Compliance Colleague · Guides
Guides
- Gulf breach-notification clocks: six countries, one table
Saudi Arabia, the UAE (onshore, DIFC, ADGM), Kuwait, Oman, Qatar and Bahrain: the deadline to the regulator and to data subjects, with sources.
Updated September 30, 2026 - How many requirements are in ISO 27001? It depends what you count
There is no official count. The requirements sit in clauses 4 to 10; Annex A's 93 controls are selected through your Statement of Applicability.
Updated September 24, 2026 - What changed in PCI DSS 4.0.1, and what didn't
No new requirements, but real changes to patching, MFA, payment-page scripts and SAQ A, with requirement numbers.
Updated September 29, 2026
Research aid only. Not legal advice.