Morocco's cybersecurity legal framework, setting security obligations for critical infrastructure operators and public administration information systems.
The PASSI qualification (Information Systems Security Audit Provider) is issued by DGSSI to audit providers, under implementing decree 2-21-406 of Law 05-20.
Morocco's law on the protection of individuals with regard to the processing of personal data, overseen by CNDP.
European directive on the security of network and information systems, imposing cybersecurity obligations on essential and important entities within the European Union.
European regulation imposing digital operational resilience requirements on financial entities and their critical ICT third-party providers within the European Union.
EU framework governing the collection, processing, and movement of personal data.
The international reference standard for establishing an information security management system (ISMS).
A family of UAE information assurance standards (188 controls), historically issued under NESA and now sitting under the Cybersecurity Council / SIA (Signals Intelligence Agency) umbrella, with local implementations by DESC in Dubai and ADDA in Abu Dhabi.
A UAE national accreditation program for cybersecurity providers, rolling out in 2026, that restricts which actors are authorized to work with critical information infrastructure entities.
Saudi Arabia's essential cybersecurity controls framework, issued by the National Cybersecurity Authority (NCA), structured into 4 domains, 28 sub-domains, and roughly 110 controls.
Cybersecurity framework issued by the Saudi Arabian Monetary Authority (SAMA), applicable to regulated financial institutions in Saudi Arabia.
Qatar's National Information Assurance policy (NIA), issued by the National Cyber Security Agency (NCSA), complemented by the PDPPL data protection law and Qatar Central Bank (QCB) requirements for the financial sector.
Payment Card Industry Data Security Standard, version 4.0 — a contractual requirement imposed by the card networks, applicable worldwide.
Service Organization Control 2 attestation, defined by the American Institute of CPAs (AICPA), covering the security, availability, processing integrity, confidentiality, and privacy trust service criteria.
African Union Convention on Cyber Security and Personal Data Protection (2014) — the continental reference framework for electronic transaction security, the fight against cybercrime, and data protection across Sub-Saharan African countries.