Which framework should you start with?
Choose what describes you or where you operate. Matching guides light up. This is a starting point for orientation, not legal or audit advice.
Global
Frameworks buyers ask about in almost every market: attestation reports, international standards and industry rules.
SOC 2
The report enterprise buyers ask for first. Learn the five Trust Services Criteria, Type I vs Type II, and where penetration testing fits.
Read the guide →SOC 1
The report your customers' auditors ask for when you touch their financial data. Type I vs II, ITGCs, user entity controls, and how SOC 1 differs from SOC 2.
Read the guide →ISO 27001
The international standard for an information security management system. Clauses, the 93 Annex A controls, and how certification works.
Read the guide →PCI DSS
The payment card standard in plain English: the 12 requirements, SAQ vs ROC, and what Requirement 11.4 says about penetration testing.
Read the guide →Vendor & TPRM
How to pass vendor security reviews faster: questionnaires (SIG, CAIQ), evidence packs and the vendor risk lifecycle.
Read the guide →HIPAA
The Privacy, Security and Breach Notification Rules explained, with the three safeguard types and risk analysis expectations.
Read the guide →NIST CSF 2.0
Six functions, 22 categories and four tiers. A flexible way to organise and communicate your security programme.
Read the guide →Middle East
Saudi, UAE and wider Gulf cybersecurity and data protection requirements, from NCA controls to national privacy laws.
NCA ECC
The Saudi National Cybersecurity Authority baseline: four domains, what assessors look for, and the testing evidence that backs each control.
Read the guide →NCA CCC
The Saudi cloud security controls for providers and the organisations that use them. Who is in scope, what is tested and how it builds on ECC.
Read the guide →NCA DCC
The Saudi data cybersecurity controls: protecting data across its lifecycle, how they relate to ECC and what testing evidence supports them.
Read the guide →Saudi PDPL
Saudi Arabia’s PDPL in plain language: SDAIA oversight, transfer rules, breach notice and the security testing evidence that backs it up.
Read the guide →UAE PDPL
The UAE federal data protection law in plain language, with honest notes on its implementation status and how it sits beside DIFC and ADGM.
Read the guide →Oman PDPL
Oman’s data protection law in plain language: the 2026 enforcement date, 72-hour breach notice, DPO duties and testing evidence.
Read the guide →Qatar, Bahrain & Egypt
Three MENA privacy laws in one guide: Qatar PDPPL, Bahrain PDPL and Egypt’s Law 151, with status notes and testing evidence.
Read the guide →DIFC and ADGM
Data protection law and cyber expectations for firms in the Dubai International Financial Centre and Abu Dhabi Global Market, and how to prepare.
Read the guide →India
Data protection and sector cybersecurity expectations for organisations serving Indian customers and regulators.
India DPDP
India’s DPDP Act and Rules explained: consent, data fiduciary duties, Section 8(5) security safeguards and the penalty tiers.
Read the guide →SEBI CSCRF and RBI
What SEBI's CSCRF and the RBI's IT and cyber rules ask of regulated entities, banks and NBFCs, including VAPT and audit expectations.
Read the guide →Europe
EU regulation on privacy, operational resilience and product security, with the dates and duties that matter.
GDPR
Seven principles, six lawful bases and the 72-hour breach clock. See how Article 32 security testing fits your obligations.
Read the guide →DORA & NIS2
EU resilience rules for financial entities (DORA) and essential and important entities (NIS2): reporting clocks, TLPT and supplier risk.
Read the guide →EU Cyber Resilience Act
Security rules for every connected product sold in the EU: essential requirements, vulnerability handling, reporting clocks and support periods.
Read the guide →Asia-Pacific
Education, privacy and prudential requirements across Australia and New Zealand.
Australia Privacy Act
Australia’s privacy law: APP 11 security duties, the Notifiable Data Breaches scheme, the 2024 reforms, new penalties and what testing evidence helps.
Read the guide →APRA CPS 230 & CPS 234
APRA’s standards for banks, insurers and super funds: information security capability, critical operations, service provider risk and assurance.
Read the guide →ST4S
The security, privacy and safety assessment Australian and New Zealand education departments use for school technology. What it covers and how vendors prepare.
