
Service 04
Compliance-readiness orientation
What ECC/CCC scope, NDMO classification, and PDPL controller–processor questions the buyer will ask — and who is qualified to answer them formally.
What you receive
An orientation note: the questions coming, in the order they arrive.
A Saudi government-linked buyer’s security team works from the NCA’s ECC-2:2024 and CCC-2:2024; its data owner works from NDMO classification; its DPO works from PDPL and the transfer regulation. Vendors who meet those questions unprepared stall for months.
We orient you: what each control set is, which questions land on a software vendor versus the provider, and where a formally qualified party must take over: an accredited auditor or Saudi-qualified counsel, explicitly not us.
Boundary
Cloudi Arabia is not an auditor or a law firm and issues no compliance opinion or certification.
Related: the Saudi cloud map · FAQ · use cases