| NCA ECC | All Saudi government entities and critical national infrastructure | ECC-2:2024 · 4 domains · 108 controls | Full |
| SAMA Cyber Security Framework | Banks, insurers and financial institutions regulated by SAMA | 4 domains · maturity levels 0–5 | Full |
| PDPL | Any entity processing personal data of individuals in KSA | Consent · transfer · DPO | Full |
| Aramco CCC (SACS-002) | Third parties connecting to or serving Saudi Aramco | Supplier certification | In build |
| NDMO data standards | Entities handling national data under SDAIA governance | 15 domains | In build |
| ISO/IEC 27001:2022 | Voluntary — commonly contractually required | 93 controls | Full |
| Essential Eight (ML1–ML3) | Federal agencies mandatory; strongly recommended for all | 8 strategies · 3 levels | Full |
| ISM / IRAP | Suppliers handling Australian Government data | 1,100+ controls | Full |
| SOCI Act 2018 | Designated critical infrastructure operators | RMP + reporting | Full |
| Privacy Act 1988 & NDB | Turnover above AU$3m, all health providers | 13 APPs | Full |
| APRA CPS 234 / CPS 230 | Banks, insurers, superannuation funds | Info security + op risk | In build |
| ISO/IEC 27001:2022 | Voluntary — commonly contractually required | 93 controls | Full |