Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Compliance

Law 05-20 & DGSSI

Morocco's cybersecurity legal framework, setting security obligations for critical infrastructure operators and public administration information systems.

PASSI Qualification (Morocco)

The PASSI qualification (Information Systems Security Audit Provider) is issued by DGSSI to audit providers, under implementing decree 2-21-406 of Law 05-20.

Law 09-08 & CNDP

Morocco's law on the protection of individuals with regard to the processing of personal data, overseen by CNDP.

NIS2 (EU Directive)

European directive on the security of network and information systems, imposing cybersecurity obligations on essential and important entities within the European Union.

DORA (Digital Operational Resilience Act)

European regulation imposing digital operational resilience requirements on financial entities and their critical ICT third-party providers within the European Union.

GDPR (General Data Protection Regulation)

EU framework governing the collection, processing, and movement of personal data.

ISO/IEC 27001:2022

The international reference standard for establishing an information security management system (ISMS).

NESA / UAE IA Standards (United Arab Emirates)

A family of UAE information assurance standards (188 controls), historically issued under NESA and now sitting under the Cybersecurity Council / SIA (Signals Intelligence Agency) umbrella, with local implementations by DESC in Dubai and ADDA in Abu Dhabi.

NCAP — National Cyber Accreditation Programme (United Arab Emirates)

A UAE national accreditation program for cybersecurity providers, rolling out in 2026, that restricts which actors are authorized to work with critical information infrastructure entities.

NCA ECC-2:2024 — Essential Cybersecurity Controls (Saudi Arabia)

Saudi Arabia's essential cybersecurity controls framework, issued by the National Cybersecurity Authority (NCA), structured into 4 domains, 28 sub-domains, and roughly 110 controls.

SAMA Cybersecurity Framework

Cybersecurity framework issued by the Saudi Arabian Monetary Authority (SAMA), applicable to regulated financial institutions in Saudi Arabia.

Qatar NIA (NCSA) & PDPPL

Qatar's National Information Assurance policy (NIA), issued by the National Cyber Security Agency (NCSA), complemented by the PDPPL data protection law and Qatar Central Bank (QCB) requirements for the financial sector.

PCI DSS v4.0

Payment Card Industry Data Security Standard, version 4.0 — a contractual requirement imposed by the card networks, applicable worldwide.

SOC 2

Service Organization Control 2 attestation, defined by the American Institute of CPAs (AICPA), covering the security, availability, processing integrity, confidentiality, and privacy trust service criteria.

Malabo Convention

African Union Convention on Cyber Security and Personal Data Protection (2014) — the continental reference framework for electronic transaction security, the fight against cybercrime, and data protection across Sub-Saharan African countries.