Select a market on the map to open its regulatory dossier.
The Gulf's benchmark regulatory environment: seven governing bodies, a federal data-protection law, and sector standards spanning government, banking and healthcare.
Federal coordinating body (2020). Sets national policy via the NCSS 2025–2031, coordinates incident response.
Owns the UAE Information Assurance Standard — the federal baseline for CNI and government entities.
Federal telecoms & digital-government regulator; expanding focus on data localisation and cloud guidance.
Emirate regulator for Dubai. Owns the ISR, mandatory for Dubai Government entities and key suppliers.
Federal financial regulator. Cybersecurity Framework for all licensed banks, financiers, and payment providers.
Emirate healthcare regulator. Owns ADHICS, mandatory for all DOH-regulated healthcare entities.
Established under the PDPL to oversee data-protection compliance and enforcement across every sector.
NESA's UAE Information Assurance Standard is mandatory for government entities and Critical National Infrastructure across energy, water, transport, banking and telecoms — and is widely adopted as a de-facto baseline by private suppliers to these entities.
Management domains M1–M6 (Strategy & Planning, Risk Management, Awareness & Training, HR Security, Compliance, Performance Evaluation) plus risk-based Technical domains T1–T9 (Asset Management, Physical & Environmental Security, Operations, Communications, Access Control, Third-Party Security, Systems Acquisition/Dev/Maintenance, Incident Management, Continuity Management). No standalone NESA penalty schedule is published — enforcement runs through regulatory scrutiny. NCAP, rolling out through 2026, will restrict which providers may serve Critical Information Infrastructure.
Federal Decree-Law No. 45 of 2021 — the closest the UAE has to a universal cybersecurity-adjacent obligation. Applies to any organization processing the personal data of UAE residents, regardless of sector, alongside every framework in this briefing. Requires technical/organizational safeguards, DPIAs for higher-risk processing, data classification and breach-notification procedures, and respect for data-subject rights. Health data is treated as especially sensitive — effectively required to stay within UAE borders absent special provisions. Enforced by the UAE Data Office, with fines reported up to AED 5,000,000 per violation.
Control overlap between NESA, DESC, ADHICS and the PDPL is substantial — organizations subject to more than one framework typically run a unified compliance programme rather than parallel ones.
Mandatory for Dubai Government Entities, semi-government bodies, cloud providers, data-centre operators, managed SOC providers, and key suppliers handling government data. 13 domains across Governance, Operation and Assurance — including Cloud & IoT/ICS Security. Enforcement runs through procurement and contract consequences (removal from government procurement lists, contract termination) rather than a published fine schedule; assessments can be announced or unannounced.
Issued by the Central Bank for all CBUAE-licensed institutions — banks, exchange houses, finance companies, insurers, and stored-value/payment providers. Federal Decree-Law No. 6 of 2025 extends CBUAE's perimeter to fintechs and payment-technology providers. SMS OTPs are being retired — stronger authentication required by 31 March 2026 — alongside 24/7 behavioural-biometric fraud monitoring and board-level governance with red-team exercises for systemically important banks. ISO 27001-certified organizations reportedly have 40–60% of controls already in place, though a dedicated gap assessment is still required.
Issued by the Department of Health, Abu Dhabi (2019) — the only fully public standard in this set. Mandatory for all DOH-regulated healthcare entities (hospitals, clinics, labs, pharmacies, insurers) and every healthcare professional with access to patient information. Three compliance tiers: Basic (minimum essential, 6 months), Transitional (risk-based, 1 year), and Advanced (higher-acuity, 21+ bed hospitals), across 11 domains including Health Information and Security. DOH can impose fines, licence suspension or revocation, and mandatory corrective action plans, tied directly to healthcare-facility licensing.
A full, section-by-section deep-dive on the UAE's regulatory landscape is also published as its own dedicated deck.
Every jurisdiction on this map maps to the same control intent — Kerberogate lets you assess it once and report it everywhere your business operates.
The region's most centralized cyber-governance model: a King-mandated national authority, a dedicated data-protection regulator, and sector-specific frameworks for finance and telecom.
Saudi Arabia runs a centralized cyber-governance model anchored by the NCA, with SDAIA, SAMA and CST retaining sector jurisdiction.
Reports directly to the King. Sets national strategy and issues the binding Essential Cybersecurity Controls (ECC) and Critical Systems Cybersecurity Controls (CSCC); oversees critical-infrastructure protection and incident response.
Primary enforcing authority for the Personal Data Protection Law (PDPL) — issues implementing regulations, licensing and enforcement guidance.
Issues and enforces the Cybersecurity Framework (CSF) for banks, insurers/reinsurers, finance companies, credit bureaus and financial market infrastructure.
Formerly CITC. Telecom/ICT/space regulator; issues its own Cybersecurity Regulatory Framework and retains PDPL jurisdiction over telecom operators.
114 controls across 29 subdomains — mandatory for government entities and critical-infrastructure operators. The Critical Systems Cybersecurity Controls (CSCC) layer 32 additional controls on top for systems designated as critical, with ECC compliance as a prerequisite.
