Frameworks and regulations, explained plainly
What each one is, who it actually binds, what an assessor will ask to see, and where readiness work starts. Written for the person who has to comply, not for an auditor.
NUEXUS delivers readiness, gap assessment, implementation support and evidence preparation. NUEXUS is not an accredited certification body and not an auditor, and cannot certify you, issue an attestation, or sign off on a result.
Gulf and Pakistan
5Regional obligations, where the requirement usually comes from a regulator or a contract rather than from a customer.
NCA ECC
Saudi Arabia
The Saudi National Cybersecurity Authority's baseline controls, and a mandatory obligation for organisations in scope inside the Kingdom.
SAMA CSF
Saudi Arabia, financial sector
The Saudi Central Bank's cyber security framework for the financial sector, applied to the institutions it supervises.
PDPL
Saudi Arabia
Saudi Arabia's personal data protection law, governing how personal data of individuals in the Kingdom may be collected, used and transferred.
SBP
Pakistan, financial sector
The regulatory expectations the State Bank of Pakistan places on the institutions it supervises for technology governance and cyber security risk.
SACS-210
Saudi Arabia, supply chain
Saudi Aramco's third-party cybersecurity standard, which suppliers must satisfy to work with Aramco and its affiliates.
International standards
5Adopted by choice or by customer pressure, and the ones most often written into supplier contracts.
ISO 27001
International
The international standard for an information security management system, and the one most often written into contracts as a supplier requirement.
SOC 2
United States, requested worldwide
A US attestation report on the controls a service organisation runs, most often requested by enterprise customers during procurement.
NIST CSF 2.0
International, US origin
A voluntary framework for organising a security programme around outcomes, widely used as a common language between technical teams and boards.
CIS Controls
International
A prioritised, prescriptive control set that tells a small team what to do first, which is what most other frameworks deliberately avoid doing.
GDPR
European Union, extraterritorial
The European Union's data protection regulation, which reaches organisations outside the EU whenever they process the personal data of people inside it.
