We design our audits and managed-protection controls around real, current international and regional frameworks — not a generic checklist. Here's exactly what that means, honestly.
Frameworks we build controls around — talk to us about your specific requirements.
Vercaa designs its security audits and managed-protection controls around ISO/IEC 27001:2022, PCI DSS 4.0.1, the UAE Personal Data Protection Law and Information Assurance Standards, the CBUAE Cybersecurity Framework, Jordan's Personal Data Protection Law and GDPR's core principles. This describes alignment with published frameworks, not a formal third-party certification.
Our audits, incident response, and managed-protection controls are designed with these real, current, published frameworks in mind.
The current international standard for information security management — 93 Annex A controls across 4 themes. Our audit methodology and managed-protection controls are aligned with this structure.
The payment-card-industry data security standard — fully mandatory since March 31, 2025. Directly relevant to any banking, fintech, or e-commerce client handling card data.
Federal Decree-Law No. 45 of 2021 — the UAE's federal data-privacy law. We design data-handling controls with its principles in mind for clients it applies to (note: government, health, and financial-sector data fall under separate regimes).
The UAE's national technical cybersecurity standard, under the UAE Cybersecurity Council — a real benchmark for government and regulated-sector clients in the region.
The UAE Central Bank's mandatory baseline for licensed banks and finance companies, structured around five domains — Govern, Identify, Protect, Detect, Respond. Our banking-sector engagements map to this structure.
Law No. 24 of 2023, in force since March 2024 — relevant regional context for clients operating in or serving Jordan.
For clients with EU-adjacent data, we design around GDPR's core principles — lawfulness, purpose limitation, data minimization, and accountability.
These are frameworks our controls and methodology are designed around — not a claim that Vercaa holds a specific third-party certification or audit for any of them. Ask us directly which specific compliance requirements apply to your organization and sector, and we'll give you a straight answer.
Message us directly with your sector and jurisdiction — we'll give you a straight answer on what applies and how we can help.