National Cyber Security Agency (NCSA) · Qatar

Qatar National Information Assurance Policy compliance software

Qatar's national information assurance baseline for government agencies and critical infrastructure — 26 domains, 356 controls, the baseline tier tracked as mandatory.

At a glance
  • RegulatorNational Cyber Security Agency (NCSA)
  • Structure26 domains — 13 governance (Section B), 13 security controls (Section C)
  • Controls356, of which 165 are baseline and mandatory
  • ScoringImplemented · Partial · Not implemented, per control
Qatar NIAAvailable
Overview

What Qatar NIA requires

Who it applies to

  • Qatar government ministries, agencies and public bodies
  • Operators of critical information infrastructure in energy, finance, health, transport and telecoms
  • Service providers that access or process information assets for mandated organisations
  • Organisations preparing for NCSA compliance audit or certification

The National Information Assurance (NIA) Policy is the State of Qatar's foundational information security framework, administered by the National Cyber Security Agency. It is mandatory for government entities and for operators of critical information infrastructure in sectors such as energy, finance, healthcare and telecommunications, and it reaches service providers that access or process information on their behalf.

The manual is in two parts. Section B sets out thirteen governance domains — governance structure, risk management, third-party security, data labelling, change management, personnel, awareness, incident management, business continuity, logging and monitoring, retention, documentation, and audit and certification. Section C sets out thirteen security-control domains, from communications and network security through gateway, product, software, media, access-control and cryptographic security to portable devices, physical security and virtualisation.

Controls marked as baseline in the manual are mandatory for every agency whatever its business impact assessment concludes; the rest are applied according to the classification of the information handled. An assessment that treats the two tiers the same either over-reports gaps or, worse, reports the mandatory tier clear when it is not.

In the platform

How GRCLens supports Qatar NIA

Qatar NIA runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Baseline tier tracked as mandatory

The 165 baseline controls carry the manual's marker, so the dashboard reports the mandatory tier separately and a gap in it cannot hide behind a healthy average.

The manual's own reading order

Section B governance domains first, Section C security controls after, with NIA's own codes — including the ones that trip people up: AC is Audit & Certification, not access control, and OS is off-site working, not operating systems.

Evidence and deliverables per control

Each control names the deliverable an NCSA auditor expects — appointment letters, registers, configuration standards, logs — and evidence is attached against it once and reused wherever ISO/IEC 27001 asks for the same thing.

Arabic and English

Every control, category and guidance note is carried in both languages, so the assessment and the report read correctly to the agency and to the regulator.

Questions

Qatar NIA frequently asked questions

Who must comply with the Qatar NIA Policy?

Qatar government entities and operators of critical information infrastructure, as designated by the National Cyber Security Agency, together with service providers that access or process information assets on their behalf.

What does 'baseline' mean in the NIA manual?

Baseline controls are the minimum every agency must implement regardless of the outcome of its business impact assessment. GRCLens marks the 165 baseline controls as mandatory and reports them as a separate tier.

Does GRCLens issue NIA certification?

No. Certification is a matter for NCSA and its accredited auditors. GRCLens runs the assessment, holds the evidence and produces the reporting the audit works from.

Talk to us about Qatar NIA

Security Solution Consultants provides Qatar NIA readiness and advisory alongside the platform, so you can combine tooling with hands-on expertise.