Country guide · Qatar

Cyber security compliance in Qatar

Qatar's National Cyber Security Agency sets one national information assurance standard for all organisations, certifies against it, and is also the competent authority for personal data. Qatar Central Bank adds technology, cloud and data rules for financial institutions, and the Qatar Financial Centre runs its own regime. This page sets out who must meet what.

At a glance
  • Frameworks listed7
  • Issuing bodies3
  • Framework pages6
  • Platform languagesEnglish and Arabic
  • DeploymentSaaS, private cloud or on-premises
QatarChecked Sep 2026

Which cybersecurity frameworks apply in Qatar?

The National Information Assurance Standard applies across the board: NCSA scopes version 2.1 to all organisations operating in Qatar, used alongside the National Data Classification Policy, with its baseline controls mandatory. Financial institutions add Qatar Central Bank's technology risk, cloud and data handling regulations. Firms in the Qatar Financial Centre follow the QFCRA's rules instead of QCB's.

What is the current version of NIAS?

Version 2.1, reviewed and approved in May 2023. The history runs from version 1.0 in 2010 to 2.0 in 2014 and 2.1 in 2023, and no version 3 has been published. Descriptions of NIAS as eleven domains with Basic, Advanced and Critical tiers describe an older structure; version 2.1 organises controls across 26 domains with confidentiality, integrity and availability ratings.

A frequent confusion is between NIAS and the NISCF Audit Standard version 3.0. The audit standard governs how certification audits are run. It is not a new edition of NIAS.

How does NIA certification work?

NCSA certifies organisations against NIAS under its national information security compliance framework. Audits are carried out by NCSA-accredited auditors and certificates are valid for three years. Organisations holding a certificate against version 2.0 re-certify against version 2.1.

What do QCB's cloud and data rules require?

QCB's Cloud Computing Regulation has been in force since 15 April 2024 and requires QCB approval before material cloud arrangements. Its Data Handling and Protection Regulation sets retention, officer and breach notification duties for licensed institutions. Both sit alongside the Technology Risks Regulation for banks and the cyber security regulation for insurers.

Who enforces personal data protection in Qatar?

NCSA is the competent authority for Law 13/2016 on the Protection of Personal Data Privacy, and it publishes guidelines for regulated entities on impact assessments, breach handling, records of processing and privacy by design. Pages naming the former communications ministry as the regulator are out of date. The Qatar Financial Centre runs its own data protection regulations.

How GRCLens runs Qatari frameworks together

NIAS, the QCB regulations and the PDPPL share one control model in GRCLens, so a bank evidences an access control once for NIAS certification and for QCB. Baseline NIAS controls are tracked as mandatory, and certification cycles carry their renewal dates. The platform runs in English and Arabic and can be hosted in Qatar or fully on-premises.

Questions

Cyber compliance in Qatar: common questions

What is the latest version of Qatar's NIAS?

Version 2.1, reviewed and approved in May 2023. No version 3 of the standard has been published.

Is NIAS mandatory in Qatar?

NCSA scopes NIAS v2.1 to all organisations operating in Qatar, and its baseline controls are mandatory.

How long does NIA certification last?

Three years. Certification audits are carried out by NCSA-accredited auditors.

When did the QCB Cloud Computing Regulation take effect?

15 April 2024. It applies to QCB-licensed entities using cloud services.

Who regulates personal data protection in Qatar?

The National Cyber Security Agency is the competent authority for Law 13/2016. The Qatar Financial Centre runs its own data protection regulations.

Sources

Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.

Run Qatar's frameworks on one platform

See GRCLens with your own frameworks loaded.