PDPL. CBE.
FRA. NTRA. One GRC Platform.

Governance, risk and compliance on one control library for banks, non-bank finance, insurers and telecoms in Egypt. Run it in your private cloud, on-premises or as SaaS.

Already in use with regulated organisations across the Middle East · Live in weeks to months

The Grace Period Is Ending.

A bank in Cairo answers to the Central Bank of Egypt’s cybersecurity framework and strict banking-secrecy rules. A consumer-finance or insurance firm answers to the Financial Regulatory Authority. A hospital group, retailer or outsourcer answers to the new Personal Data Protection Center, with licences and a DPO required.

Most teams still track this in spreadsheets, email trails and a tool that only covers IT controls. Governance and enterprise risk stay manual. Keep your advisors; give them one platform to work from.

LockThreat maps your obligations once, tests your controls continuously, and gives your board one current view of risk.

The Clock Is Running.

Already in force
Cybercrime & Banking Laws
180-day log retention for service providers; strict secrecy for bank data.
21 Oct 2025
FRA Cyber Decree
Security policy, cyber insurance and penetration tests for non-bank firms.
2 Nov 2025
PDPL Regulations in Force
Executive Regulations take effect; the one-year countdown begins.
24 Aug 2026
CBE Digital Identity Rules
eKYC rules for banks, with data protection and cyber controls.
1 Nov 2026
Full PDPL Compliance Due
Licences and a registered DPO required. Fines up to EGP 5 million.

Built for Egypt’s Most Regulated Sectors

Banks

CBE cybersecurity framework, banking secrecy and outsourcing rules.

Non-Bank Finance & Fintech

FRA Decree 227/2025 and fintech technology rules.

Insurers

FRA cyber requirements and the Unified Insurance Law.

Telecoms & Critical Infrastructure

NTRA frameworks, the Cloud First Policy and national cyber priorities.

Healthcare

PDPL licences for sensitive health data.

IT & Outsourcing Exporters

PDPL at home; ISO 27001, SOC 2 and GDPR for clients abroad.

Spreadsheets and IT-Only Tools Leave agap
Regulators Will Find.

Legacy Enterprise
GRC
Compliance-First Tools
LockThreat
Egyptian Frameworks
Custom build
Limited local depth
PDPL, CBE, FRA, NTRA
GRC Depth
Full G+R+C
Compliance only
Full G+R+C
Deployment
Complex to configure
Typically SaaS only
Private cloud, on-prem, SaaS
Multi-Regulator Mapping
Consultant-heavy
IT controls only
Test once, map across regulators
Continuous Monitoring
Limited or none
IT & cyber only
Enterprise-wide
AI Governance
Separate add-on
Limited
Built-in, incl. agentic AI
Time to Value
12–18 months
Weeks, compliance only
Weeks to months
Egyptian Frameworks
Legacy Enterprise GRC
Custom build
Compliance-First Tools
Limited local depth
LockThreat
PDPL, CBE, FRA, NTRA
GRC Depth
Legacy Enterprise GRC
Full G+R+C
Compliance-First Tools
Compliance only
LockThreat
Full G+R+C
Deployment
Legacy Enterprise GRC
Complex to configure
Compliance-First Tools
Typically SaaS only
LockThreat
Private cloud, on-prem, SaaS
Multi-Regulator Mapping
Legacy Enterprise GRC
Consultant-heavy
Compliance-First Tools
IT controls only
LockThreat
Test once, map across regulators
Continuous Monitoring
Legacy Enterprise GRC
Limited or none
Compliance-First Tools
IT & cyber only
LockThreat
Enterprise-wide
AI Governance
Legacy Enterprise GRC
Separate add-on
Compliance-First Tools
Limited
LockThreat
Built-in, incl. agentic AI
Time to Value
Legacy Enterprise GRC
12–18 months
Compliance-First Tools
Weeks, compliance only
LockThreat
Weeks to months

Frameworks for Egypt

Mapped to one control library, so a control tested once serves every framework it supports. Tracking something not listed? Ask us.

