Skip to content

Saudi Arabia's Dedicated B2B Cybersecurity Procurement Platform.

Procure with proof, governed by AYN. Standardize technical scoping into Saudi MoF format, discover vetted Saudi providers, evaluate proposals on merit, and lock milestone payouts to Signit digital signatures.

NCA ECC-2:2024 Aligned
SAMA CSF v3.1 Matched
Signit Governed Contracts
100% In-Kingdom Data Lock
cyberayn.com/workspace/tender-sa-4910
Riyadh Enterprise Pod · #RFP-SA-4910 · Multi-Service Scope
Cybersecurity Project: GRC, Pen Testing & Managed SOC
Status:Committee Review Active
Project Scope
3 ServicesBundled
GRC · PT · 24/7 SOC
NCA Alignment
100%ECC & CSF
138 Mandatory Controls
Proposals
4 BidsVetted
Sealed Submissions
MULTI-SERVICE EVALUATION · 60% TECHNICAL / 40% COMMERCIAL Recommended Award
Proposal A · Accredited Tier-1 Saudi ProviderRECOMMENDED AWARD
95.4 / 100Capability Score
01. GRC Compliance100% Mapped

NCA ECC-2:2024 & SAMA CSF gap assessment with remediation roadmap.

02. Penetration TestingFull Scope

External black-box attack surface, web apps, and Active Directory retests.

03. 24/7 Managed SOC< 15m SLA

Continuous SIEM ingestion, live threat triage, and automated containment.

04. Sovereign Staffing100% In-Kingdom

Dedicated on-soil Saudi engineers (OSCP, CISSP, CISA) with local clearances.

MOC Verified NCA Licensed Operator CREST & ISO 27001
Select Bidder Submission to Inspect:
Committee Finding: Proposal A covers all 3 services with verified local engineering.Execute via Signit
Sovereign Compliance
NCA ECC-2:2024
SAMA CSF v3.1
Signit Digital Signatures
PDPL Sovereign Lock
NCA CSCC
NCA CCC
DGA Standards
CST CCRF
NCA ECC-2:2024
SAMA CSF v3.1
Signit Digital Signatures
PDPL Sovereign Lock
NCA CSCC
NCA CCC
DGA Standards
CST CCRF

Vetted Service Providers

Explore Verified Cohort
DeepSource logo
IGRC Square logo
Sahara Net logo
Resilience logo
DeepSource logo
IGRC Square logo
Sahara Net logo
Resilience logo
DeepSource logo
IGRC Square logo
Sahara Net logo
Resilience logo
+ and more
40+ Vetted Providers
01. Scope & Specification

Turn Plain Language into MoF Deliverables in Seconds.

Say goodbye to 8 to 12 weeks of consultant drafting. AYN analyzes your infrastructure footprint, uncovers latent regulatory exposure, and generates a concrete Ministry of Finance-standard technical tender.

100% deterministic Table of Quantities with binding deliverable minimums
Direct mapping across 138 NCA ECC-2:2024 and SAMA CSF controls
Zero scope drift: suppliers bid on identical, concrete specifications
ayn.cyberayn.com/scoping/tender-4910
100% CONCRETE BoQ
Standardized Technical RFPTechnical Procurement Specification
NCA ECC-2 AUDITED
01. GRC Compliance Baseline AssessmentNCA ECC § 1.1–§ 5.4 · 138 mandatory controls audited
Complete
02. Penetration Testing & Red Team Exercise14 Cloud VPCs, 12 Web Apps & Active Directory Domain
4 Cycles
03. 24/7 Managed SOC & Incident ContainmentTier-2/3 Saudi-soil analysts · Sub-15m critical containment SLA
12 Mos
Confidential Budget: SAR •••••• [Sealed Until Technical Bar]Synthesis: 84 Seconds
registry.cyberayn.com/provider/ksa-defense-pod
100% ON-SOIL
Verified Saudi Cybersecurity ProviderNational Defense & Cyber Assurance Operator
ACCREDITED TIER-1
Commercial Reg.
CR #1010•••••• (Active)Ministry of Commerce Verified
Regulatory License
NCA Lic. #CY-••••••National Authority Approved
Technical Standards
CREST & ISO 27001International Gold Standard
On-Soil Staffing
100% In-KingdomOSCP, CISSP, CISA Cleared
Milestone Delivery Score: 98.4% (24 Engagements)Riyadh Pod Vetted
02. Sovereign Verification

Pre-Vetted Saudi Providers. Zero Sales Hype.