Read the guide →Frameworks side by side
Some are attestations, some are laws and some are buyer processes. Knowing which is which saves months.
| Framework | What it is | Region | Who usually needs it |
|---|---|---|---|
| SOC 2 | Security assurance | Global | SaaS and cloud platforms; Fintech and payments teams |
| SOC 1 | Security assurance | Global | Payments and billing providers; Payroll and HR outsourcers |
| ISO 27001 | Security assurance | Global | Companies selling internationally; Regulated and public-sector suppliers |
| PCI DSS | Payments | Global | Merchants taking card payments; Payment and platform providers |
| Vendor & TPRM | Third-party risk | Global | SaaS vendors selling to enterprise; Security and procurement teams |
| NCA ECC | Saudi Arabia | Middle East | Government bodies and their suppliers; Energy, utilities and telecoms |
| NCA CCC | Saudi Arabia | Middle East | Cloud and hosting providers; Government and regulated tenants |
| NCA DCC | Saudi Arabia | Middle East | Government entities and suppliers; Financial and payments firms |
| Saudi PDPL | Privacy law | Middle East | SaaS and cloud providers serving Saudi customers; Banks, fintechs and insurers |
| UAE PDPL | Privacy law | Middle East | Software and cloud companies in the UAE; Mainland businesses holding customer data |
| Oman PDPL | Privacy law | Middle East | Banks, insurers and fintechs in Oman; Telecom, energy and large enterprises |
| Qatar, Bahrain & Egypt | Privacy law | Middle East | Banks and fintechs; Software and cloud providers |
| DIFC and ADGM | Financial free zones | Middle East | Banks, asset managers and brokers; Fintechs and payments firms |
| India DPDP | Privacy law | India | Indian SaaS and consumer apps; Fintech and lending platforms |
| SEBI CSCRF and RBI | Financial regulation | India | Brokers, depository participants and asset managers; Exchanges, depositories and clearing bodies |
| GDPR | Privacy law | Europe | SaaS and online services; HR, recruiting and employers |
| DORA & NIS2 | EU regulation | Europe | Banks, insurers and fintechs; Cloud and software suppliers |
| EU Cyber Resilience Act | EU regulation | Europe | Software and app makers; Connected device manufacturers |
| HIPAA | Healthcare | Global | Digital health and telehealth; Cloud and SaaS for healthcare |
| NIST CSF 2.0 | Security frameworks | Global | Enterprises and boards; Technology and SaaS vendors |
| Australia Privacy Act | APAC privacy | Asia-Pacific | Businesses over A$3M turnover; Health and childcare providers |
| APRA CPS 230 & CPS 234 | APAC financial regulation | Asia-Pacific | Banks and authorised deposit-taking institutions; Insurers and superannuation funds |
| ST4S | Education sector | Asia-Pacific | Edtech and learning platforms; Student information and communication tools |
How to approach compliance without burning out
- 1
Know who is asking
Customers, regulators and procurement teams decide which frameworks matter. Start with the questionnaires and contract clauses you already receive.
- 2
Pick the smallest set that unlocks revenue
One well-scoped framework beats three half-finished ones. Choose the one blocking the most pipeline or the nearest deadline.
- 3
Test once, map many times
A single human-led penetration test can be mapped to several frameworks, so you do not pay for the same evidence twice.
- 4
Report to leadership in plain language
Boards and executives need risk, deadlines and owners, not control IDs. Keep a one-page view alongside the technical detail.
Why a single penetration test goes a long way
Penetration testing evidence supports SOC 2 monitoring criteria, ISO 27001 vulnerability controls, PCI DSS Requirement 11.4, GDPR Article 32, HIPAA risk analysis, NIST CSF, DORA testing and the Saudi NCA controls, along with most vendor questionnaires. Summit scopes one engagement and maps the findings to every control reference you need.
Framework basics
What is the difference between a framework, a standard and a regulation?
A framework is guidance you adopt voluntarily, such as NIST CSF. A standard such as ISO 27001 or PCI DSS defines requirements you can be assessed against. A regulation or law, such as GDPR, the Saudi PDPL or DORA, is binding on the organisations it covers. Buyers often ask for evidence against all three, so it helps to know which type you are dealing with.
Which framework should a startup begin with?
Start with whatever your first enterprise customers ask for. For many B2B SaaS companies that is SOC 2, for companies selling in Europe or the Middle East it is often ISO 27001, and privacy laws apply as soon as you handle personal data of people in a covered country. One well-scoped framework usually beats three half-finished ones.
Can one penetration test support several frameworks?
Yes. A scoped, human-led test with clear severity ratings and a retest can serve as technical evidence for several frameworks at once. Each requesting auditor, customer or regulator decides what they accept, so we map the same findings to the control references each one uses.
Do you cover Middle East and Gulf requirements?
Yes. The hub includes the Saudi NCA controls (ECC, CCC and DCC), the Saudi, UAE, Omani, Qatari, Bahraini and Egyptian data protection laws, and the DIFC and ADGM regimes, each with its own guide.
Are these guides legal advice?
No. They are educational summaries last reviewed in October 2026. Laws and standards change, so confirm current requirements with your auditor, counsel or regulator before committing to a plan.
How quickly can you scope an engagement?
Share your systems, your deadline and who is asking. We reply with a fixed-scope quote in 15 minutes, and most teams are testing within days once scope and authorisation are agreed.
Last reviewed October 2026.