NCA Control Readiness
Readiness and improvement support for applicable Essential, Critical Systems, Cloud, Data, and Operational Technology cybersecurity controls.

GRC & regulatory compliance
Connect regulatory obligations, business risk, architecture, evidence, and accountable execution—without reducing governance to a checklist.
Outcome-led engagement
IRIS supports readiness and implementation programs across Saudi, Jordanian, regional, and international requirements. We translate control intent into ownership, policies, processes, technical safeguards, evidence, and an improvement roadmap aligned to the organization’s actual environment.
Capability system
Each capability can stand alone or combine into a broader transformation and operating program.
Readiness and improvement support for applicable Essential, Critical Systems, Cloud, Data, and Operational Technology cybersecurity controls.
Maturity assessment, control improvement, architecture, risk, evidence, and governance aligned to applicable SAMA, NCA, CBJ, and sector expectations.
Operating models for Saudi PDPL, Jordan’s Personal Data Protection Law, and applicable regional requirements covering inventory, purpose, roles, lifecycle, rights, protection, sharing, and accountable processing.
Gap assessment, risk treatment, policy architecture, control implementation, evidence readiness, and continual-improvement support.
Risk methodology, appetite, registers, scenarios, treatment, third-party risk, reporting, and linkage to technology investment.
Control design and effectiveness reviews, evidence models, remediation tracking, audit preparation, and executive-level reporting.
Regulatory intelligence
Our strongest regulatory depth comes from Saudi Arabia and Jordan. We use that experience to build reusable control systems, then map them to each client’s operating jurisdictions and sector obligations.
Connect control applicability, ownership, engineering, evidence, testing, exceptions, and continuous improvement.
Explore the insight ↗Build one defensible control and evidence system with mapped overlays for banks, finance companies, credit bureaus, and connected services.
Explore the insight ↗Translate data-protection principles into accountable data inventory, purpose, rights, retention, safeguards, transfer, and third-party controls.
Explore the insight ↗REGIONAL SCOPEThese briefings provide practical context, not legal opinions or a claim that every framework applies to every organization. Applicability and current requirements must be confirmed with the relevant authority and qualified advisers.
Built-in assurance
IRIS supports readiness and implementation; independent certification and regulatory decisions remain with the relevant authorized bodies.
Evidence requirements are designed with the control so assurance does not become an end-of-cycle scramble.
Remediation reflects exposure, business criticality, dependency, feasibility, and control value.
Governance recommendations connect directly to the platforms, data, identities, networks, cloud, and OT environments they govern.
Talk to IRIS
Bring us the objective, the constraint, or the problem. We will bring the right regional specialists into the conversation.