spine when several national regimes apply at once |
| NIST SP 800-53 Rev. 5 | Control catalogue | Depth mapping where a client's control set is US-derived |
| CIS Controls v8 | Prioritised technical control set | Common baseline for technology teams |
| COBIT 2019 | Technology governance | Used in the Govern pillar for IT and digital governance structures |
| SOC 2 | Service organisation controls | Trust services criteria for clients who serve enterprise customers |
| PCI DSS 4.0 | Payment card security | Applied where card data is in scope |
| IEC 62443 | Industrial automation and control systems | Applied to OT estates alongside the national OT controls |
| Open FAIR | Risk quantification taxonomy | The quantification method used throughout the Anticipate pillar |
Hosting and contracting
Settle residency before tenant design. It is the item most often left until too late.
Data residency
In-country hosting should be assumed for critical information infrastructure and for government-related workloads. QFC-regulated firms should test residency against QFCRA outsourcing expectations.
Contracting entity
Registered Qatari entity. Qatari clients contract locally.