Independent Cybersecurity Auditing · Al Khobar, Eastern Province, KSA

Cybersecurity Auditing · GRC Consulting

Independent audits for
Saudi Arabia's
regulatory frameworks.

Raqeeb Consulting delivers compliance audits and GRC advisory across SAMA, NCA, Insurance Authority, CST, and Aramco standards. No product sales. No vendor affiliations. Independent assurance only.

11Frameworks covered
6Regulatory authorities
10+Certifications held
100%Audit-only independence
Framework registry Coverage index
CSFCyber Security FrameworkBanks, insurers, financing companies, fintechsSAMA · Audit
MVCMinimum Verification ControlsTechnical baseline for all SAMA entitiesSAMA · Audit
CRFRCyber Resilience Fundamental RequirementsNew licensees & sandbox entrantsSAMA · Audit
ECCEssential Cybersecurity Controls 2:2024All private sector organisationsNCA · Audit
DCCData Cybersecurity ControlsData classification & protectionNCA · Audit
CCCCloud Cybersecurity ControlsCloud service users & providersNCA · Audit
CSCCCritical Systems Cybersecurity ControlsOperators of critical systemsNCA · Audit
TCCTelework Cybersecurity ControlsRemote work environmentsNCA · Audit
IA CSFInsurance Authority Cybersecurity FrameworkInsurance & reinsurance companiesIA · Audit
CST CSFCST Cybersecurity Regulatory FrameworkTelecom, ICT & postal licenseesCST · Audit
SACS-210Third-Party Cybersecurity StandardAramco vendors — CCC / CCC+ readinessAramco · GRC

Team certifications

CISACertified Information Systems Auditor
ISO 27701 Lead AuditorPrivacy Information Management
ISO 27001 Lead AuditorInformation Security Management
ISO 27001 Lead ImplementerISMS Design & Implementation
ISO 27005 Lead Risk ManagerInformation Security Risk
CEH v13Certified Ethical Hacker
CSAPSecurity Analytics Professional
CySA+Cybersecurity Analyst
Security+Security Fundamentals
CCCertified in Cybersecurity
ICCACertified Cloud Associate
CISACertified Information Systems Auditor
ISO 27701 Lead AuditorPrivacy Information Management
ISO 27001 Lead AuditorInformation Security Management
ISO 27001 Lead ImplementerISMS Design & Implementation
ISO 27005 Lead Risk ManagerInformation Security Risk
CEH v13Certified Ethical Hacker
CSAPSecurity Analytics Professional
CySA+Cybersecurity Analyst
Security+Security Fundamentals
CCCertified in Cybersecurity
ICCACertified Cloud Associate

Services

Two disciplines. One standard of independence.

Raqeeb Consulting does not sell security products or resell vendor licences. Every engagement is an independent assessment — the assurance your regulator and board expect.

Service 01

Cybersecurity Compliance Auditing

Structured, evidence-based audits producing regulator-ready findings, maturity scores, and remediation roadmaps.

SAMA CSFCyber Security Framework maturity assessmentSAMA
SAMA MVCMinimum Verification Controls auditSAMA
SAMA CRFRCyber Resilience Fundamental RequirementsSAMA
NCA ECCEssential Cybersecurity Controls 2:2024NCA
NCA DCCData Cybersecurity ControlsNCA
NCA CCCCloud Cybersecurity ControlsNCA
NCA CSCCCritical Systems Cybersecurity ControlsNCA
NCA TCCTelework Cybersecurity ControlsNCA
IA CSFInsurance Authority Cybersecurity FrameworkIA
CST CSFCST Cybersecurity Regulatory FrameworkCST
Deliverables: gap register · risk-rated findings · maturity scoring · remediation roadmap · regulator-ready report
Service 02

Cybersecurity GRC Consulting

Governance, risk, and compliance advisory across every framework we audit — plus dedicated Aramco third-party readiness.

SACS-210Aramco third-party standard — CCC / CCC+ readiness, gap assessment & evidence packagingAramco
All SAMACSF / MVC / CRFR programme design & compliance roadmapsSAMA
All NCAECC / DCC / CCC / CSCC / TCC implementation advisoryNCA
IA · CSTSector framework compliance programmesIA / CST
PolicyCybersecurity policies, standards & procedures developmentAll
RiskRisk assessments, risk registers & treatment planningAll
vCISORetained executive advisory & committee representationAll
VendorThird-party vendor security assessmentsAll
Engagement models: fixed-fee projects · readiness programmes · monthly retainers

Why Raqeeb

Built for Saudi Arabia's regulatory landscape

Regulator-native expertise, audit-only independence, and Eastern Province presence — under one practice.

Regulator-native expertise

Working knowledge of SAMA, NCA, IA, CST, and Aramco frameworks built through direct implementation in KSA organisations — not imported methodology adapted after the fact.

Audit-only independence

No security products. No vendor resale. No commercial conflicts. Every engagement is a fully independent assessment — which is exactly what regulators and boards require.

Eastern Province presence

Based in Al Khobar, at the centre of the Kingdom's energy and industrial sector. On-site delivery for Aramco supply chain and Eastern Province clients without travel overhead.

Methodology

From scoping to regulator-ready report

A disciplined five-stage process — consistent across every framework, predictable for you, defensible for your regulator.

STAGE 01

Scoping

Identify applicable frameworks, define audit boundary, confirm timelines and deliverables. Initial call is free.

STAGE 02

Document review

Review policies, architecture, prior assessments, and evidence artefacts to establish baseline context.

STAGE 03

Control assessment

Structured testing via interviews, observation, and evidence sampling against each framework's control set.

STAGE 04

Findings & report

Risk-rated gap register, maturity scores, and a formal regulator-ready report with remediation roadmap.

STAGE 05

Post-audit support

Optional retained support to track remediation, prepare follow-ups, and maintain ongoing compliance.

Contact

Request an audit or scoping call

Based in Al Khobar, serving clients across the Eastern Province and the broader Kingdom. Initial scoping calls are free and can be held remotely.

LocationAl Khobar, Eastern Province, Saudi Arabia

Start a conversation

Tell us about your organisation and compliance needs. We respond within one business day.