Categories
No frameworks match your search.

Data Protection

Personal Data Protection Law (Law No. 151 of 2020)
PDPL Executive Regulations (MCIT Decree No. 816 of 2025)
Cloud First Policy (2024)
ISO/IEC 27701
GDPR (General Data Protection Regulation)

Cyber & Critical Infrastructure

Anti-Cyber and Information Technology Crimes Law (Law No. 175 of 2018)
National Cybersecurity Strategy 2023–2027
NTRA IoT Regulatory Framework (2022)
NIST CSF 2.0
CIS Critical Security Controls
ISO 22301

Banking & Financial Services

Central Bank and Banking Sector Law (Law No. 194 of 2020)
CBE Cybersecurity Regulatory Framework
CBE Digital Financial Identity (eKYC) Regulations, 2026
FinTech Law (Law No. 5 of 2022)
FRA Decree No. 139 of 2023 (Technology Infrastructure & Security)
FRA Decree No. 227 of 2025 (Cybersecurity)
Unified Insurance Law (Law No. 155 of 2024)
PCI DSS
SWIFT Customer Security Programme

Governance, Risk & ESG

Egyptian Code of Corporate Governance
EGX Listing and Delisting Rules
FRA ESG & Climate Disclosure (Decrees No. 107 & 108 of 2021)
ISO 31000
COSO (Committee of Sponsoring Organizations)

Global Standards

ISO 27001:2022
ISO/IEC 27018
CSA CCM (Cloud Controls Matrix)
ISO/IEC 20000-1

AI Governance

National AI Strategy (Second Edition) 2025–2030
Egyptian Charter for Responsible AI
ISO/IEC 42001 (AI Management System)
NIST AI Risk Management Framework (NIST AI RMF)
EU AI Act
The Risk Nobody’s Governing

Your teams are already using AI on customer and employee data. Under Egyptian data protection and banking-secrecy rules, you’re accountable for it. Do you know which AI tools and agents are breaching your controls?

AI Security & Governance Flow

Your Data. Your Boundary.

Egyptian rules keep sensitive data close: PDPL-regulated firms need a licence from the Personal Data Protection Center to send personal data abroad, and the Cloud First Policy keeps secret and top-secret government data in Egypt.

Choose how LockThreat runs: in your own private cloud, on-premises in your data centre in Egypt, or as managed SaaS. The same full G+R+C depth, regardless of deployment.

SaaS
Managed by us.
Private Cloud
Your cloud. Your region.
On-Premises
Fully within your walls.

One Platform for the Whole Buying Committee

Blue shield icon with a white award ribbon symbol featuring a star in the center.Vertical flowchart with four outlined circles connected by dotted lines in dark blue, beige, and light blue colors.
CISO
  • CBE, FRA and PDPL evidence collected continuously, not the week before an inspection.
  • Third-party and outsourcing risk tracked alongside your own controls.
Line drawing of a human head and upper torso facing forward with a large dark blue dot near the brain area and a smaller bright blue dot near the upper chest.
DPO & Chief Compliance Officer
  • PDPL obligations mapped to controls, with the 72-hour breach clock tracked in incident workflows.
  • Policies and gap analysis generated against the frameworks you answer to.
Line art icon with a stylized head and shoulders and three floating dots above representing communication or connection.
Chief Risk Officer
  • Risk quantified in financial terms with FAIR modelling and Monte Carlo simulation.
  • One enterprise risk register across business units and locations.
Two overlapping blue circles connected by a black diagonal line on a white background.
Internal Audit & Audit Committee
  • Continuous control testing instead of periodic sampling.
  • Board and committee reporting drawn from live data, not spreadsheets.
Outline of a person’s head and shoulders with a blue circle above representing the mind or focus.

