NCA. SAMA.
PDPL. CMA. One GRC Platform.

Governance, risk and compliance on one control library for government, banks, capital markets and energy. Hosted in the Kingdom, in your private cloud or on-premises.

Already in use with regulated organisations in the region · Live in weeks to months

One Kingdom. Many Regulators. One View.

A bank in Riyadh answers to SAMA, the National Cybersecurity Authority and SDAIA. A listed company adds the Capital Market Authority. An energy group adds NCA controls for its operational technology and oversight of a large contractor network.

As Vision 2030 accelerates, each regulator publishes its own controls, templates and reporting cycle, and the NCA now has penalty powers over private-sector entities. Most teams still reconcile it all in spreadsheets. Keep your advisors; give them one platform to work from.

LockThreat maps your obligations once, tests your controls continuously, and gives your board one current view of risk across the Kingdom.

The Bar Has Been Raised.

14 Sep 2024
PDPL Fully Enforceable
Fines up to SAR 5 million, which can double for repeat violations.
17 Oct 2024
NCA ECC-2:2024
An updated cyber baseline for government and critical infrastructure.
22 Dec 2024
NCA Penalty Powers
Royal decree lets the NCA fine private entities up to SAR 25 million.
28 Dec 2025
Private-Sector Controls
NCA controls now reach companies outside critical infrastructure.
Jan 2026
PDPL Enforcement Under Way
SDAIA committees report 48 violation decisions in a year.

Built for the Kingdom’s Most Regulated Sectors

Government & CNI

NCA ECC-2:2024, CSCC and cloud controls, with on-premises options.

Banks & Fintech

SAMA cyber, IT governance, BCM and counter-fraud frameworks.

Capital Markets

CMA cybersecurity guidelines and corporate governance rules.

Healthcare

PDPL sensitive-data duties for hospitals, labs and health-tech.

Energy, Utilities & Giga-Projects

NCA OT controls and contractor risk at scale.

Large Private Companies

NCA’s new private-sector controls and PDPL, group-wide.

Spreadsheets and IT-Only Tools Leave agap
Regulators Will Find.

Legacy Enterprise
GRC
Compliance-First Tools
LockThreat
Saudi Frameworks
Custom build
Limited KSA depth
NCA, SAMA, PDPL, CMA
GRC Depth
Full G+R+C
Compliance only
Full G+R+C
Deployment
Complex to configure
Typically SaaS only
In-Kingdom SaaS, cloud, on-prem
Multi-Regulator Mapping
Consultant-heavy
IT controls only
Test once, map across regulators
Continuous Monitoring
Limited or none
IT & cyber only
Enterprise-wide
AI Governance
Separate add-on
Limited
Built-in, incl. agentic AI
Time to Value
12–18 months
Weeks, compliance only
Weeks to months
Saudi Frameworks
Legacy Enterprise GRC
Custom build
Compliance-First Tools
Limited KSA depth
LockThreat
NCA, SAMA, PDPL, CMA
GRC Depth
Legacy Enterprise GRC
Full G+R+C
Compliance-First Tools
Compliance only
LockThreat
Full G+R+C
Deployment
Legacy Enterprise GRC
Complex to configure
Compliance-First Tools
Typically SaaS only
LockThreat
In-Kingdom SaaS, cloud, on-prem
Multi-Regulator Mapping
Legacy Enterprise GRC
Consultant-heavy
Compliance-First Tools
IT controls only
LockThreat
Test once, map across regulators
Continuous Monitoring
Legacy Enterprise GRC
Limited or none
Compliance-First Tools
IT & cyber only
LockThreat
Enterprise-wide
AI Governance
Legacy Enterprise GRC
Separate add-on
Compliance-First Tools
Limited
LockThreat
Built-in, incl. agentic AI
Time to Value
Legacy Enterprise GRC
12–18 months
Compliance-First Tools
Weeks, compliance only
LockThreat
Weeks to months

Frameworks for Saudi Arabia

Mapped to one control library, so a control tested once serves every framework it supports. Tracking something not listed? Ask us.

