Solutions · Saudi Arabia & the Gulf
Compliance across Saudi Arabia and the Gulf
A group with entities in Riyadh, Doha and Dubai answers to three national authorities and several sector regulators. xmodo sets up each regulation on its own terms and reports maturity levels where the regulator requires them. A shared control is implemented once.
By country
What is in the library today
Saudi Arabia
The central bank's cyber security framework with its maturity levels, and the National Cybersecurity Authority's essential controls, each set up with its requirements. Results show the maturity level achieved as well as a percentage.
Qatar
The national information assurance policy, set up so that controls are selected according to data classification.
United Arab Emirates
Federal, emirate, free-zone and sector regulations, each included in full, with a tool that lists them by entity type.
Maturity levels
Maturity levels as the regulator assesses them
SAMA CSF and NCA ECC are assessed on maturity levels. xmodo calculates the level achieved in each domain from the status of your controls and evidence. It shows the percentage alongside, so the board sees the regulator's level and the work behind it.
Frequently asked questions
Is the Saudi PDPL in the library?
It is not yet available as a ready-made framework. You can add any framework yourself, with the same mappings, dashboards and evidence tools as a library framework. We share the Saudi roadmap on the scoping call.
Can a Gulf group run SAMA CSF and the UAE regulations together?
Yes. Each entity is scoped to the regulations that apply to it, and shared controls are implemented once. The group view combines compliance status while keeping legal scopes separate.
Are maturity levels calculated or entered manually?
They are calculated from the status of your controls and evidence, with the reasoning for each domain shown. A named reviewer can adjust a level, and the reason is recorded.