+966 11 208 6999
Learning resourcesBlogBook a meeting
MstndMstnd logo
Home
PricingWhy Mstnd?Contact us
Try free nowGo to Mstnd
Laws, frameworks, and standards applied in every document

Accreditations & Regulatory Frameworks Mstnd Complies With and Applies

Mstnd is built on the national and international laws, frameworks, and standards for data protection, document management, and cybersecurity. Here we walk through every accreditation and regulatory framework, its key aspects, and how Mstnd complies with it and applies it inside the system.

Request a demoExplore Mstnd security
Personal Data Protection Law
National Data Management Office
National Cybersecurity Authority
ISO/IEC 27001
Google Cloud
Digital Government Authority
National Center for Archives & Records
Nafath (National Single Sign-On)
General Authority for SMEs (Monsha'at)
Compliance in practice

Compliance is not a slogan — it's controls that work in every document

Mstnd turns the requirements of laws and regulatory frameworks into real controls that operate at the level of every document: classification and confidentiality levels, precise permissions and an organizational structure, data encryption, an immutable audit trail, retention and disposal management, and secure, documented sharing. Below are the accreditations and frameworks that Mstnd complies with and applies, each explained along with how it works inside the system.

PDPLSDAIANDMONCAISO/IEC 27001Google CloudDGANCARNafathMonsha'at

Data Protection & Privacy

Personal Data Protection Law

Personal Data Protection Law

PDPL
National lawAuthority: Saudi Data & AI Authority (SDAIA)
Official website

The Personal Data Protection Law is the Saudi law issued by Royal Decree No. (M/19) and its amendments, setting the binding rules for collecting, processing, storing, sharing, disclosing, and disposing of personal data within the Kingdom. It is overseen by the Saudi Data & AI Authority (SDAIA) and aims to protect the privacy of individuals and their rights over their data and to regulate how it is handled.

Key aspects

  • The legal basis and the data subject's consent to processing
  • The data subject's rights: to be informed, to access, to correct, to obtain a copy, and to request disposal
  • Notifying the competent authority of any personal data breach or leak
  • Controls for retaining data and disposing of it as soon as its purpose has ended
  • Appointing a data protection officer and conducting a privacy impact assessment when needed

How Mstnd applies it

  • Classifies documents that contain personal data and tags them with the appropriate confidentiality levels
  • Restricts access on a least-privilege basis through more than 90 granular permissions and an organizational structure
  • Encrypts data at rest and in transit
  • Logs every access and processing action in an immutable audit trail (who, when, and what)
  • Manages retention periods and secure disposal once the purpose has ended
  • Empowers data subjects to exercise their rights through access, correction, and exporting a copy
Saudi Data & AI Authority

Saudi Data & AI Authority

SDAIA
The national data referenceAuthority: A government entity linked to the Prime Minister
Official website

The Saudi Data & AI Authority (SDAIA) is the national reference for everything related to data and artificial intelligence in the Kingdom. It was established by Royal Order No. (A/471) and is linked directly to the Prime Minister. It sets the strategic direction for data as a national asset and oversees its governance, and the National Data Management Office (NDMO) and the National Information Center (NIC) report to it.

Key aspects

  • Setting the national data and AI strategy and overseeing its implementation
  • Governing and protecting national data as a national asset
  • Overseeing the application of the Personal Data Protection Law and monitoring compliance
  • Building the national register of entities that process personal data

How Mstnd applies it

  • Treats the organization's data as a governed asset: classification, ownership, confidentiality levels, and a lifecycle
  • Applies the national data governance principles the Authority oversees by controlling availability and sharing
  • Provides a ready-made foundation for applying the Personal Data Protection Law and NDMO standards
  • Documents the data lifecycle from creation to disposal in a reviewable log
National Data Management Office

National Data Management Office

NDMO
Data management standardsAuthority: Part of the Saudi Data & AI Authority (SDAIA)
Official website

The National Data Management Office (NDMO) is the national regulator and reference for data management and governance in the Kingdom, and it is part of the Saudi Data & AI Authority. It issued the Data Management and Personal Data Protection Standards, organized into 15 knowledge domains, which entities and their partners are required to apply and against which compliance is measured periodically.

Key aspects

  • The Data Management and Personal Data Protection framework and standards (15 knowledge domains)
  • Data classification and controls for its availability and sharing between entities
  • Data governance, quality, and management of reference and master data
  • Open data and freedom of information
  • Data protection and security and enabling the Personal Data Protection Law

How Mstnd applies it

  • Classifies documents and data and manages their metadata
  • Defines the owner of each document and the responsibilities associated with it
  • Controls confidentiality levels and the rules for availability and sharing between teams
  • Manages the document lifecycle and retention and disposal periods
  • Documents every operation on data in a complete audit trail

Cybersecurity & International Standards

National Cybersecurity Authority

National Cybersecurity Authority

NCA
Cybersecurity controlsAuthority: The national reference for cybersecurity in the Kingdom
Official website

The National Cybersecurity Authority (NCA) is the national reference for cybersecurity in the Kingdom. It issued the Essential Cybersecurity Controls (ECC), which comprise 5 domains, 29 subdomains, and 114 controls, in addition to the controls for critical systems and cloud computing, aiming to raise the level of protection of entities' information and technology assets.

