Your posture against the frameworks the regulator actually asks for.
Upload the firewall, cloud, and identity configs you already run. CyberTwin scores them against the Kingdom’s and the Gulf’s binding frameworks — NCA ECC, CCC, CSCC and OTCC, SAMA CSF, PDPL, UAE IA and DESC — and hands you the quarterly report your regulator expects, with every control labeled proven or modeled.
Essential Cybersecurity Controls — the baseline for KSA government + CNI entities.
Cloud Cybersecurity Controls — for cloud service providers and tenants.
Critical Systems Cybersecurity Controls — the higher bar for critical systems.
Operational Technology Controls — plant-floor / ICS environments.
The central bank framework binding every KSA financial institution.
Personal Data Protection Law — the data-privacy regime across the Gulf.
UAE Information Assurance standard for government + regulated entities.
Dubai Electronic Security Centre standard for Dubai government entities.
Part of the 24 frameworks CyberTwin scores. Every control is labeled proven from your config or modeled from a crosswalk — a score built only on derived mappings is capped, because a crosswalk never masquerades as an audit.
The documents you hand the regulator.
A quarterly posture summary built from your snapshot series — the document your risk committee files, not just a score on a dashboard.
Per-control coverage with a proven-vs-modeled provenance stamp on every line, so an assessor sees show-me evidence, not a self-attestation.
Dollar-quantified exposure, the top moves, and the one thing — present it live or export the editable slide deck for the board.
Every figure ships a signed proof anyone can re-verify at /verify — the defensibility a regional CISO needs when the regulator asks "prove it."
All generated from configs you already have — 1,917 deterministic checks across 37 vendors. No agent, no live scan, nothing fabricated. Decision support for your compliance function — never a filing determination or an accreditation CyberTwin holds.