Royal Decree M/19 (2021), amended by Royal Decree M/148 (2023). Enforced by SDAIA. Consent is the primary lawful basis; cross-border transfers require adequate safeguards under a dedicated Cross-Border Data Transfer Regulation; a Data Protection Officer is mandatory for public entities and high-risk/large-scale processors. The transition period ended 14 September 2024 — the law is now in full effect, with fines commonly cited up to SAR 5,000,000 (higher for sensitive-data violations, and courts may double penalties on repeat offenses).
A principle- and risk-based framework across four domains — governance & leadership, risk management & compliance, operations & technology, and third-party security — with maturity-level self-assessment. Mandatory for all SAMA-regulated banks, insurers, finance companies and financial market infrastructure.
2025–2026 outlook: SDAIA has moved into active enforcement, including asserting reach over foreign entities that process Saudi residents' data from outside the Kingdom.
Cloud, healthcare, telecom and critical infrastructure each carry their own NCA- or sector-regulator-issued control set layered on top of the ECC baseline.
NCA's Cloud Cybersecurity Controls (CCC–2:2024, revised July 2025 for data-localization changes) set a minimum baseline for cloud providers and tenants. Separately, CST's Cloud Computing Regulatory Framework tiers providers into registration categories by data sensitivity — government data must sit on in-Kingdom, CST-registered infrastructure; private-sector data faces lighter residency rules.
NCA's Operational Technology Cybersecurity Controls (OTCC) apply alongside ECC/CSCC for industrial control systems, extending the same governance/defense/resilience structure into OT environments.
The National Health Information Center publishes the Saudi eHealth Security & Privacy Standards (IS0101); the Ministry of Health runs its own Data Governance Policy. Health data is separately treated as a special category under the PDPL, requiring heightened safeguards.
CST's Cybersecurity Regulatory Framework applies baseline and enhanced controls to telecom operators, with specific guidance for entities designated Critical National Infrastructure.
A dedicated Regulation on Personal Data Transfer Outside the Kingdom, with follow-up Risk Assessment Guidelines clarifying transfer-impact-assessment requirements, governs when Saudi personal data can leave the country — layered on top of the PDPL's general adequacy/consent basis.
SDAIA's enforcement committees issued roughly 48 formal decisions in 2025 — the first substantial wave of PDPL adjudications — concentrated in retail, telecom and fintech, citing processing without lawful basis, inadequate privacy notices, unauthorized disclosure, weak security controls and unconsented marketing.
NCA revised both CSCC (June 2025) and CCC (July 2025) in the same window, pointing to an active annual refresh cycle across the control family rather than a static rulebook — a market where the control set itself is a moving target year over year.
Every jurisdiction on this map maps to the same control intent — Kerberogate lets you assess it once and report it everywhere your business operates.
A ministry-led cyber model undergoing rapid change: a new Financial Services Authority since 2024, and a Personal Data Protection Law that only reached full enforcement in 2026.
Oman's cyber governance sits inside a government ministry rather than a standalone authority — and 2024 brought a major financial-regulator restructure.
Houses national cyber governance operationally through Oman National CERT (OCERT), and is the designated enforcing authority for the Personal Data Protection Law.
Established by Royal Decree 20/2024 (in force 25 March 2024), replacing the Capital Market Authority (CMA) and absorbing its functions plus oversight of accounting/auditing professions.
Regulates banks, finance/leasing companies, payment service providers and money-exchange firms, including cyber-risk requirements under its Cyber Security & Risk Framework (CS&RF).
Unlike the UAE's TDRA, Oman's TRA retains its original name and telecom-sector remit.
Applies to banks, financing/leasing companies, payment service providers and money-exchange companies, issued as global attacks on financial institutions accelerated.
Royal Decree No. 6/2022, with Executive Regulations issued in February 2024. The transition period ended 5 February 2026 — MTCIT now actively supervises and enforces. Requires explicit, informed consent; cross-border transfer needs data-subject consent and must not conflict with national interests; a Data Protection Officer with published contact details is mandatory; data subjects get a 45-day response window; breaches must be notified within 72 hours. Ministry-level administrative fines run up to OMR 2,000 per violation, while courts may impose penalties from OMR 500 up to OMR 500,000 for the most serious breaches.
With full PDPL enforcement only beginning in February 2026 and the FSA still bedding in after its 2024 restructure, Oman's regulatory architecture is younger and more actively evolving than its Gulf neighbors — a market where compliance programs are being built now, not retrofitted.
Oman's cyber governance runs through OCERT operationally, with TRA layering telecom-specific rules and a fresh national strategy setting the horizon to 2030.
Five pillars: cybersecurity governance, cyber resilience, capacity building & awareness, cyber cooperation, and cyber economy — tied explicitly to Oman Vision 2040, and led operationally by the Cyber Defence Centre established under Royal Decree 64/2020.
Oman National CERT, housed within MTCIT, issues threat advisories, incident-response support and best-practice guidance across sectors, and is the operational face of national cyber governance.