Key aspects

  • The Essential Cybersecurity Controls ECC: 5 domains, 29 subdomains, and 114 controls
  • Cybersecurity governance and risk management
  • Cybersecurity defense: identity, access, encryption, and logging
  • Cybersecurity resilience and business continuity
  • Third-party and cloud computing security

How Mstnd applies it

  • Manages identity and access through Firebase Auth, signed JWT tokens (RS256), and httpOnly sessions with token rotation
  • Applies the least-privilege principle through a 13-layer guard chain and 90+ granular permissions
  • Encrypts data at rest and in transit and isolates each organization's data
  • Records events in immutable audit trails and monitors them
  • Protects against denial-of-service attacks through Cloud Armor and rate limiting
  • Validates inputs, prevents database injection, and covers the OWASP Top 10
ISO/IEC 27001

ISO/IEC 27001

ISO/IEC 27001
International standard for information securityAuthority: The International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC)
Official website

ISO/IEC 27001 is the most renowned international specification for information security management systems (ISMS), providing a framework to establish, maintain, and continually improve an information security management system. It adopts a holistic approach that spans people, policies, and technology together, and its controls cover four themes: organizational, people, physical, and technological.

Key aspects

  • Assessing and treating information security risks systematically
  • Applying the Annex A controls across organizational, people, physical, and technological themes
  • Access control, permission management, and encryption
  • Operations security and security incident management
  • Managing supplier relationships and continual improvement

How Mstnd applies it

  • Applies information security controls in line with the principles of ISO/IEC 27001 and international best practices
  • Manages permissions and protects information assets through a granular permissions model
  • Encrypts data, controls access, and logs events
  • Manages incidents and provides backups and recovery (Cloud SQL PITR)
  • Adopts continual improvement of policies and operational controls
Google Cloud

Google Cloud

Google Cloud
Cloud infrastructure and hostingAuthority: Google
Official website

Google Cloud is Google's cloud infrastructure and services platform (hosting, compute, and storage), holding the foremost global security accreditations and certifications such as ISO/IEC 27001 and SOC reports. Mstnd is built on Google Cloud's secure infrastructure to benefit from scalability, high availability, and protection of the underlying infrastructure.

Key aspects

  • Cloud infrastructure holding global security accreditations (ISO/IEC 27001, SOC)
  • Scalability and High Availability
  • Secrets, key management, and encryption
  • Backup and disaster recovery
  • Protection against denial-of-service attacks at the infrastructure level

How Mstnd applies it

  • Runs its services on Cloud Run with immutable containers and no SSH access
  • Keeps secrets in Google Secret Manager, away from the code
  • Uses Cloud SQL with a private address, an encrypted connection (SSL), and backups for point-in-time recovery (PITR)
  • Distributes files through time-limited signed links with retention policies for storage
  • Protects the front end through Cloud CDN and Cloud Armor against denial-of-service attacks

Digital Governance & Document and Records Management

Digital Government Authority

Digital Government Authority

DGA
Government digital governanceAuthority: The national regulator for digital government
Official website

The Digital Government Authority (DGA) is the regulator for digital government in the Kingdom, established by Cabinet Resolution No. (418). It sets the policies, standards, and frameworks for government digital transformation, governs government cloud computing, and measures the maturity of entities in delivering digital services.

Key aspects

  • Government digital transformation policies, standards, and frameworks
  • Governance of government cloud computing
  • Measuring the maturity of entities in digital services
  • Raising the efficiency, reliability, and transparency of digital services

How Mstnd applies it

  • Governs the document lifecycle from creation to archiving
  • Defines roles and responsibilities through a clear organizational structure
  • Documents and tracks every action in an audit trail
  • Integrates with systems through APIs and supports digital identity (Nafath)
  • Provides reliable and transparent management of digital records
National Center for Archives & Records

National Center for Archives & Records

NCAR
Document and records managementAuthority: The national reference for archives and records
Official website

The National Center for Archives & Records (NCAR) is the national reference for document and records management in the Kingdom, established by Royal Decree No. (M/55). It regulates the preservation, classification, indexing, retention periods, and disposal of documents and records, identifies documents of permanent value, and oversees digital archiving.

Key aspects

  • Regulating the preservation of documents and records in line with the archives and records law
  • Retention and disposal schedules for documents
  • Indexing, classification, and coding
  • Preserving documents of permanent value
  • Digital archiving of documents

How Mstnd applies it

  • Provides complete electronic archiving of documents and records
  • Applies retention schedules, document review, and secure disposal
  • Indexes, classifies, and codes documents through structured numbering and metadata
  • Controls versions and preserves the history of every change
  • Documents access and changes in an audit trail

Digital Identity & Enterprise Classification

Nafath (National Single Sign-On)

Nafath (National Single Sign-On)

Nafath
National digital identityAuthority: The National Information Center — Saudi Data & AI Authority
Official website

Nafath is the national single sign-on system for digital identity in the Kingdom, developed by the National Information Center under the Saudi Data & AI Authority. It lets citizens and residents verify their identity securely through their Absher account without entering sensitive data in every service, and it is used to verify the identity of a user or signatory across hundreds of government and private services.