Everything Enterprise GRC Should Have Been.

True GRC Depth

Most GRC tools deliver compliance, with governance and risk as an afterthought.

Here, governance comes first: the policies that move your organisation forward, the controls that contain risk across every department, and the compliance that follows naturally from both.

No spreadsheets. No disconnected tools. No point-in-time snapshots. One centralised, ongoing view of your risk and compliance posture.

GRC for Everyone

Your regulatory obligations don’t respect org charts or borders.

Every department, from finance, legal and HR to operations, cyber and IT, managed in one place, without the sprawl.

The locations you operate in, from Cairo, Giza and Alexandria to the New Administrative Capital and your offices worldwide, managed in one place without adding more tools.

AI Governance & Security

Which AI tools are your employees using? Are they approved? Are they handling personal data your PDPL notices and licences don’t cover?

And when AI agents act autonomously, accessing systems, making decisions, breaching controls, who’s watching? Now you are.

From shadow AI discovery and ISO/IEC 42001 alignment to real-time prompt protection and agentic control enforcement, reported directly into your GRC framework.

Risk Clarity

Every stakeholder needs a different view of the same risk reality, from one source of truth.

Express risk in financial terms your board and CFO can act on, using FAIR modelling and Monte Carlo simulation.

Detailed enough for the analyst, clear enough for the Chief Risk Officer and the CISO, compelling enough for the board.

Continuous Assurance

Compliance isn’t an annual exercise; it’s an ongoing operating requirement.

LockThreat validates that your controls are working, right now, across cloud infrastructure, cyber endpoints and enterprise applications.

Far less scrambling for evidence before a CBE inspection, an FRA review or a client security audit.

Framework Convergence

Map the PDPL, CBE and FRA requirements and the Cybercrime Law to ISO 27001, NIST and SOC 2, and to each other, eliminating redundant work.

Tie everything to your own policy library and control framework, so governance becomes a living system, not a compliance filing cabinet.

Fast Time to Value

Enterprise GRC depth without the 18-month implementation. Up and running in weeks to months, on the technology stack you already have.

Minimal dependence on scarce specialists once you’re live.

Already running another GRC platform? Run LockThreat alongside it during transition, no rip-and-replace required.

What GRC Leaders Say

Compliance across multiple international standards used to be a serious resource drain. LockThreat unified everything into one platform and eliminated the spreadsheet chaos entirely. It’s been a game-changer for our team.

Director of Risk & Compliance
World’s Most Sustainable City

LockThreat gave our team a single pane of glass across every framework we manage. What used to take weeks of manual mapping now happens automatically. Our clients see faster results and our consultants can focus on higher-value work.

Managing Director
Big-4 Professional Services Firm

We evaluated a lot of GRC tools and nothing came close to LockThreat’s combination of breadth across governance, risk and compliance, combined with AI automation and ease of use. Our team was up and running quickly, and the cross-framework mapping alone saved us hundreds of hours.

VP of Security & Risk
CirrusLabs

The real-time evidence validation and risk dashboards gave our leadership team the visibility they needed without burdening our security team. LockThreat just works.

Head of GRC
Octave

LockThreat fits perfectly into an agile environment. Controls and policies evolve alongside our work. It’s not a static compliance checkbox, it’s a living system that keeps up with our pace.

VP of Security
Agile Trailblazers

Connects to Your Existing Stack

See LockThreat on Your Egyptian Frameworks

A focused 30-minute walkthrough, plus pricing for your deployment. No generic pitch, no obligation.

Tell us which regulators and frameworks you answer to (PDPL, CBE, FRA or NTRA) and how you want to deploy. We’ll tailor the session to your programme.

  1. A 30-minute walkthrough on your frameworks, following your priorities.
  2. Your deployment path: private cloud, on-premises in your data centre, or SaaS.
  3. Pricing for your scope, based on your entities, frameworks and deployment model.

Prefer email? info@lockthreat.com