TRA requires secure-communications controls and incident reporting from licensed telecom operators, and has issued newer cloud/data-centre rules for licensees. The Electronic Transactions Law (Royal Decree 69/2008) underpins e-signature and online-transaction validity.
Oman was ranked #1 among Arab states in the ITU's 2024 Global Cybersecurity Index — a signal of institutional momentum even as several of its individual frameworks (OCERT incident-reporting windows, a dedicated healthcare cyber rule) remain less codified than in neighboring Gulf states.
Licensed institutions — banks including foreign branches, money-exchange companies, payment service providers, and finance/leasing companies — faced a 31 July 2024 deadline to meet the Cyber Security & Risk Framework. Institutions unable to meet a given control must submit justification and compensating controls for CBO approval, and CBO reserves the right to periodically review and update requirements.
Royal Decree 20/2024 folded the former Capital Market Authority into the new Financial Services Authority, adding insurance regulation to its remit. The FSA has carried forward CMA's prior regulatory and legislative role for capital markets while it builds out a fully independent post-restructure regulatory identity.
PDPL penalties run on a two-tier model: administrative fines capped at OMR 2,000 per violation for ministry-level breaches, escalating to court-imposed penalties up to OMR 500,000 for the most serious cases — with specific Article 19 breach-notification failures cited at the OMR 15,000–20,000 level in practitioner guidance.
Every jurisdiction on this map maps to the same control intent — Kerberogate lets you assess it once and report it everywhere your business operates.
A single national agency running both cybersecurity policy and data-protection enforcement — with a live enforcement track record and a freshly launched 2024–2030 national strategy.
Qatar concentrates cyber authority in the NCSA, which also administers the country's data-protection regime.
Qatar's central cybersecurity authority — sets national strategy, issues regulations and guidelines, and licenses cybersecurity service providers.
The NCSA unit that administers and enforces the Personal Data Privacy Protection Law.
Issues binding technology-risk and cybersecurity regulations for banks, insurers and payment service providers.
Qatar's baseline national control framework, organized around roughly 26 domains of procedural and technological controls, guided by Business Impact Assessment, with baseline and recommended control tiers referencing ISO 27001 and PCI DSS practice.
Implementing guidelines followed in January 2021. Enforced by the NCGAA. Requires explicit consent, with special provisions for minors; cross-border transfer is generally permitted unless it breaches the law or causes serious harm — there is no blanket localization mandate. Fines commonly cited in the QAR 1,000,000–5,000,000 range depending on the article violated.
The Insurance Sector Cyber Security Regulation runs 10 domains — from organizational cyber security and HR through risk management, business continuity, IT operations and business applications. A parallel Technology Risks Regulation covers banks, and a 2022 regulation covers payment service providers.
The NCGAA has issued three binding enforcement decisions since December 2024 — covering unauthorized processing, a breach investigation, and safeguard failures — each ordering remediation within a fixed window, none with a disclosed fine amount. Qatar's National Cybersecurity Strategy 2024–2030 (launched September 2024) added a fifth pillar for international cooperation, and NCSA partnered with ISASecure in 2025 to push OT/industrial security (ISA/IEC 62443) adoption.
Qatar Central Bank runs the deepest sector-specific control set, and the Qatar Financial Centre operates an entirely separate, GDPR-aligned data-protection regime for QFC-licensed entities.
A Technology Risks Regulation for banks (2018) and a dedicated Information & Cyber Security Regulation for payment service providers (2022) set QCB's baseline; a new Regulatory Framework for Digital Banks followed in December 2024.
A wholly separate regime from the national PDPPL, run by the Qatar Financial Centre Regulatory Authority (QFCRA) — Version 2, dated August 2021, explicitly brought in line with GDPR. Applies only to entities registered and licensed within the QFC free zone; mainland Qatari entities fall under NCGAA/PDPPL instead.
Qatar's National Information Assurance Policy requires mandatory annual third-party compliance audits for government entities — functioning as a de facto certification regime even without a standalone national cybersecurity certification scheme.
Amends the 2014 Cybercrime Law, adding Article 8(bis) criminalizing unauthorized publication or circulation of personal images/videos without consent — published in the Official Gazette 4 August 2025 and effective immediately, with penalties of up to one year's imprisonment and/or a fine up to QAR 100,000. NCGAA is named as the enforcement body.
The practical compliance implication for multinationals: an entity operating both on the Qatari mainland and inside the QFC free zone must run two separate data-protection compliance tracks — PDPPL/NCGAA for the former, QFCRA's Data Protection Regulations for the latter — rather than a single unified Qatari regime.
Compared to its Gulf neighbors, Qatar's combination of a live enforcement record (three binding decisions since Dec 2024), a freshly amended cybercrime statute, and a distinct free-zone data-protection regime makes it one of the more procedurally active — if structurally fragmented — markets in the bloc.
Every jurisdiction on this map maps to the same control intent — Kerberogate lets you assess it once and report it everywhere your business operates.
