Skip to content

Service 04

Compliance-readiness orientation

What ECC/CCC scope, NDMO classification, and PDPL controller–processor questions the buyer will ask — and who is qualified to answer them formally.

What you receive

An orientation note: the questions coming, in the order they arrive.

A Saudi government-linked buyer’s security team works from the NCA’s ECC-2:2024 and CCC-2:2024; its data owner works from NDMO classification; its DPO works from PDPL and the transfer regulation. Vendors who meet those questions unprepared stall for months.

We orient you: what each control set is, which questions land on a software vendor versus the provider, and where a formally qualified party must take over: an accredited auditor or Saudi-qualified counsel, explicitly not us.

Boundary

Cloudi Arabia is not an auditor or a law firm and issues no compliance opinion or certification.

Related: the Saudi cloud map · FAQ · use cases