Skip to main content
Frameworks · Learn · Prepare

Every framework your buyers ask about, explained and tested.

Twenty-three plain-English guides to the security and privacy frameworks behind your questionnaires, audits and contracts, each with a clear view of the business risk and where penetration testing evidence fits.

23
framework guides, each with FAQs and a roadmap
5
regions covered: global, Middle East, India, Europe and Asia-Pacific
1
evidence-ready penetration test can serve many of them
15 min
to a fixed-scope quote for your engagement
Find your starting point

Which framework should you start with?

Choose what describes you or where you operate. Matching guides light up. This is a starting point for orientation, not legal or audit advice.

Middle East

Saudi, UAE and wider Gulf cybersecurity and data protection requirements, from NCA controls to national privacy laws.

Compare

Frameworks side by side

Some are attestations, some are laws and some are buyer processes. Knowing which is which saves months.

FrameworkWhat it isRegionWho usually needs it
SOC 2Security assuranceGlobalSaaS and cloud platforms; Fintech and payments teams
SOC 1Security assuranceGlobalPayments and billing providers; Payroll and HR outsourcers
ISO 27001Security assuranceGlobalCompanies selling internationally; Regulated and public-sector suppliers
PCI DSSPaymentsGlobalMerchants taking card payments; Payment and platform providers
Vendor & TPRMThird-party riskGlobalSaaS vendors selling to enterprise; Security and procurement teams
NCA ECCSaudi ArabiaMiddle EastGovernment bodies and their suppliers; Energy, utilities and telecoms
NCA CCCSaudi ArabiaMiddle EastCloud and hosting providers; Government and regulated tenants
NCA DCCSaudi ArabiaMiddle EastGovernment entities and suppliers; Financial and payments firms
Saudi PDPLPrivacy lawMiddle EastSaaS and cloud providers serving Saudi customers; Banks, fintechs and insurers
UAE PDPLPrivacy lawMiddle EastSoftware and cloud companies in the UAE; Mainland businesses holding customer data
Oman PDPLPrivacy lawMiddle EastBanks, insurers and fintechs in Oman; Telecom, energy and large enterprises
Qatar, Bahrain & EgyptPrivacy lawMiddle EastBanks and fintechs; Software and cloud providers
DIFC and ADGMFinancial free zonesMiddle EastBanks, asset managers and brokers; Fintechs and payments firms
India DPDPPrivacy lawIndiaIndian SaaS and consumer apps; Fintech and lending platforms
SEBI CSCRF and RBIFinancial regulationIndiaBrokers, depository participants and asset managers; Exchanges, depositories and clearing bodies
GDPRPrivacy lawEuropeSaaS and online services; HR, recruiting and employers
DORA & NIS2EU regulationEuropeBanks, insurers and fintechs; Cloud and software suppliers
EU Cyber Resilience ActEU regulationEuropeSoftware and app makers; Connected device manufacturers
HIPAAHealthcareGlobalDigital health and telehealth; Cloud and SaaS for healthcare
NIST CSF 2.0Security frameworksGlobalEnterprises and boards; Technology and SaaS vendors
Australia Privacy ActAPAC privacyAsia-PacificBusinesses over A$3M turnover; Health and childcare providers
APRA CPS 230 & CPS 234APAC financial regulationAsia-PacificBanks and authorised deposit-taking institutions; Insurers and superannuation funds
ST4SEducation sectorAsia-PacificEdtech and learning platforms; Student information and communication tools
Strategy

How to approach compliance without burning out

  1. 1

    Know who is asking

    Customers, regulators and procurement teams decide which frameworks matter. Start with the questionnaires and contract clauses you already receive.

  2. 2

    Pick the smallest set that unlocks revenue

    One well-scoped framework beats three half-finished ones. Choose the one blocking the most pipeline or the nearest deadline.

  3. 3

    Test once, map many times

    A single human-led penetration test can be mapped to several frameworks, so you do not pay for the same evidence twice.

  4. 4

    Report to leadership in plain language

    Boards and executives need risk, deadlines and owners, not control IDs. Keep a one-page view alongside the technical detail.

One test, many frameworks

Why a single penetration test goes a long way

Penetration testing evidence supports SOC 2 monitoring criteria, ISO 27001 vulnerability controls, PCI DSS Requirement 11.4, GDPR Article 32, HIPAA risk analysis, NIST CSF, DORA testing and the Saudi NCA controls, along with most vendor questionnaires. Summit scopes one engagement and maps the findings to every control reference you need.

FAQ

Framework basics

What is the difference between a framework, a standard and a regulation?

A framework is guidance you adopt voluntarily, such as NIST CSF. A standard such as ISO 27001 or PCI DSS defines requirements you can be assessed against. A regulation or law, such as GDPR, the Saudi PDPL or DORA, is binding on the organisations it covers. Buyers often ask for evidence against all three, so it helps to know which type you are dealing with.

Which framework should a startup begin with?

Start with whatever your first enterprise customers ask for. For many B2B SaaS companies that is SOC 2, for companies selling in Europe or the Middle East it is often ISO 27001, and privacy laws apply as soon as you handle personal data of people in a covered country. One well-scoped framework usually beats three half-finished ones.

Can one penetration test support several frameworks?

Yes. A scoped, human-led test with clear severity ratings and a retest can serve as technical evidence for several frameworks at once. Each requesting auditor, customer or regulator decides what they accept, so we map the same findings to the control references each one uses.

Do you cover Middle East and Gulf requirements?

Yes. The hub includes the Saudi NCA controls (ECC, CCC and DCC), the Saudi, UAE, Omani, Qatari, Bahraini and Egyptian data protection laws, and the DIFC and ADGM regimes, each with its own guide.

Are these guides legal advice?

No. They are educational summaries last reviewed in October 2026. Laws and standards change, so confirm current requirements with your auditor, counsel or regulator before committing to a plan.

How quickly can you scope an engagement?

Share your systems, your deadline and who is asking. We reply with a fixed-scope quote in 15 minutes, and most teams are testing within days once scope and authorisation are agreed.

Last reviewed October 2026.

Not sure which one you need?

Tell us who is asking and by when. We will point you to the right evidence and quote it in 15 minutes.

Get a Quote in 15 mins →