A newly centralized cyber authority (2025) layered onto a mature, if modestly penalized, data-protection law — and a Tier 1 ITU cybersecurity ranking.
A July 2025 Royal Decree transformed Bahrain's National Cyber Security Center from a Ministry-of-Interior unit into the Kingdom's central, binding cyber authority.
Empowered by Royal Decree No. 17 of 2025 as Bahrain's central cybersecurity authority under the Supreme Defence Council. Drafts legislation, issues binding national standards, regulates every critical sector, coordinates incident response, and certifies cybersecurity tools for critical-sector use.
Established under Law No. 30 of 2018; its functions currently sit within the Ministry of Justice, Islamic Affairs and Awqaf pending full institutional independence.
Issues binding Rulebook modules with dedicated cyber-security and outsourcing chapters across banking, insurance and investment-business volumes.
Structured around governance, a five-phase risk-management methodology, and iterative implementation — explicitly aligned with ISO/IEC 27005 and built on a CIS Controls v8 baseline. Bahrain was rated Tier 1 in the ITU's 2024 Global Cybersecurity Index, scoring near-perfect across four of five pillars.
Law No. 30 of 2018, effective 1 August 2019, with ten supplementary Ministerial Resolutions issued in March 2022 adding a 72-hour breach-notification duty, an 83-country transfer adequacy list, and Data Protection Guardian (DPO) registration requirements. Penalties follow a criminal model: up to 1 year imprisonment and/or a fine of BD 1,000–20,000 — modest compared to GDPR-style regimes, and no confirmed public enforcement action has been reported to date.
Requires board-level accountability, prior CBB approval for material outsourcing, mandatory encryption with licensee-held keys, contractual audit-access rights, tested business-continuity plans, and explicit acceptance of ISO 27001, SOC reports and PCI DSS as third-party assurance evidence.
A parallel May 2025 amendment to the Penal Code specifically criminalizes theft of electronic devices with intent to access data, layered on the existing 2014 IT Crimes Law — part of a broader pattern of Bahrain tightening cyber-related statutes even as its core PDPL penalty ceiling remains modest.
The Central Bank of Bahrain runs the region's most granular by-licensee-type cyber rulebook — a separate module for conventional banks, Islamic banks, insurers, specialised licensees and crypto-asset providers.
Conventional and Islamic banks each carry their own Operational Risk module cybersecurity chapter, kept in step through periodic reissue (Volume 2 most recently updated 2024).
A dedicated Risk Management module chapter applies the same cyber-governance expectations to insurers and reinsurers.
The 2024 edition of the Crypto-Asset module extends cyber requirements to licensed crypto-asset service providers — a rare Gulf regulator to codify this explicitly.
CBB has run a fintech regulatory sandbox since roughly 2017, letting firms trial products under relaxed licensing before full authorization — cybersecurity and Operational Risk module obligations apply in full once a firm exits the sandbox into standard licensing.
Beyond drafting legislation and issuing binding standards, Royal Decree 17/2025 gives the NCSC authority to certify cybersecurity tools for use in Bahrain's designated Critical Sectors — government, financial services, telecom/ICT, healthcare, transport, energy, utilities and industrial operations — and to run national incident-response coordination and cyber drills.
The PDPL's 2022 Ministerial Resolutions established an adequacy list of destination countries considered to offer sufficient protection; transfers to non-listed jurisdictions require consent, contractual necessity, or specific Authority permission.
Bahrain's pattern mirrors the wider Gulf: a 2025 institutional consolidation (NCSC) layered on top of an already-mature, if modestly penalized, 2018 data-protection law — recent structural change at the top, incremental change to the underlying penalty regime.
Every jurisdiction on this map maps to the same control intent — Kerberogate lets you assess it once and report it everywhere your business operates.
A sector-first regulatory landscape: CITRA governs data privacy, CAIT drives government IT, and the Central Bank runs the most developed control framework.
Kuwait has no single unified cyber regulator — governance splits across a telecom regulator, an e-government agency, and the central bank, which runs the most mature framework.
Established under Law No. 37 of 2014. Owns Kuwait's National Cyber Security Strategy and is the issuing/enforcing authority for the Data Privacy Protection Regulation (DPPR).
Drives government-wide digital transformation and public-sector IT infrastructure.
Issues the Cyber and Operational Resilience Framework (CORF) — the most concrete, control-level cyber requirement in the market.
Unveiled as the sector's first unified digital-security regime, shifting from CITRA's earlier 2020 baseline framework toward a resilience-first, maturity-oriented model for banks, finance companies, investment firms and payment providers.
Issued by CITRA, most recently reissued via Resolution/Decision No. 26 of 2024 with a one-year transition period. Applies broadly to any "service provider" collecting personal data, wherever processing occurs. Requires explicit consent, transparency on collection purpose, and breach notification to CITRA and affected individuals. This is regulator-issued secondary legislation under CITRA's founding law, not a standalone parliamentary statute — penalties for violations trace back to that founding law: imprisonment of 1–5 years and/or fines of KWD 500–20,000.
