Accelerate your journey for cybersecurity compliance today!

Complyan GRC Platform for Compliance

Every regulator you report to,
in one library.

NCA, SAMA, UAE IA, QCB, CBB, CBK, NDPA, POPIA, ISO 27001, SOC 2 and more, preloaded and ready to assign. Collect evidence once and reuse it wherever frameworks share a requirement.

Built in the UAE. Supported locally across the GCC and Africa, in English, Arabic, and French.

70+Frameworks preloaded
11+Countries
165Automated tests
3Languages
Framework library

Open any framework to see what it covers

Middle East and GCC

18 frameworks

Saudi Arabia's Essential Cybersecurity Controls. Mandatory for government entities and critical infrastructure operators in the Kingdom.

Saudi Arabia guides →

Cybersecurity framework for banks, insurers, and finance companies regulated by the Saudi Central Bank.

Banking and finance →

Cybersecurity requirements for capital market institutions licensed by the CMA.

Saudi Arabia guides →

The UAE's national information assurance standard for federal entities and critical infrastructure across all emirates.

UAE regulation guides →

Health information and cybersecurity standard for every healthcare entity licensed in Abu Dhabi.

Healthcare →

Federal personal data protection law covering how UAE residents' data is collected, processed, and transferred.

Data privacy regulations →

Dubai's Information Security Regulation, issued by the Dubai Electronic Security Center for government entities and their suppliers.

Public sector →

The UAE's business continuity standard for government and critical entities.

UAE regulation guides →

Cybersecurity standard for schools and education providers in Abu Dhabi.

Public sector →

Qatar Central Bank's cybersecurity requirements for banks and financial institutions. The largest regional library we ship.

Banking and finance →

Qatar's National Information Assurance policy for government and critical sector organisations.

Public sector →

Qatar's Personal Data Privacy Protection Law (Law No. 13 of 2016) for organisations handling residents' personal data.

GCC data sovereignty guide →

Cyber risk requirements from the CBB Rulebook, including security operations, incident response, and outsourcing.

Banking and finance →

The National Cyber Security Center's baseline controls for organisations in Bahrain.

Cybersecurity compliance →

Cybersecurity framework for banks and financial institutions regulated by the Central Bank of Kuwait.

Kuwait guides →

CITRA's IT governance requirements for telecom and IT licensees in Kuwait.

Telecoms →

Cybersecurity requirements for banks and financial institutions licensed in Oman.

Banking and finance →

Cybersecurity instructions for banks and financial institutions in Jordan.

Banking and finance →

Africa

8 frameworks

Nigeria's data protection act, covering lawful processing, data subject rights, and breach notification.

NDPA 2023 guide →

The CBN risk-based cybersecurity framework and data localisation directive for banks, payment providers, and fintechs.

CBN localisation guide →

South Africa's Protection of Personal Information Act, setting the conditions for lawful processing of personal information.

Data privacy regulations →

Kenya's Data Protection Act, covering registration, processing, and cross-border transfer of personal data.

Data privacy regulations →

Ghana's Data Protection Act for organisations processing personal data of Ghanaian residents.

Data privacy regulations →

Egypt's Personal Data Protection Law for organisations collecting or processing data of Egyptian residents.

Data privacy regulations →

Cyber and Information Security Directive for banks, specialised deposit-taking institutions and payment service providers in Ghana.

Banking and finance →

Guidance note on cybersecurity for banks licensed by the Central Bank of Kenya.

Banking and finance →

International and industry

21 frameworks

The international ISMS standard, accepted by regulators across the GCC, Africa, and Europe. The 2013 edition is also available for teams mid-transition.

Cybersecurity compliance →

Privacy extension to ISO 27001. A practical bridge between your ISMS and laws like PDPL, NDPA, and POPIA.

Data privacy and governance →

Management system standard for organisations that build or use AI.

Complyan AI →

Trust Services Criteria report that enterprise customers ask SaaS and service providers for.

SOC 2 Type I vs Type II →

Required for anyone storing, processing, or transmitting cardholder data.

PCI DSS for retailers →

Customer Security Programme controls for institutions connected to the SWIFT network.

Banking and finance →

Applies to any organisation handling EU residents' data, including GCC and African companies selling into Europe.

GDPR in 2026 →

ICT risk, incident reporting, resilience testing, and third-party oversight for EU financial entities.

Banking and finance →

Risk-based cybersecurity framework used worldwide as a common baseline. Version 1.1 is also available.

Cyber risk management →

The Secure Controls Framework behind Complyan's cross mapping. It is what lets one control count across many frameworks.

Cross mapping guide →

IT governance framework widely used in GCC banking and government.

Governance and policy →

Business continuity management, often requested by GCC financial regulators alongside sector frameworks.

Ransomware readiness →

IT service management standard, aligned with ITIL practice.

Cybersecurity compliance →

US health data rules, relevant to providers with US patients, partners, or data flows.

Healthcare →

Maturity model for security operations centres across people, process, and technology.

Cyber maturity assessment →

Canadian baseline cybersecurity controls for small and medium organisations.

For SMEs →

Integrity requirements for the software supply chain, from source to build to release.

Supply chain security →

Basic cyber hygiene for suppliers in the US defence supply chain.

Supply chain security →

Technology risk management guidelines for financial institutions regulated by MAS.

Banking and finance →

UK government-backed scheme covering five basic technical controls.

For SMEs →

Cybersecurity Capability Maturity Model for assessing and improving cybersecurity programmes.

Cyber maturity assessment →

Don't see your framework?

Share the custom or public framework you need with us, and find it here in your library.

Share your framework →
Cross mapping

Answer once, satisfy many.

Complyan maps frameworks to a common control set built on the Secure Controls Framework. When a control is complete, its evidence counts toward the matching requirements in the frameworks you track. One incident response plan covers four of them here.

How a common control framework works →
By industry

Which frameworks apply to your sector

A starting point. Your licence and data flows decide the final list.

IndustryISO 27001NCA ECCSAMA / CBB / QCBUAE IAPCI DSSPDPL / NDPA / POPIASOC 2
Banking and finance✓✓✓✓✓✓◑
Public sector✓✓·✓·✓·
Healthcare✓◑·✓◑✓◑
Telecoms✓✓·✓◑✓◑
Retail✓◑·◑✓✓◑
Legal✓◑·◑·✓✓
Manufacturing✓◑·◑·◑·

✓ Usually required   ◑ Depends on licence or data flows   · Rarely required

Accelerate your journey for cybersecurity compliance today!