Services

Three services, one control set

An assessment that tells you where you stand, readiness work that closes the gaps, and a read-only agent that keeps your evidence current. Scope and fee are fixed before any work begins.

What we do

Assess

Cybersecurity and Data Protection Assessment

We measure your controls against the NCA Essential Cybersecurity Controls and the extensions that apply to you, the Personal Data Protection Law, and the SAMA Cyber Security Framework if SAMA regulates you, and ISO/IEC 27001 where it helps. You receive a gap report and a roadmap ranked by risk, not by how easy each fix is.

Get ready

Compliance readiness

We map your controls once to every framework in scope, prepare the evidence, and work through the gaps with your team until you are ready for the regulator's or the auditor's review.

Stay current

Read-only compliance agent

The agent observes configuration across your cloud and infrastructure and reports drift against your control set. It has read-only access, cannot make changes and does not remediate. Every change stays with your team.

What the assessment delivers

Deliverables

Scope
Which frameworks apply to you and why, confirmed in writing
Findings
Control-by-control results, each tied to the evidence we saw
Gap register
Every gap, its risk and the requirement it relates to
Roadmap
The order to close gaps in, with owners and realistic effort
Board summary
A short summary your leadership can act on

What we do not do

Clear boundaries are part of doing this properly.

  • We do not certify you or declare you compliant. That decision belongs to the regulator, or to an accredited auditor where one is involved.
  • We do not act for, or speak on behalf of, any regulator.
  • Our agent does not change your systems. It observes and reports; your team decides and acts.
  • We do not treat compliance as a purchase. It is a state you maintain, which is why the evidence has to stay current.

How an engagement starts

  1. A ten-minute roadmap call

    Tell us what you do and who regulates you. We tell you which rules apply and where the gaps usually are.

  2. A fixed scope and fee

    We confirm the frameworks, systems and deliverables in writing, with a fixed fee, before any work begins.

  3. Assessment, then readiness

    We assess first, agree the roadmap with you, then work through it together.

Ten minutes to know exactly where you stand

Tell us what you do and who regulates you. We will show you which Saudi rules apply, where the gaps usually are, and the shortest route to ready. No slides, no pitch.