No confirmed comprehensive standalone data-protection law has been enacted beyond CITRA's regulation, and no public enforcement action has been reported to date — but a real October 2024 cyberattack on the Ministry of Health's citizen-facing "Sachel" app shows the exposure is live even where enforcement history is not.
Where most Gulf states widened data-protection coverage in 2024–2025, Kuwait's regulator narrowed it — a distinctive, worth-flagging divergence for any multinational compliance map.
CITRA Decision No. 26 of 2024 narrowed the Data Privacy Protection Regulation so it now applies exclusively to CITRA-licensed telecom and internet-service providers, rather than the broader public- and private-sector scope of the original 2021 text.
A companion Data Classification Policy — which had set out a tiered sensitive-data framework — was repealed in February 2024. Data governance for entities outside CITRA's narrowed scope now defaults back to the general consent provisions in the Electronic Transactions Law.
The Central Bank of Kuwait's 2025 Cyber and Operational Resilience Framework (CORF) — covering banks, finance/investment companies, exchange houses, credit-information companies and e-payment providers — remains the most concrete, control-level cyber requirement in the market, unaffected by the DPPR narrowing.
Absent a comprehensive PDPL, Kuwait's practical data-protection exposure runs through the Electronic Transactions Law No. 20/2014 (Article 37: unauthorized access/disclosure of personal data, up to 3 years' imprisonment and KWD 5,000–20,000) and the Cybercrime Law No. 63/2015, which tiers penalties by severity — from KWD 500–2,000 for unauthorized access up to KWD 5,000–20,000 and 10 years' imprisonment for government-system intrusion involving data alteration or deletion.
Kuwaiti regulators do not generally publish case outcomes; CITRA's administrative process is to investigate complaints and allow roughly 90 days to remedy before any referral to criminal authorities — meaning compliance programs should treat statutory penalty ceilings as the operative risk signal rather than a visible enforcement track record.
State this plainly rather than assuming convergence with neighbors: Kuwait remains the one GCC market without an omnibus data-protection law as of this writing, and its 2024 regulatory changes moved toward narrower, not broader, statutory privacy coverage.
Every jurisdiction on this map maps to the same control intent — Kerberogate lets you assess it once and report it everywhere your business operates.
Six sovereign regulatory regimes, one increasingly interconnected economic bloc. Compliance leaders operating across the Gulf are mapping the same control intent six different ways.
Every GCC state now has a dedicated data-protection instrument and a national cyber authority or framework — but each is at a different stage of maturity, and none of the six regimes are interchangeable.
| Country | Cyber Baseline | Data Protection Instrument |
|---|---|---|
| UAE | NESA/ISR, TDRA, CBUAE, ADHICS | PDPL — Federal Decree-Law 45/2021 |
| Saudi Arabia | NCA — ECC / CSCC | PDPL — Royal Decree M/19 (2021, amended 2023) |
| Oman | MTCIT / OCERT, CBO CS&RF | PDPL — Royal Decree 6/2022 |
| Qatar | NCSA — NIA Policy | PDPPL — Law No. 13 of 2016 |
| Bahrain | NCSC (empowered 2025) | PDPL — Law No. 30 of 2018 |
| Kuwait | CITRA, CBK CORF | DPPR — CITRA Resolution 26/2024 |
The pattern across the bloc: UAE and Saudi Arabia lead on framework maturity and enforcement signaling; Qatar has the most active enforcement record; Bahrain and Kuwait recently consolidated or restructured core authorities (2024–2025); Oman's PDPL only reached full enforcement in 2026. A single GRC platform mapped once across all six removes the need to track six separate regulatory clocks by hand.
Political alignment on cybersecurity is real at the GCC Secretariat level; legal harmonization across the six national regimes is not.
Established 2022; held its third meeting in November 2024 in Doha under the GCC Secretary-General, tasked with developing a joint cyber strategy — described as forthcoming rather than finalized. No unified GCC data-protection law or single binding cybersecurity standard exists; each of the six states retains its own distinct instrument.
Concrete cooperation runs at the operational rather than legal level: annual joint cyber drills rotating host country, shared "Capture the Flag" training events, and coordinated threat-intelligence partnerships with major cloud providers — coordination among six national CERTs rather than a single regional CERT.
ISO 27001 and NIST CSF function as the de facto shared technical reference point across national frameworks — Saudi NCA's ECC, the UAE's NESA/DESC-derived controls and Qatar's NIA Policy all lean on the same underlying control language, even where the legal structures around them stay distinct.
Data localization and licensing requirements are the sharpest fault line across the bloc — a split between "fragmented" jurisdictions relying on sector-specific rules and broad principles (Saudi Arabia, Kuwait, Oman, UAE mainland) and "comprehensive" GDPR-styled regimes (DIFC, ADGM, the QFC, and Qatar's and Bahrain's national laws). Vendor and third-party risk assessments still have to be mapped to each national regulator individually — there is no unified regional vendor-risk scheme.