Categories
No frameworks match your search.

National Cybersecurity (NCA & CST)

NCA Essential Cybersecurity Controls (ECC-2:2024)
NCA Critical Systems Cybersecurity Controls (CSCC)
NCA Cloud Cybersecurity Controls (CCC-2:2024)
NCA Operational Technology Cybersecurity Controls (OTCC)
NCA Data Cybersecurity Controls (DCC)
NCA Telework Cybersecurity Controls (TCC)
NCA Non-CNI Private Sector Entities Cybersecurity Controls (NCNICC-1:2025)
CST Cybersecurity Regulatory Framework for ICT Service Providers

Data Protection & Data Governance

Personal Data Protection Law (PDPL) & Implementing Regulation
Regulation on Personal Data Transfer outside the Kingdom
Rules for Appointing a Personal Data Protection Officer
NDMO Data Management & Personal Data Protection Standards
Cloud First Policy (MCIT)
CST Cloud Computing Services Provisioning Regulations

Banking & Fintech (SAMA)

SAMA Cyber Security Framework
SAMA Information Technology Governance Framework
SAMA Business Continuity Management Framework
SAMA Counter-Fraud Framework
SAMA Rules on Outsourcing
SAMA Cyber Resilience Fundamental Requirements
SAMA Open Banking Framework
PCI DSS
SWIFT Customer Security Programme

Capital Markets & Governance

CMA Cybersecurity Guidelines for Capital Market Institutions
CMA Corporate Governance Regulations
Companies Law (2022)
ISO 31000
COSO (Committee of Sponsoring Organizations)

Global Standards

ISO 27001:2022
ISO 22301
ISO/IEC 27701
NIST CSF 2.0

AI Governance

SDAIA AI Ethics Principles
SDAIA Generative AI Guidelines
SDAIA AI Adoption Framework
ISO/IEC 42001 (AI Management System)
NIST AI Risk Management Framework (NIST AI RMF)
The Risk Nobody’s Governing

Your teams are already using AI on customer and citizen data. Under the PDPL, you’re accountable for it. Do you know which AI tools and agents are breaching your controls?

AI Security & Governance Flow

Your Data. In the Kingdom.

Saudi rules keep sensitive data close to home: the Cloud First Policy keeps government cloud data inside the Kingdom, and PDPL transfer rules set a high bar for sending personal data abroad.

Choose how LockThreat runs: managed SaaS hosted in the Kingdom, your own private cloud, or on-premises in your data centre. The same full G+R+C depth, regardless of deployment.

SaaS
Managed by us. Hosted in the Kingdom.
Private Cloud
Your cloud. Your boundary.
On-Premises
Fully within your walls.

One Platform for the Whole Buying Committee

Blue shield icon with a white award ribbon symbol featuring a star in the center.Vertical flowchart with four outlined circles connected by dotted lines in dark blue, beige, and light blue colors.
CISO
  • One evidence trail for NCA assessments, SAMA reviews and CMA requirements.
  • Third-party and contractor risk tracked alongside your own controls.
Line drawing of a human head and upper torso facing forward with a large dark blue dot near the brain area and a smaller bright blue dot near the upper chest.
Chief Risk & Compliance Officer
  • Risk quantified in financial terms with FAIR modelling and Monte Carlo simulation.
  • Policies and gap analysis generated against the frameworks you answer to.
Line art icon with a stylized head and shoulders and three floating dots above representing communication or connection.
Data Protection Officer
  • PDPL, transfer rules and DPO duties mapped to controls, with the 72-hour breach clock tracked.
  • Visibility of AI tools handling personal data.
Two overlapping blue circles connected by a black diagonal line on a white background.
Chief Audit Executive
  • Continuous control testing instead of periodic sampling.
  • Board and committee reporting drawn from live data, not spreadsheets.
Outline of a person’s head and shoulders with a blue circle above representing the mind or focus.

