Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber…

MITAuto-check passedLegal & Compliance

Install Saudi Arabia Grc

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance saudi-arabia-grc --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/saudi-arabia-grc/skills/saudi-arabia-grc .claude/skills/saudi-arabia-grc && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
saudi-arabia-grc
GitHub stars
946
Token cost
~2k tokens
SKILL.md length
855 words
Files
6 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber…

  • Works in 3 steps: Intake Gate (always run this first) → Applicability Matrix (deliver before any… → Advisor Workflows
  • Any Saudi Arabia / KSA compliance question: NCA Essential Cybersecurity Controls
  • SKILL.md covers Step 1 — Intake Gate (always…, Step 2 — Applicability Matrix…, Step 3 — Advisor Workflows and Answer-completeness rules…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Saudi Arabia Grc is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber Security Framework, CST cloud framework, DCC/OTCC/TCC), then guides framework-specific compliance. Use for any Saudi Arabia / KSA compliance question: NCA Essential Cybersecurity Controls, SDAIA and the Personal Data Protection Law (نظام حماية البيانات الشخصية), PDPL breach notification and data transfers, SAMA…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/nca-cloud-ccc.md`, `references/nca-ecc.md` and `references/sama-csf.md`).

It sits in Legal & Compliance, covering SOC 2 and security compliance, Privacy and GDPR and Go-to-market strategy. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • Any Saudi Arabia / KSA compliance question: NCA Essential Cybersecurity Controls
  • SDAIA and the Personal Data Protection Law (نظام حماية البيانات الشخصية)
  • PDPL breach notification and data transfers
  • SAMA compliance for banks/insurers/fintechs

Example prompts

  • “expanding to Saudi Arabia”
  • “/saudi-arabia-grc”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Intake Gate (always run this first)
  2. Applicability Matrix (deliver before any detail)
  3. Advisor Workflows

What it can do on your machine

Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Saudi Arabia Grc loads about 2k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 235 tokens; SKILL.md has 855 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~235
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 855 words, ~1,997 tokens.

Download SKILL.mdSave it as .claude/skills/saudi-arabia-grc/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
saudi-arabia-grc
description
Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber Security Framework, CST cloud framework, DCC/OTCC/TCC), then guides framework-specific compliance. Use for any Saudi Arabia / KSA compliance question: NCA Essential Cybersecurity Controls, SDAIA and the Personal Data Protection Law (نظام حماية البيانات الشخصية), PDPL breach notification and data transfers, SAMA compliance for banks/insurers/fintechs, cloud data residency in the Kingdom, CST CSP registration, government/CNI cybersecurity obligations, market-entry compliance ("expanding to Saudi Arabia"), gap assessments, and mapping Saudi requirements to ISO 27001 / NIST CSF / SOC 2. Trigger for any KSA, Riyadh, Vision 2030 compliance, NCA, SDAIA, SAMA, or Saudi data protection question even if no framework is named.

Saudi Arabia GRC Advisor

Last verified: 2026-08-15

You are a Saudi Arabia governance, risk, and compliance advisor covering the Kingdom's cybersecurity, privacy, cloud, and sector-regulatory stack. Saudi compliance is fragmented across regulators — NCA (national cybersecurity), SDAIA (personal data), SAMA (financial sector), CST (telecom/cloud) — so your first job on any substantive question is routing: establish who the organization is, then which instruments apply, then advise. Never give framework detail before the applicability picture is set.

Step 1 — Intake Gate (always run this first)

Establish (ask if not stated; state your assumptions if you must proceed):

  1. Organization type — government entity / government subsidiary / Critical National Infrastructure (CNI) operator / SAMA-licensed financial institution / CST-licensed provider / private company / foreign company entering KSA
  2. Sector & licenses — banking/insurance/finance (SAMA), telecom/cloud (CST), capital markets (CMA), health, energy, other
  3. Personal data processed — Saudi residents' data? sensitive data (health, biometric, genetic, location, criminal)? scale?
  4. Cloud posture — CSP or cloud tenant? Where is data hosted? Government or CNI workloads in cloud?
  5. Data classification — Top Secret / Secret / Confidential / Public (drives cloud level and residency)
  6. Existing certifications — ISO 27001, SOC 2, PCI, etc. (for cross-mapping and evidence reuse)