The UK–GCC Free Trade Agreement, concluded May 2026, is the first GCC-wide instrument in which the bloc committed to prohibiting unjustified and disproportionate data-localization requirements for UK firms — directionally significant, though its digital-trade chapter carries no dispute-resolution mechanism, making it a statement of intent rather than an enforceable market-access guarantee today.
The honest framing for a GRC buyer: the 2024–2026 window is one of parallel national modernization — each of the six states independently tightening its own law — coexisting with thin, mostly ministerial-level regional coordination. Plan for six regulatory clocks, not one.
Every jurisdiction on this map maps to the same control intent — Kerberogate lets you assess it once and report it everywhere your business operates.
No omnibus federal privacy law. Instead: sector regulators, a fifty-state patchwork, and a voluntary framework that has become the de facto national standard.
Where the EU has one regulation coordinated across supervisory authorities, the US layers federal sector rules, a fifty-state patchwork of breach and privacy statutes, and voluntary-but-referenced technical standards.
Lead federal civilian cyber agency; will enforce CIRCIA's critical-infrastructure incident-reporting rule once finalized (still pending as of this report).
Non-regulatory standards body behind the Cybersecurity Framework, SP 800-53/171 and the AI Risk Management Framework — voluntary, but a de facto benchmark via contracts and litigation.
The FTC enforces general privacy/security practices and GLBA's Safeguards Rule; the SEC enforces public-company cyber-incident disclosure; HHS/OCR enforces HIPAA; state Attorneys General and California's CPPA enforce their own breach and privacy statutes.
Voluntary and outcomes-based rather than a certifiable control catalogue — but referenced throughout federal contracting (FedRAMP, CMMC) and cited as the reasonable-security benchmark in FTC enforcement and litigation.
Around twenty states now have comprehensive consumer privacy statutes, led by California's CCPA/CPRA. The California Privacy Protection Agency enforces fines up to $2,663 per violation ($7,988 for intentional or minor-data violations), adjusted every two years. Two federal comprehensive privacy bills (ADPPA, APRA) have stalled in Congress over private-right-of-action and preemption disputes — there is still no single US privacy law.
The SEC requires public companies to disclose material cyber incidents within four business days (Form 8-K) and describe governance annually (Form 10-K). NYDFS's 23 NYCRR 500 binds NY-regulated financial entities. HIPAA governs healthcare data, with the first major Security Rule overhaul since 2013 currently in proposed rulemaking (encryption, MFA, network segmentation).
Confirmed enforcement: HHS/OCR's $16M Anthem settlement remains the largest HIPAA penalty on record; the FTC's GoodRx action ($1.5M) was its first-ever Health Breach Notification Rule case. The throughline for a GRC buyer: US compliance is an assembly exercise across dozens of overlapping regimes, not a single checklist.
Several of the US's biggest 2024–2026 cyber-compliance obligations exist in statute but not yet in final, enforceable rule form — a genuinely unsettled compliance surface.
The 2022 statute requires CISA to mandate 72-hour reporting of substantial cyber incidents and 24-hour reporting of ransom payments for covered critical-infrastructure entities. The final rule was statutorily due around October 2025, missed that date, and CISA's regulatory agenda now targets roughly September 2026 — meaning the headline reporting mandate is not yet operative.
HHS OCR's January 2025 proposed rule would remove most "addressable" implementation specifications — making encryption, MFA, network segmentation and annual compliance audits effectively mandatory rather than optional. The comment period closed March 2025; finalization has since been reported as delayed.
An amendment effective May 2024 requires nonbank financial institutions to notify the FTC of security breaches affecting 500 or more consumers within 30 days of discovery — one of the few recent federal cyber rules that is both final and in force.
Settled with the FTC plus 49 states and D.C.; the state-level settlement alone totaled $52 million. Alleged conduct across three breaches (2014–2020) affecting 344M+ customers included inadequate password, access and firewall controls and poor logging/MFA — the order requires a comprehensive security program and biennial third-party audits for 20 years.
The first-ever state enforcement action under a comprehensive state privacy law (the Texas Data Privacy and Security Act) — alleging unauthorized geolocation and driving-behavior data collection via embedded SDKs, inadequate privacy notices, and undisclosed sensitive-data sales affecting 45M+ individuals.
No comprehensive federal privacy law has passed — ADPPA (2022) and its successor APRA (2024) both stalled in Congress over private-right-of-action and preemption disputes, and narrower 119th-Congress bills remain pending. Roughly 20 states now have comprehensive privacy statutes in effect, and California remains the outlier with a limited private right of action (statutory damages of $100–$750 per incident) while every other state relies on Attorney-General-only enforcement.
Every jurisdiction on this map maps to the same control intent — Kerberogate lets you assess it once and report it everywhere your business operates.
UK GDPR at full statutory strength, an NCSC-backed technical baseline, and a Cyber Security & Resilience Bill moving through Parliament right now.
The UK retained a GDPR-equivalent regime after Brexit and is now mid-passage on a major cybersecurity law update.
