KSA’s NCA / SAMA cybersecurity regimes and GCC-wide PDPL data protection laws are now two of the strongest forces shaping governance in the region. For most banks and large institutions, the majority of new governance, risk, and compliance work traces back to one of these two streams: hard cyber controls and evolving data protection requirements.
Trying to implement them separately—one project for NCA, one for SAMA, another for PDPL in each country—creates duplication, inconsistency, and unnecessary cost. Falconry360 allows you to design a single implementation blueprint where NCA/SAMA cyber controls and GCC PDPL are modelled once and then reused across entities, regulators, and use cases.
Step 1: Start from Shared Libraries, Not Separate Projects
The foundation of the blueprint is three shared libraries in Falconry360:
- Control Library – one canonical cyber and privacy control set that you can map to:
- NCA ECC, OTCC, CCC, DCC, CSCC, NCNICC‑1
- SAMA Cyber Security Framework domains and principles
- GCC PDPL obligations (KSA PDPL, UAE FDPL/PDPL, Oman, Qatar).
- Obligations Library – NCA/SAMA clauses and GCC PDPL articles represented as structured obligations with tags for regulator, country, theme, and risk type.
- Data / Asset / Service Library – shared records of critical systems, business services, data categories, and third parties that are reused by cyber, privacy, and vendor risk.
By investing in these libraries first, you avoid building separate “mini frameworks” for each regulation.
Step 2: Design Two Primary Use-Case Streams
Once libraries exist, you can structure Falconry360 configuration around two major streams, each spanning several layers (ANTICIPATE, COMPLY, WITHSTAND, ASSURE).
- NCA/SAMA Cyber Governance Stream
Core use cases:
- Cyber Risk Register (ANTICIPATE)
- Cyber risks aligned to NCA domains (e.g., governance, defence, resilience, third‑party) and SAMA CSF pillars.
- Linked to assets, services, vendors, and controls from the central library.
- NCA/SAMA Obligation Mapping (COMPLY)
- ECC/OTCC/CCC/DCC/CSCC/NCNICC‑1 and SAMA CSF clauses mapped to controls, policies, and evidence.
- Coverage and gap views per entity (e.g., SAMA‑regulated bank vs non‑CNI private sector).
- Cyber Incidents and Issues (WITHSTAND/ASSURE)
- Common incident model that captures NCA/SAMA impact, affected controls, and required reporting.
- Issues and remediation plans tracked against the same controls and obligations.
FalconryX can then: read NCA/SAMA updates, suggest new obligations, propose mappings, and draft impact assessments.
- GCC PDPL Compliance Stream
Core use cases:
- PDPL Obligations and Data Inventory (COMPLY / ANTICIPATE)
- Common PDPL themes (lawful basis, consent, rights, retention, security, transfers) mapped once and tagged by country.
- Data processing inventory linking systems, purposes, and data categories to PDPL obligations.
- Privacy Controls and Workflows
- Controls from the central library (access control, encryption, logging, DPIAs, rights handling) linked to PDPL obligations and processing activities.
- Standard workflows for DPIAs, new products, vendor onboarding, and change management that automatically pull in PDPL requirements.
- Incidents and Rights Requests
- Incidents with PDPL impact flags per country and required notification timelines.
- Rights requests tracked end‑to‑end, linked to systems and obligations.
FalconryX can: extract PDPL obligations from new guidance, help draft DPIAs, and generate regulator‑ready breach summaries.
Step 3: Reuse the Same Objects Across Both Streams
The key to this blueprint is deliberate reuse.
- A cloud platform might be:
- A critical system under NCA CSCC/CCC and SAMA CSF.
- A PDPL‑relevant system processing customer data in KSA and UAE.
- A vendor might simultaneously be:
- In scope for NCA OTCC/DCC third‑party cyber controls.
- A PDPL “processor” handling personal data across multiple GCC markets.
By modelling these as single assets and vendors, with multiple tags, you avoid double‑counting and conflicting views.
Step 4: Anchor Both Streams in the Five Falconry360 Layers
Map the blueprint explicitly to Falconry360’s layers:
- GOVERN – Policies and charters for NCA/SAMA cyber, PDPL, AI, and vendor governance.
- ANTICIPATE – Cyber, operational, and privacy risks connected to NCA/SAMA and PDPL obligations.
- COMPLY – All NCA, SAMA, and PDPL clauses as obligations with mappings to controls and evidence.
- WITHSTAND – Resilience scenarios where cyber incidents or data breaches impact important business services.
- ASSURE – Audit and ICFR scopes that include NCA/SAMA and PDPL controls, with shared issues and remediation.
This ensures NCA/SAMA and PDPL are not separate “programmes” but part of one governance operating system.
Step 5: Deliver a Clear Story to Regulators and Boards
With this blueprint, you can explain to stakeholders:
- To regulators: how NCA, SAMA, and PDPL obligations are captured, mapped, executed, and assured in one model.
- To boards: how cyber and privacy risks sit on the same map of critical services, systems, and vendors, and how actions are prioritised.
Falconry360 provides the structure; FalconryX provides the intelligence layer that keeps it current and reduces manual effort.





