By sector · Where the obligation actually bites

Compliance is not generic, so the starting point should not be either.

The obligations that matter, and the order in which they matter, depend on the sector you operate in and who supervises it. These pages set out what we see in each sector, what changes when the work is organised properly, and the specific trap that costs the most to discover late.

Banking and financial services

Overlapping supervisory expectations, a permanent audit cycle, and evidence gathered by hand every quarter.

CBUAE · SAMA CSF · NESA · ISO 27001 · UAE PDPL · SOC 2
Read the sector view →
Healthcare

Clinical data raises the bar on every control, and the entity classification decides how far that bar moves.

ADHICS · ISO 27001 · UAE PDPL · NESA
Read the sector view →
Government and public sector

National assurance expectations, information classification, and suppliers pulled into scope by contract.

Dubai ISR · NESA · NCA ECC · Qatar NIA · Oman IA
Read the sector view →
Technology and SaaS
In preparation

Enterprise procurement asks for a certificate before it asks about your product.

SOC 2 · ISO 27001 · GDPR · UAE PDPL
Read the sector view →
Your sector is not listed?

The regimes overlap more than the sector labels suggest, and an assessment establishes which obligations are genuinely in scope before anyone commits budget to closing them.

Establish your position →