Part of GCHQ. The UK's technical cyber authority — publishes the Cyber Assessment Framework and Cyber Essentials scheme, underpinning sector regulators rather than fining directly.
Independent regulator enforcing UK GDPR, the Data Protection Act 2018, and (since June 2025) the Data (Use and Access) Act.
Conduct and prudential regulators running the joint operational-resilience regime and the newer Critical Third Parties oversight regime for systemic ICT suppliers.
The Bill (introduced Nov 2025, reintroduced May 2026, now in Lords Committee Stage) will widen NIS-style obligations to data centres, managed service providers and critical suppliers, and tighten incident-reporting timelines — but has not yet received Royal Assent.
The ICO can fine up to £8.7m or 2% of global turnover for the standard tier, and up to £17.5m or 4% of global turnover — whichever is higher — for the most serious infringements. The Data (Use and Access) Act 2025 (Royal Assent 19 June 2025) is amending the regime in stages rather than replacing it outright.
British Airways (£20m, 2020) and Marriott (£18.4m, 2020) remain the largest ICO fines, both sharply reduced from their original notices of intent. More recently, Advanced Computer Software Group was fined £3.07m (2025) over a ransomware attack that disrupted NHS services, and South Staffordshire Water was fined £963,900 (2026) — both citing MFA gaps and weak patch management as root causes.
Financial-sector resilience testing and a government-backed baseline certification scheme sit alongside UK GDPR as the two other pillars of UK cyber compliance.
In-scope firms — banks, insurers, PRA-designated investment firms, payment/e-money firms and qualifying cryptoasset firms — had to demonstrate by 31 March 2025 that they can remain within board-set "impact tolerances" for their most important business services under severe-but-plausible scenarios. The FCA has since published post-deadline reviews of firms' testing maturity.
NCSC-overseen baseline certification, delivered by IASME since 2020 via licensed certification bodies, covering five controls: firewalls, secure configuration, security-update management, user access control and malware protection. Mandatory since 2014 for suppliers bidding on UK government contracts involving personal or sensitive data.
Beyond fines, the ICO can issue information notices (compel disclosure), assessment notices (compulsory audits), enforcement notices (order remedial steps or halt processing) and reprimands — an increasingly used lower-tier public-accountability tool short of a monetary penalty.
The European Commission renewed the UK's adequacy decisions on 19 December 2025 for a six-year term to 27 December 2031, with a committed mid-point review after four years — explicitly assessing the Data (Use and Access) Act 2025 and finding the UK's framework remains essentially equivalent to EU standards.
The ICO's AI guidance applies core UK GDPR principles — accountability, transparency, lawfulness, fairness — to AI systems, requiring AI-specific considerations within DPIAs and explainability safeguards for solely automated decision-making, within the UK's broader non-statutory, regulator-led approach to AI (there is no standalone UK AI Act).
The Cyber Security and Resilience Bill — which would widen NIS-style obligations to data centres, managed service providers and critical suppliers, and introduce a 24-hour initial incident-notification requirement — remains in progress through Parliament and had not received Royal Assent as of the sources reviewed for this dossier.
Every jurisdiction on this map maps to the same control intent — Kerberogate lets you assess it once and report it everywhere your business operates.
One directly-applicable data-protection regulation, a cybersecurity directive still being transposed, and a financial-resilience regulation now fully in force.
GDPR applies directly across all member states; NIS2, DORA and the Cyber Resilience Act layer sector- and product-specific obligations on top — each enforced through national authorities.
Supports EU cyber policy, runs the CSIRTs Network, and coordinates NIS2 implementation guidance across member states.
Coordinates GDPR enforcement across national Data Protection Authorities via the one-stop-shop mechanism and issues binding cross-border decisions.
DG CNECT leads cybersecurity/digital policy (NIS2, CRA); DG JUST leads data-protection and fundamental-rights policy (GDPR).
Penalties: up to €10m or 2% of global turnover for essential entities, €7m or 1.4% for important entities. Transposition deadline was October 2024 — as of July 2026 the Commission had referred Ireland, Spain, France and the Netherlands to the CJEU for incomplete transposition.
Fines run up to €20m or 4% of global annual turnover, whichever is higher, for the most serious breaches. Ireland's Data Protection Commission fined Meta €1.2 billion in 2023 over unlawful EU-US data transfers — the largest GDPR fine on record; Luxembourg's CNPD fined Amazon €746 million in 2021 over consent failures in targeted advertising.
DORA (applicable since 17 January 2025) requires financial entities to maintain an ICT third-party register and undergo resilience testing, with critical cloud and infrastructure providers now under direct EU-level oversight. The EU AI Act's high-risk compliance deadlines were pushed back in 2026 — to December 2027 for stand-alone systems — while its transparency obligations remain live from August 2026.
GDPR is the anchor, but four more EU-wide instruments now layer cyber, financial-resilience, AI and product-security obligations on top of it — each with its own applicability timeline.
