The regulatory tide reshaping the GCC
From NESA v2 and SAMA's Cyber Resilience Framework refresh to the UAE Personal Data Protection Law's enforcement window — 2026 is the year compliance becomes board-level operational risk.
How regulation, AI governance, cyber resilience and the talent gap are reshaping the GCC's governance, risk and compliance landscape — drawn from a survey of 240 boards and CISOs across UAE, KSA, Qatar, Bahrain and Oman.
Each chapter is anchored in primary research, regulator interviews and engagement data from MASTC's 2025 portfolio.
From NESA v2 and SAMA's Cyber Resilience Framework refresh to the UAE Personal Data Protection Law's enforcement window — 2026 is the year compliance becomes board-level operational risk.
ISO/IEC 42001 adoption is accelerating, the UAE's AI Charter is influencing procurement, and KSA's SDAIA is publishing operational expectations. We map what's mandated, what's expected and what's still optional.
Boards are no longer asking 'are we secure?' but 'how fast do we recover?' DORA-style expectations are landing in the GCC via SAMA and CBUAE — recovery time, not perimeter, is the new metric.
Open GRC roles in the GCC are at a 5-year high. Hybrid managed-service models — vCISO, vDPO, internal-audit-as-a-service — are filling the gap. We profile what works.
Where regulators, boards, attackers and technology converge over the next 12 months — and the moves leading GCC enterprises are making now.
78-page PDF — five chapters, full survey methodology, regulator-by-regulator mapping and 24 charts you can use in your own board materials.
We host the live PDF under Resources — request the gated copy there and our research team will send the chart pack alongside it.
Get the PDF & chart pack