Never buy cybersecurity on blind trust again. Every provider on Cyberayn passes rigorous institutional verification before submitting a single proposal.

Ministry of Commerce commercial registration validation and active status
Confirmed on-soil engineering talent with national security clearances
Track record audited by previous Saudi buyers with verified milestone releases
03. Contract Governance

Governed by Signit. Signed Contracts & Verified Delivery Acceptance.

Engagement agreements and milestone delivery notes are executed via Signit digital signatures, compliant with the Saudi Electronic Transactions Law and Digital Government Authority (DGA) standards. Work progresses in sequential stages with verified deliverables.

Legally binding agreement execution via Signit under Saudi Electronic Transactions Law
Sequential milestone gating: review deliverable evidence stage by stage
Signit delivery acceptance notes and timestamped audit logs for boards and regulators
signit.cyberayn.com/contracts/SGT-SA-9042
DGA ACCREDITED
Signit Digital Contract ExecutionEngagement Agreement #SGT-SA-9042
STAGE 2 ACTIVE
Stage 1: Architecture Review & Gap AnalysisAudit dossier uploaded · Verified against NCA ECC-2:2024
APPROVED
Stage 2: Penetration Testing & ExploitationRed team report submitted. Awaiting committee confirmation
IN REVIEW
Stage 3: 24/7 Managed SOC HandoverUnlocks automatically upon Stage 2 sign-off
LOCKED
Saudi Electronic Transactions Law · DGA Stamped
Hash: 0x9B4F...82AE

Tailored digital security solutions

From 24/7 sovereign SOC monitoring to offensive red teaming and national authority audits. Scope your mandate with concrete line-item deliverables.

01

Detection and Response

Continuous 24/7 SIEM threat hunting, incident triage, and automated containment to safeguard your crown jewels with sub-15 minute isolation SLAs.

Mandatory Table of Quantities
  • 850 Monitored Endpoints & Agent Telemetry
  • 4 Sovereign VPCs & In-Kingdom Log Ingestion
  • Sub-15 Minute Active Incident Containment SLA
SAMA CSF § 4.1 & NCA ECCSAR 32,000 / mo
Scope with AYN
02

Offensive Security

Specialized adversary simulations, external attack surface diagnostics, and Active Directory penetration tests to prove security readiness and verify remediation.

Mandatory Table of Quantities
  • 12 Web Applications & Public Perimeter Attack Surface
  • Full Exploitation Proof-of-Concepts & CVSS Scoring
  • Complimentary 30-Day Remediation Retest & Attestation
NCA CSCC § 2.8.2 & SAMASAR 45,000 / audit
Scope with AYN
03

NCA & SAMA Compliance

Comprehensive gap assessments, governance policy blueprints, and board-ready evidence dossiers aligned directly to National Cybersecurity Authority mandates.

Mandatory Table of Quantities
  • 138 Controls Mapped with Evidence Artifact Blueprints
  • Executive Board Summary & Prioritized Gap Roadmap
  • PDPL Sovereign Data Residency Attestation Dossier
NCA ECC-2:2024 & PDPLSAR 60,000 / audit
Scope with AYN
Want to inspect a full Saudi Ministry of Finance tender specification?
84 Sec

Average Tender Drafting

Replaces 8 to 12 weeks of consultant drafting with instant, concrete Saudi MoF specifications.

100%

NCA & SAMA Control Coverage

Direct auto-mapping against NCA ECC-2:2024, CSCC, and SAMA CSF frameworks.

SAR 0

Buyer Cost to Scope & Source

Zero upfront platform fees or tender bidding commissions for enterprise procurement teams.

100%

In-Kingdom Data Lock

Full PDPL compliance with dedicated on-soil sovereign cloud infrastructure and zero leakage.

Institutional Procurement Questions

More on the About page
No. You pay your provider directly. Cyberayn tracks milestones and acceptance so both sides share one record of what was agreed and delivered. The platform charges its own fees separately, and buyers source for free.

Make your next cybersecurity purchase the confident one.

Scope your regulatory tender in minutes, compare verified providers on merit, and track delivery to acceptance.

Zero speculative bidding or vendor lock-in
•
100% In-Kingdom Saudi Data Residency