DEGOOLCYBER SECURITY SOLUTIONS
CERTIFICATIONS & COMPLIANCE

Audited, attested, evidenced

We hold our own certifications and map every control we operate on your behalf back to the frameworks your auditor cares about.

ISO/IEC 27001

Information security management system covering all managed services.

CERTIFIED · RENEWED 2026

ISO/IEC 27701

Privacy information management extension for personal-data processing.

CERTIFIED

SOC 2 Type II

Security, availability and confidentiality trust service criteria.

ATTESTED · ANNUAL

PCI DSS 4.0

Qualified to support cardholder-data environment monitoring.

SERVICE PROVIDER LEVEL 1

CITRA Kuwait

Licensed cybersecurity service provider under national regulation.

LICENSED

GDPR / DPA

Data processing agreements and in-region residency guarantees.

COMPLIANT

NIST CSF 2.0

Control mapping and maturity assessment for client programmes.

ALIGNED

IEC 62443

Industrial automation and control system security for OT engagements.

ALIGNED

Control coverage matrix
Control domains mapped to ISO 27001, SOC 2 and NIST CSF
CONTROL DOMAINISO 27001 ANNEX ASOC 2 CRITERIANIST CSF 2.0DEGOOL COVERAGE
Identity & access managementA.5.15–A.5.18CC6.1–CC6.3PR.AA
96%
Threat detection & monitoringA.8.15–A.8.16CC7.2DE.CM
98%
Incident responseA.5.24–A.5.28CC7.3–CC7.5RS.MA
97%
Vulnerability managementA.8.8CC7.1ID.RA
94%
Configuration & change controlA.8.9, A.8.32CC8.1PR.PS
91%
Data protection & encryptionA.8.24CC6.7PR.DS
93%
Supplier & third-party riskA.5.19–A.5.22CC9.2GV.SC
88%
Logging & audit evidenceA.8.15CC4.1DE.AE
99%
Business continuityA.5.29–A.5.30A1.2RC.RP
86%

Find out what your telemetry is already telling you.

Two-week assessment: we ingest your existing logs, run the Sentinel detection pack, and hand back a prioritised findings report. No agents, no commitment.