Compliance Hub

Explore detailed information on a wide range of industry-leading compliances and regulations

Try Sahl AI for Compliance Automation | Free Trial

GCC Focused Compliances

""

NCA Compliance

Ensures adherence to national cybersecurity standards in Saudi Arabia, as mandated by the National Cybersecurity Authority (NCA) to protect critical information infrastructure.

Ensures adherence to national cybersecurity standards in Saudi Arabia, as mandated by the National Cybersecurity Authority (NCA) to protect critical information infrastructure.
""

UAE PDPL

Governs data protection and privacy in the UAE, focusing on safeguarding personal data.

Governs data protection and privacy in the UAE, focusing on safeguarding personal data.
""

KSA PDPL

Regulates personal data protection in Saudi Arabia, setting standards for data privacy and security.

Regulates personal data protection in Saudi Arabia, setting standards for data privacy and security.

Global Compliances

""

ISO/IEC 27018:2019

Establishes controls to protect personally identifiable information (PII) in public cloud environments, emphasizing privacy and data protection.

Establishes controls to protect personally identifiable information (PII) in public cloud environments, emphasizing privacy and data protection.
""

ISO/IEC 27017:2015

Provides guidelines for information security controls specifically tailored for cloud service providers and their customers.

Provides guidelines for information security controls specifically tailored for cloud service providers and their customers.
""

ISO/IEC 42001:2023

Defines requirements for managing artificial intelligence (AI) systems responsibly, focusing on transparency, risk management, and ethical governance.

Defines requirements for managing artificial intelligence (AI) systems responsibly, focusing on transparency, risk management, and ethical governance.
""

ISO 45001:2018

Establishes requirements for an occupational health and safety (OH&S) management system, aimed at improving employee safety and reducing workplace risks.

Establishes requirements for an occupational health and safety (OH&S) management system, aimed at improving employee safety and reducing workplace risks.
""

ISO 14001

Provides a framework for effective environmental management systems (EMS), enabling organizations to minimize environmental impact and comply with regulations.

Provides a framework for effective environmental management systems (EMS), enabling organizations to minimize environmental impact and comply with regulations.
""

ISO 9001:2015

Specifies requirements for a quality management system (QMS), helping organizations consistently deliver products and services that meet customer and regulatory standards.

Specifies requirements for a quality management system (QMS), helping organizations consistently deliver products and services that meet customer and regulatory standards.
""

HITRUST CSF Certification

Demonstrates compliance with a certifiable framework that harmonizes multiple data protection standards, widely used in the healthcare and financial sectors.

Demonstrates compliance with a certifiable framework that harmonizes multiple data protection standards, widely used in the healthcare and financial sectors.
""

SAMA Compliance

Regulates cybersecurity and data protection standards for financial institutions in Saudi Arabia under the Saudi Central Bank’s guidelines.

Regulates cybersecurity and data protection standards for financial institutions in Saudi Arabia under the Saudi Central Bank’s guidelines.
""

PCI DSS

Establishes security measures for organizations that process credit card information to maintain a secure processing environment.

Establishes security measures for organizations that process credit card information to maintain a secure processing environment.
""

ISO 27701

ISO 27701 builds on ISO 27001, outlining requirements for setting up, maintaining, and improving a privacy management system.

ISO 27701 builds on ISO 27001, outlining requirements for setting up, maintaining, and improving a privacy management system.
NIST

NIST Cybersecurity Framework

The NIST Cybersecurity Framework (CSF) provides guidelines to manage and reduce cybersecurity risks. It includes five core functions: Identify, Protect, Detect, Respond, and Recover.

The NIST Cybersecurity Framework (CSF) provides guidelines to manage and reduce cybersecurity risks. It includes five core functions: Identify, Protect, Detect, Respond, and Recover.
""

ISO 27001

Provides a framework for an information security management system (ISMS) to ensure the safety of consumer data.

Provides a framework for an information security management system (ISMS) to ensure the safety of consumer data.
SOC 2

SOC 2

Defines standards for handling data with a focus on five key principles: protection, availability, integrity, confidentiality, and privacy of data.

Defines standards for handling data with a focus on five key principles: protection, availability, integrity, confidentiality, and privacy of data.
""

HIPAA

HIPAA requires healthcare teams to protect PHI, maintain audit trails, and train staff, all with limited resources. Sahl simplifies it by centralizing compliance in one platform built for lean, fast-moving teams.

HIPAA requires healthcare teams to protect PHI, maintain audit trails, and train staff, all with limited resources. Sahl simplifies it by centralizing compliance in one platform built for lean, fast-moving teams.
GDPR

GDPR

Sets forth rules for data protection and privacy for individuals within the European Union and the European Economic Area.

Sets forth rules for data protection and privacy for individuals within the European Union and the European Economic Area.
AD for LEAP (Large Rectangle (IAB))