Everything Enterprise GRC Should Have Been.

True GRC Depth

Most GRC tools deliver compliance, with governance and risk as an afterthought.

Here, governance comes first: the policies that move your organisation forward, the controls that contain risk across every department, and the compliance that follows naturally from both.

No spreadsheets. No disconnected tools. No point-in-time snapshots. One centralised, ongoing view of your risk and compliance posture.

GRC for Everyone

Your regulatory obligations don’t respect org charts or borders.

Every department, from finance, legal and HR to operations, cyber and IT, managed in one place, without the sprawl.

The sites you operate in, from Riyadh, Jeddah and Dammam to NEOM and your offices across the GCC, managed in one place without adding more tools.

AI Governance & Security

Which AI tools are your employees using? Are they approved? Are they handling personal data they shouldn’t under the PDPL?

And when AI agents act autonomously, accessing systems, making decisions, breaching controls, who’s watching? Now you are.

From shadow AI discovery and ISO/IEC 42001 alignment to real-time prompt protection and agentic control enforcement, reported directly into your GRC framework.

Risk Clarity

Every stakeholder needs a different view of the same risk reality, from one source of truth.

Express risk in financial terms your board and CFO can act on, using FAIR modelling and Monte Carlo simulation.

Detailed enough for the analyst, clear enough for the Chief Risk Officer and the CISO, compelling enough for the board.

Continuous Assurance

Compliance isn’t an annual exercise; it’s an ongoing operating requirement.

LockThreat validates that your controls are working, right now, across cloud infrastructure, cyber endpoints and enterprise applications.

Far less scrambling for evidence before an NCA assessment, a SAMA review or a CMA inspection.

Framework Convergence

Map NCA ECC-2, SAMA CSF, PDPL and the CMA guidelines to ISO 27001, NIST and SOC 2, and to each other, eliminating redundant work.

Tie everything to your own policy library and control framework, so governance becomes a living system, not a compliance filing cabinet.

Fast Time to Value

Enterprise GRC depth without the 18-month implementation. Up and running in weeks to months, on the technology stack you already have.

Implemented and supported by our in-region team and partners.

Already running another GRC platform? Run LockThreat alongside it during transition, no rip-and-replace required.

What GRC Leaders Say

Compliance across multiple international standards used to be a serious resource drain. LockThreat unified everything into one platform and eliminated the spreadsheet chaos entirely. It’s been a game-changer for our team.

Director of Risk & Compliance
World’s Most Sustainable City

LockThreat gave our team a single pane of glass across every framework we manage. What used to take weeks of manual mapping now happens automatically. Our clients see faster results and our consultants can focus on higher-value work.

Managing Director
Big-4 Professional Services Firm

We evaluated a lot of GRC tools and nothing came close to LockThreat’s combination of breadth across governance, risk and compliance, combined with AI automation and ease of use. Our team was up and running quickly, and the cross-framework mapping alone saved us hundreds of hours.

VP of Security & Risk
CirrusLabs

The real-time evidence validation and risk dashboards gave our leadership team the visibility they needed without burdening our security team. LockThreat just works.

Head of GRC
Octave

LockThreat fits perfectly into an agile environment. Controls and policies evolve alongside our work. It’s not a static compliance checkbox, it’s a living system that keeps up with our pace.

VP of Security
Agile Trailblazers

Connects to Your Existing Stack

See LockThreat on Your Saudi Frameworks

A focused 30-minute walkthrough, plus pricing for your deployment. No generic pitch, no obligation.

Tell us which regulators and frameworks you answer to (NCA, SAMA, PDPL, CMA or CST) and how you need to deploy. We’ll tailor the session to your programme.

  1. A 30-minute walkthrough on your frameworks, following your priorities.
  2. Your deployment path: SaaS hosted in the Kingdom, private cloud or on-premises.
  3. Pricing for your scope, based on your entities, frameworks and deployment model.

Delivered by our in-region team and partners. Prefer email? info@lockthreat.com