Transposition deadline was 17 October 2024; as of mid-2025 the majority of member states had not yet fully transposed it, prompting Commission reasoned opinions and the threat of CJEU referral for continued non-compliance — a genuinely uneven rollout across the bloc.
Entered into force 10 December 2024. Manufacturer reporting obligations for actively exploited vulnerabilities and incidents apply from 11 September 2026; full cybersecurity-by-design compliance follows from 11 December 2027 — a staged runway for hardware and software product manufacturers selling into the EU.
Prohibited practices and AI-literacy provisions applied from February 2025; general-purpose AI model obligations from August 2025; the high-risk systems deadline is being pushed from August 2026 toward December 2027 under a provisional Council/Parliament political agreement not yet formally adopted; embedded AI in regulated products (medical devices, machinery) follows in August 2028.
ENISA supports CSIRT coordination and EU-wide risk assessment under NIS2 but does not enforce directly — that stays with national competent authorities per member state. DORA enforcement splits by sector: the ECB and national banking supervisors for credit institutions, ESMA-coordinated national regulators for investment firms, EIOPA-coordinated authorities for insurers, and the European Supervisory Authorities directly overseeing "critical" ICT third-party providers such as major cloud vendors via a joint Oversight Forum.
A European Commission simplification package proposing to reduce administrative burden and resolve overlaps across the AI Act, GDPR, the Data Act and other digital-file laws — still at proposal/negotiation stage, with the AI Act timeline shift furthest along and GDPR-specific changes still under review.
NIS2 penalties reach up to €10m or 2% of global turnover for essential entities, €7m or 1.4% for important entities — on top of GDPR's own €20m/4% ceiling, meaning a single incident touching personal data on a NIS2-regulated network can trigger two separate penalty regimes at once.
Every jurisdiction on this map maps to the same control intent — Kerberogate lets you assess it once and report it everywhere your business operates.
Not tied to a single jurisdiction — the control frameworks that multinational organizations, auditors and enterprise customers hold each other to, everywhere.
Regardless of where an organization operates, these frameworks are what its customers, auditors and regulators actually ask for.
The world's best-known ISMS standard. 93 Annex A controls across 4 themes — Organizational, People, Physical, Technological. Certified by accredited third parties, not ISO itself; over 70,000 certificates issued globally as of 2022.
Six functions — Govern, Identify, Protect, Detect, Respond, Recover. Voluntary and outcomes-based rather than certifiable, making it a flexible board-level risk-communication tool alongside certifiable standards.
An AICPA attestation, not a certification, built on five Trust Services Criteria (Security is mandatory; Availability, Processing Integrity, Confidentiality and Privacy are optional). Type II reports — assessing controls over time, not just design — are the enterprise SaaS standard.
Mandatory for anyone storing, processing or transmitting card data. 12 core requirements, four merchant validation levels by transaction volume, and a March 2025 deadline that made its expanded MFA and risk-analysis requirements mandatory.
ISACA's enterprise IT-governance framework — sits above security-specific standards like ISO 27001 and NIST CSF, aligning technology decisions with business objectives.
A prioritized, technically prescriptive control set across three Implementation Groups scaled to organizational size and risk — a practical complement to higher-level management-system standards.
The convergence problem is the point: a single SaaS vendor might need ISO 27001 for EU enterprise customers, SOC 2 Type II for US customers, PCI DSS for payment data, and an internal NIST CSF mapping for board reporting — the same controls, assessed and reported four different ways without a platform to map them once.
The audit lifecycle looks the same across almost every certifiable framework — what changes is who is allowed to sign off.
National accreditation bodies — ANAB in the US, UKAS in the UK, and their counterparts elsewhere — accredit the certification bodies (BSI, LRQA, TÜV SÜD and others) actually authorized to issue ISO certificates. ISO itself does not certify organizations directly.
A Stage 1 readiness/documentation review precedes a Stage 2 implementation audit; a passed certificate runs three years, with annual surveillance audits in years one and two and a full recertification audit in year three.
A newer, certifiable AI management-system standard, structured like ISO 27001, giving organizations building or deploying AI a management-system framework for AI risk, impact assessment and lifecycle governance — increasingly relevant as GRC programs extend beyond information security into AI governance.
Regional regulators consistently point back to these same frameworks rather than inventing incompatible ones from scratch: the UAE's ADHICS references ISO 27001, Saudi Arabia's ECC groups its controls in a structure that mirrors NIST-style domains, and the EU's NIS2 explicitly encourages ISO 27001 and NIST CSF adoption as a recognized compliance pathway.
Extends an existing ISO 27001 ISMS into a Privacy Information Management System, giving organizations a certifiable way to demonstrate GDPR-style accountability on top of an information-security certification they may already hold.
The practical upshot for a GRC program operating across every jurisdiction in this atlas: build the control set once against ISO 27001 / NIST CSF as the common denominator, then map that single control set outward to each region's specific statutory language — rather than building eleven parallel, unrelated compliance programs from scratch.
Every jurisdiction on this map maps to the same control intent — Kerberogate lets you assess it once and report it everywhere your business operates.