Guide · international frameworks

International frameworks alongside Omani rules

Omani law sets the floor. International clients, card networks and partners often ask for more. Here is when each framework applies and how they fit together.

Last verified against official sources: 26 September 2026

When each international framework applies
FrameworkWhat it isWhen it applies to an Omani firm
ISO/IEC 27001A certifiable standard for an information security management systemVoluntary. Often requested in tenders and by international clients, and a strong structure for the controls the Personal Data Protection Law expects.
SOC 2An attestation report under the AICPA Trust Services CriteriaVoluntary. Commonly requested by North American clients of service providers.
PCI DSSThe card industry's data security standardRequired by contract with the card networks wherever cardholder data is stored, processed or transmitted.
NIST CSF 2.0A voluntary framework organized around Govern, Identify, Protect, Detect, Respond and RecoverVoluntary. A useful common language for a risk program and for board reporting.
EU GDPRThe EU's data protection regulationWhere you offer goods or services to people in the EU or monitor their behavior.

One program, not five

The frameworks overlap more than they differ. A breach process that meets the 72 hours rules in the Executive Regulations also meets GDPR's 72 hours. Access control evidence for ISO/IEC 27001 also answers SOC 2 and PCI DSS. Map each control once, collect the evidence once, and report against each framework from the same record.

How AccuSights helps

We build that single control set, starting from the Personal Data Protection Law, and extend it to the frameworks your clients ask for. See our services.

AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the Ministry of Transport, Communications and Information Technology, the Cyber Defence Centre, OCERT, the Central Bank of Oman or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. English quotations of Omani law are translations; the Arabic text published in the Official Gazette is binding.

Sources

  1. ISO, ISO/IEC 27001 information security management (opens in a new tab)
  2. AICPA, System and Organization Controls reports, including SOC 2 (opens in a new tab)
  3. PCI Security Standards Council, PCI DSS (opens in a new tab)
  4. NIST, Cybersecurity Framework 2.0 (opens in a new tab)
  5. EUR-Lex, General Data Protection Regulation (EU) 2016/679 (opens in a new tab)

Ten minutes to know exactly where you stand

Tell us what you do and what data you hold. We will show you what the amended Personal Data Protection Law asks of you, where the gaps usually are, and the shortest route to ready. No slides, no pitch.