Key aspects

  • A national single sign-on system for digital identity
  • Secure verification of a user's or signatory's identity without passwords or paper documents
  • Linked to the Absher account and part of the National Information Center
  • Supports biometric verification and digital signing

How Mstnd applies it

  • Integrates with Nafath to verify the identity of the signatory and external parties during signing and approval
  • Links the verification result to the signing action and stores its time and outcome in the action log
  • Grants electronic signatures a trusted level of identity verification
General Authority for SMEs (Monsha'at)

General Authority for SMEs (Monsha'at)

Monsha'at
Enterprise classification and enablementAuthority: A government entity organizationally linked to the Ministry of Commerce
Official website

Monsha'at is the General Authority for Small and Medium Enterprises, established in 2016 by Cabinet Resolution No. (301). It is concerned with organizing, supporting, and developing the SME sector in line with global best practices, so as to raise its contribution to GDP. It is responsible for classifying enterprises and issuing proof of their classification.

Key aspects

  • The regulator and supporter of the small and medium enterprise sector
  • Developing entrepreneurship and innovation and diversifying funding sources
  • Administrative and technical support and training programs for enterprises
  • Classifying enterprises and issuing the enterprise classification certificate

How Mstnd applies it

  • Mstnd is a Saudi system from a company registered and classified with Monsha'at
  • Designed to enable small and medium enterprises to manage their documents professionally
  • Provides enterprise-grade governance, archiving, and security tailored to SMEs

Frequently asked questions about accreditations and compliance

Does Mstnd apply the requirements of the Personal Data Protection Law (PDPL)?

Yes. Mstnd applies personal data protection requirements by classifying documents that contain personal data, restricting access on a least-privilege basis, encrypting data at rest and in transit, logging every access and processing action in an immutable audit trail, managing retention periods and secure disposal, and empowering data subjects to exercise their rights to access, correct, and obtain a copy.

How does Mstnd comply with the National Data Management standards (NDMO)?

Mstnd applies the NDMO standards by classifying documents and managing their metadata, defining the owner and responsibilities, controlling confidentiality levels and the rules for availability and sharing, managing the document lifecycle and retention periods, and documenting every operation on data in a reviewable log.

Does Mstnd comply with the controls of the National Cybersecurity Authority (NCA)?

Yes. Mstnd applies controls aligned with the Essential Cybersecurity Controls through identity and access management, the least-privilege principle, data encryption, event logging, backups, protection against denial-of-service attacks, isolation of each organization's data, and coverage of the OWASP Top 10.

Does Mstnd apply the ISO/IEC 27001 controls?

Yes. Mstnd applies information security controls in line with the principles of the international standard ISO/IEC 27001 and international best practices, from risk assessment, permission management, and protection of information assets to incident management and continual improvement.

What infrastructure does Mstnd run on?

Mstnd runs on Google Cloud's secure infrastructure, which holds the foremost global security accreditations, with immutable containers, secrets management, databases on a private address with an encrypted connection and recovery backups, and protection against denial-of-service attacks.

Does Mstnd support signing and identity verification through Nafath?

Yes. Mstnd integrates with Nafath to verify the identity of the signatory and external parties during signing and approval, links the verification result to the signing action, and stores it in the action log.

Is Mstnd a Saudi system?

Yes. Mstnd is a Saudi system from a company registered and classified with the General Authority for Small and Medium Enterprises (Monsha'at), built to serve enterprises in the Kingdom in line with its laws and regulatory frameworks.

Accreditations and regulatory frameworks, applied in every document

Explore how Mstnd turns national and international laws and frameworks into real controls that protect your organization's documents and data.

Request a demoDiscuss your requirements with our team
Explore the layers of protection, permissions, and security inside Mstnd

Complete the picture

Archiving & retention managementOrganizational structure & permissionsElectronic signature & NafathIntegrations & APIAudit trail & version control
Mstnd logo

A cloud document management system built for companies and organizations in Saudi Arabia.

Product

  • Features
  • Pricing
  • Industries
  • Scanning & digitization
  • Integrations
  • Why Mstnd?

Support

  • Contact us
  • Contact Sales
  • Book a meeting
  • Learning resources

Company

  • About
  • Blog

Legal

  • Security
  • Compliance & Accreditations
  • Privacy
  • Terms

Information

Unified Company Number
7037370603
National Address
RADC3385, Al Nada District, Riyadh 13317
Detailed Address
3385 Al Thumamah Street, Building 8398, Saudi Arabia

Accreditations & Partners

Communications, Space & Technology Commission
Saudi Business Center
National Data Management Office (NDMO)
Digital Government Authority (DGA)

All rights reserved © 2026 Unique Content for Information Technology

LinkedInXInstagramYouTube
Developed byUC Tech logo
Chat with us on WhatsApp