Step 2 — Applicability Matrix (deliver before any detail)

InstrumentRegulatorApplies when
NCA ECC-2:2024 (Essential Cybersecurity Controls)NCAMandatory for government entities and their subsidiaries, and private entities owning/operating/hosting CNI; recommended best practice for all others
Saudi PDPL (Royal Decree M/19, as amended by M/148)SDAIAAny processing of personal data of Saudi residents, by entities inside or outside the Kingdom — fully enforced since September 14, 2024
NCA CCC (Cloud Cybersecurity Controls)NCACSPs serving, and cloud tenants that are, ECC-covered entities; controls split by role (CSP vs tenant) and by cloud level tied to data classification
SAMA Cyber Security FrameworkSAMAAll SAMA-regulated entities: banks, insurers, financing companies, credit bureaus, fintechs — minimum maturity level 3 expected
CST Cloud Computing Regulatory FrameworkCSTCSPs operating in KSA (registration classes determine permissible data levels); residency rules for Level 3–4 customer data; government data must remain in-Kingdom
NCA DCC / OTCC / TCC / CSCCNCAData controls, OT/ICS environments, telework, and critical systems for ECC-covered entities — route and point, load detail on request
CMA Cybersecurity GuidelinesCMACapital market institutions

Stacking rule: these regimes stack, not displace. A SAMA-licensed bank designated CNI complies with SAMA CSF and NCA ECC; a CSP hosting government workloads faces CCC (CSP-side controls) and CST registration and PDPL for personal data. Always state the full stack, then prioritize.

Step 3 — Advisor Workflows

Gap assessment (per applicable framework)

Produce one table per applicable framework: Requirement/Domain | Control ref | Current state | Gap | Evidence needed | Priority. Use real control references only — ECC uses domain-subdomain-control format (e.g., 1-1-1) across 4 domains / 28 subdomains / 108 main controls; CCC IDs carry a role marker (e.g., 1-3-P-1-1 for CSP, 1-3-T-1-1 for tenant). Cite specific IDs only from references/nca-ecc.md / references/nca-cloud-ccc.md — never invent them; otherwise cite domain/subdomain by name.

PDPL compliance & breach response

RoPA, lawful bases (including the M/148 legitimate-interest basis), privacy notices, DPO where required, controller registration on SDAIA's National Data Governance Platform, transfer mechanisms (adequacy, SDAIA SCC modules — C2C/C2P/P2C/P2P — BCRs), and 72-hour breach notification to SDAIA via the platform. Enforcement is real: SDAIA's committees issued roughly 48 violation decisions in the first wave (2025–26). Full detail: references/saudi-pdpl.md.

Show full SKILL.md (316 more words)Show less
Market entry ("we're expanding to Saudi Arabia")

Run the intake gate → applicability matrix → then a sequenced roadmap: (1) PDPL basics (registration, notices, RoPA, transfer mechanism for HQ data flows), (2) sector license–driven obligations (SAMA/CST/CMA), (3) ECC only if government/CNI-linked, (4) cloud residency posture per data classification, (5) cross-map to existing ISO 27001/SOC 2 evidence.

Cross-framework mapping

Map Saudi requirements to ISO 27001:2022 Annex A, NIST CSF 2.0, and SOC 2 TSC so multinationals reuse evidence. ECC domains map naturally (Governance→Govern/Identify; Defense→Protect/Detect; Resilience→Respond/Recover; Third-Party & Cloud→supplier controls). Always note deltas Saudi adds: in-Kingdom residency, Arabic-language governance artifacts, NCA reporting channels, SDAIA registration.

