Firm
Framework library
What the platform maps, by domain. Indicative rather than exhaustive, and maintained as the instruments change. The applicable set for any client is confirmed during scoping.
Every item below maps into the same normalised control library. That is the point of the library: a control you already operate can satisfy requirements in several of these at once, and the mapping makes that visible rather than assumed.
Where two instruments word a requirement differently enough that one test will not satisfy both, the platform flags it rather than quietly merging them.
Information security management
- ISO/IEC 27001:2022
- ISO/IEC 27002:2022
- ISO/IEC 27017
- ISO/IEC 27018
- NIST CSF 2.0
- NIST SP 800-53 Rev. 5
- NIST SP 800-171
- CIS Controls v8
- SOC 2
National cyber security regimes
- UAE Information Assurance Standards
- DESC Information Security Regulation
- ADHICS
- NCA ECC-2:2024
- NCA CSCC
- NCA CCC
- NCA DCC
- NCA TCC
- NCA OTCC-1:2022
- NCSA Qatar National Information Assurance
- Qatar CIIP
- Oman national cyber security framework
- Bahrain NCSC standards
- CITRA Cyber Security Framework
- UK NCSC CAF
- Cyber Essentials and Cyber Essentials Plus
- NIS Regulations 2018
Financial sector regulation
- CBUAE information security and consumer protection requirements
- SCA technology requirements
- SAMA Cyber Security Framework
- SAMA BCM Framework
- SAMA IT Governance and outsourcing rules
- CMA Saudi Arabia
- Qatar Central Bank technology risk circulars
- QFCRA requirements
- Central Bank of Oman cyber security requirements
- Oman FSA requirements
- CBB Rulebook — operational risk, cyber security, outsourcing
- Central Bank of Kuwait framework
- FCA PS21/3 and PRA SS1/21
- UK critical third parties regime
- PCI DSS 4.0
Privacy and data protection
- UAE Federal Decree-Law 45 of 2021
- ADGM Data Protection Regulations 2021
- DIFC Data Protection Law 5 of 2020
- Saudi PDPL and Implementing Regulations
- SDAIA Data Transfer Regulations
- NDMO data management standards
- Qatar Law 13 of 2016
- QFC Data Protection Regulations 2021
- Oman Royal Decree 6 of 2022
- Bahrain Law 30 of 2018
- CITRA Data Privacy Protection Regulation
- UK GDPR and Data Protection Act 2018
- ISO/IEC 27701
Resilience and continuity
- ISO 22301
- NCEMA 7000
- SAMA BCM Framework
- FCA and PRA operational resilience
- NIST CSF 2.0 Respond and Recover
- UK NCSC CAF Objectives C and D
- DORA — for entities with EU exposure
Technology, OT and AI
- COBIT 2019
- IEC 62443
- ISO/IEC 42001:2023
- NIST AI Risk Management Framework
- MITRE ATT&CK
- Open FAIR
On counts. We do not publish a framework count. The number moves, and it says less than the mapping quality does. During scoping we will show you the actual coverage for the regimes that apply to you, including where coverage is partial.