Cyber Security · Compliance & Standards

Aligned with the standards
enterprise buyers actually ask for.

We design our audits and managed-protection controls around real, current international and regional frameworks — not a generic checklist. Here's exactly what that means, honestly.

  • ISO/IEC 27001:2022-aligned
  • PCI DSS 4.0.1-aligned
  • UAE & Jordan data-law aware
  • CBUAE-aligned for banking
Compliance Alignment Live
ISO 27001:2022
93 controls, 4 themes
PCI DSS 4.0.1
Mandatory since Mar 2025
UAE PDPL & IAS
Regional data-law aware
CBUAE
Banking-sector framework

Frameworks we build controls around — talk to us about your specific requirements.

Frameworks we build around

International standards, regional awareness.

Our audits, incident response, and managed-protection controls are designed with these real, current, published frameworks in mind.

ISO/IEC 27001:2022

The current international standard for information security management — 93 Annex A controls across 4 themes. Our audit methodology and managed-protection controls are aligned with this structure.

PCI DSS 4.0.1

The payment-card-industry data security standard — fully mandatory since March 31, 2025. Directly relevant to any banking, fintech, or e-commerce client handling card data.

UAE Personal Data Protection Law

Federal Decree-Law No. 45 of 2021 — the UAE's federal data-privacy law. We design data-handling controls with its principles in mind for clients it applies to (note: government, health, and financial-sector data fall under separate regimes).

UAE Information Assurance Standards

The UAE's national technical cybersecurity standard, under the UAE Cybersecurity Council — a real benchmark for government and regulated-sector clients in the region.

CBUAE Cybersecurity Framework

The UAE Central Bank's mandatory baseline for licensed banks and finance companies, structured around five domains — Govern, Identify, Protect, Detect, Respond. Our banking-sector engagements map to this structure.

Jordan Personal Data Protection Law

Law No. 24 of 2023, in force since March 2024 — relevant regional context for clients operating in or serving Jordan.

GDPR-Aligned Data Principles

For clients with EU-adjacent data, we design around GDPR's core principles — lawfulness, purpose limitation, data minimization, and accountability.

These are frameworks our controls and methodology are designed around — not a claim that Vercaa holds a specific third-party certification or audit for any of them. Ask us directly which specific compliance requirements apply to your organization and sector, and we'll give you a straight answer.

Questions

The honest answers

Is Vercaa ISO 27001 certified?
Our practices and controls are aligned with ISO/IEC 27001:2022's principles. Ask us directly about your organization's specific certification requirements — we'll give you a straight answer.
Can you help us pass a PCI DSS audit?
Yes — our security audit methodology maps directly onto PCI DSS 4.0.1's technical requirements, including the vulnerability scanning and testing it now mandates.
Which data protection law applies to us?
It depends on your sector and where your users are — UAE and Jordan each have their own personal data protection law, with sector-specific carve-outs for government, health, and financial data. Message us directly and we'll help you figure out what actually applies.
We're a bank — what specifically applies to us?
The CBUAE Cybersecurity Framework is the relevant baseline if you're UAE-licensed — our Managed Protection controls are built with its five domains in mind.
Do you handle compliance paperwork for us?
We help with the technical controls and evidence a compliance process actually requires. For formal certification/audit engagements themselves, we'll tell you honestly whether that's something we handle directly or coordinate alongside a specialist auditor.
Talk to us about compliance

Tell us what you're working toward.

Message us directly with your sector and jurisdiction — we'll give you a straight answer on what applies and how we can help.