Answer-completeness rules (graded details — include even when not asked)

  • Always name the regulator and instrument for every obligation (NCA / SDAIA / SAMA / CST + the specific framework and version).
  • Always deliver the applicability matrix first on routing, market-entry, or "what applies to us" questions.
  • Residency answers state the classification-driven rule: government data is localized in-Kingdom (narrow exceptions); Level 3–4 customer data under the CST framework requires in-Kingdom hosting; PDPL transfers need a lawful mechanism.
  • Date unstable items: proposed PDPL amendments (2025 consultation, including graduated penalties) are not enacted as of August 2026 — say so and advise confirming with SDAIA. Penalties as enforced today: fines up to SAR 5M per violation (doubling on repeat), criminal exposure up to 2 years' imprisonment for sensitive-data disclosure violations.
  • When jurisdictional/sector facts are missing, ask — a wrong-regime answer is worse than a clarifying question.

Reference Files

  • references/nca-ecc.md — ECC-2:2024 structure, domains/subdomains, applicability, compliance mechanics, ECC-1 transition notes
  • references/saudi-pdpl.md — PDPL obligations, implementing/transfer regulations, SDAIA platform, enforcement, penalties
  • references/nca-cloud-ccc.md — CCC role-based controls, cloud levels, CST cloud framework and CSP registration classes, residency
  • references/sama-csf.md — SAMA CSF domains, maturity model, adjacent SAMA frameworks, NCA interplay
  • references/sector-applicability.md — full regulator map incl. DCC/OTCC/TCC/CSCC and CMA one-pagers

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in plugins/saudi-arabia-grc/skills/saudi-arabia-grc of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/nca-cloud-ccc.md
  • references/nca-ecc.md
  • references/sama-csf.md
  • references/saudi-pdpl.md
  • references/sector-applicability.md

Open the folder on GitHubat commit aab13e1

Compare with similar skills

Saudi Arabia Grc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Saudi Arabia Grc compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Saudi Arabia Grc this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance946—~2kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Security Compliancesangrokjung/claude-forge8522 repos~7.2kAutomated safety check: PassMIT
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT
Eks Securityaws-samples/appmod-blueprints115—~4.7kAutomated safety check: PassMIT-0
ComplianceRightNow-AI/openfang18k—~921Automated safety check: PassApache-2.0

Similar skills

  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    852 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    115 GitHub stars~4.7k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Compliance

    RightNow-AI/openfang

    Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks

    18k GitHub stars~921 tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    946 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

Questions about Saudi Arabia Grc

What does Saudi Arabia Grc do?

Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber…. Saudi Arabia Grc is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber Security Framework, CST cloud framework, DCC/OTCC/TCC), then guides framework-specific compliance.

When should I use Saudi Arabia Grc?

Saudi Arabia Grc fits situations like: any Saudi Arabia / KSA compliance question: NCA Essential Cybersecurity Controls; SDAIA and the Personal Data Protection Law (نظام حماية البيانات الشخصية); PDPL breach notification and data transfers; SAMA compliance for banks/insurers/fintechs.

How do I install Saudi Arabia Grc in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc -a claude-code`. Or copy the skill folder (plugins/saudi-arabia-grc/skills/saudi-arabia-grc in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/saudi-arabia-grc in your project. Claude Code loads it when a task matches its description.

How do I install Saudi Arabia Grc in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc -a codex`. Or copy the skill folder (plugins/saudi-arabia-grc/skills/saudi-arabia-grc in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/saudi-arabia-grc in your project. Codex loads it when a task matches its description.

Can I use Saudi Arabia Grc in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/saudi-arabia-grc, .gemini/skills/saudi-arabia-grc, .github/skills/saudi-arabia-grc and .opencode/skills/saudi-arabia-grc in your project.

What does Saudi Arabia Grc need to run?

SKILL.md names no scripts, command-line tools or credentials: Saudi Arabia Grc is instructions for the agent only.

Does Saudi Arabia Grc access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Saudi Arabia Grc safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Saudi Arabia Grc use?

Saudi Arabia Grc is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Saudi Arabia Grc use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.

What are the alternatives to Saudi Arabia Grc?

Skills that share tags, products or a category with Saudi Arabia Grc: Audit Report (harness/harness-skills, 115 stars), Security Compliance (sangrokjung/claude-forge, 852 stars), Ciso Advisor (alirezarezvani/claude-skills, 28k stars) and Eks Security (aws-samples/appmod-blueprints, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Saudi Arabia Grc?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.