For SAMA-regulated organisations

BCM software built for SAMA-regulated organisations

The platform KSA banks, insurers and fintechs use to map the full SAMA BCM Framework and ISO 22301 to one workspace. Schema-per-tenant data residency. Native §8.4.4 plans. Audit-ready PDFs in one click.

Who it’s for

Three buyer profiles, one platform

We don’t chase volume. We work with a focused group of SAMA-regulated organisations who want a platform built around their regulator, not retrofitted.

Tier-1 KSA bank

BCM Manager

Replace the 2015-era platform that can’t produce ISO 22301 §8.4.4-shaped plans without three weeks of consulting time. Stand up the SAMA annual programme in days, not quarters.

  • §8.4.4 native fields and §8.5 activation log
  • Programme coverage rollup against SAMA themes
  • PDF export the auditor can sign off

Mid-market insurer / fintech

CISO

Move BCM out of SharePoint + Excel before the next SAMA examination. Want a platform with serious data isolation and a schema your information security committee will actually approve.

  • Schema-per-tenant data isolation
  • 5-role RBAC with department scoping
  • Audit log on every mutation

Group internal audit

Head of Resilience

Need a platform that proves continuity capability across multiple business units, integrates with your existing audit and governance systems, and produces evidence trails an external auditor can sample.

  • Webhook-feed audit findings into BCMStack
  • BCMS evidence repository + attestation
  • Improvement actions traced to closure
What’s different

Four things no peer ships

These are the differentiators that come up in every demo with a SAMA-regulated buyer. Not slideware — verified in our integration test suite.

Schema-per-tenant data isolation

Every customer gets their own Postgres schema, accessed via SET LOCAL search_path inside transactions. Cross-tenant access is impossible by construction — different schemas, not row-level filters. Castellan, Fusion, Origami, LogicManager, Quantivate and 6clicks all use row-level. For an information security committee that wants to see the schema list, this is the difference between a yes and a no.

ISO 22301 §8.4.4 as native fields

Purpose, scope, activation criteria, activation authority, deactivation criteria, classification, target RTO and target RPO are discrete columns on the BCP record. An auditor can diff them across versions, search across plans, filter by classification. Peer platforms store them as free-text in a single description box.

§8.5 activation log as first-class

Every BCP invocation is captured as a structured row: activatedAt, activatedBy, triggerSummary, crisisEventId linkage, outcome, improvement-action count. Deactivation updates the same row in place. SAMA auditors specifically sample whether plans have been invoked rather than just authored. We make that evidence searchable.

SAMA coverage rollup

The annual exercise programme tracks SAMA's mandatory coverage themes — IT system loss, cyber, critical vendor unavailability, staff unavailability, workspace disruption. Each passing or partial exercise contributes its theme tags to the programme’s union. Failing exercises don’t. The view shows what’s covered vs what’s required, in real time.

How we compare

BCMStack vs Castellan, Fusion, Origami

Honest comparison on the dimensions that decide a SAMA-regulated deal. We update this when peer pricing or capabilities change.

FeatureBCMStackCastellanFusionOrigami
Schema-per-tenant data isolationYesRow-levelSalesforce orgRow-level
ISO 22301 §8.4.4 native fieldsYesFree-textFree-textFree-text
§8.4.5 phased recovery (respond/recover/restore)YesFlat listFlat listFlat list
§8.5 activation log as first-classYesVia crisis
SAMA coverage rollupYes
Modern stack (RSC / Next.js / Drizzle)YesSalesforce
Transparent pricingYesHiddenHiddenHidden
Native iOS/Android crisis appRoadmapYesSFDC mobile
SOC 2 / ISO 27001 attestationIn progressYesYesYes

See the full feature-by-feature comparison: BCMStack vs Castellan →

Pricing

Published price band

Mid-market SAMA-regulated organisations typically land here. Final pricing depends on user count, regulator scope and data-residency requirements.

Annual contract value
$30K – $60K

For a typical 100-500-employee SAMA-regulated organisation, all modules included.

Why we publish it

Most peers gate pricing behind a sales call. Many smaller customers walk away rather than start that conversation.

What’s included

All six modules, schema-per-tenant tenancy, audit log, PDF export, RBAC, support during business hours.

What’s extra

KSA-region data residency, custom integrations, dedicated implementation services, after-hours support.

Request a tailored quote
Implementation

14 days from contract to first BIA approved

Same-day workspace provisioning. Two weeks of focused work to a live BCMS and a tabletop in the calendar.

Day 1 – 3

Workspace + framework setup

  • Workspace provisioned with dedicated Postgres schema
  • User invitations sent (org_admin, BCM Manager, dept_heads)
  • Framework selection — SAMA, ISO 22301, ISO 22398
  • BCM committee + meeting cadence configured

Day 4 – 7

Process inventory + first BIA

  • Process / vendor / app / location import (CSV)
  • Configurable impact matrix tuned to your scale
  • First BIA wizard run for the most-critical service
  • Criticality auto-classification + heatmap

Day 8 – 10

First BCP authored

  • BCP §8.4.4 template — purpose, scope, activation criteria
  • RACI team + stakeholder communications matrix
  • Phased recovery steps (respond / recover / restore)
  • Plan submitted for review and approval

Day 11 – 14

First exercise + board pack

  • Annual test programme created with SAMA themes
  • First exercise scheduled (tabletop, walkthrough or simulation)
  • AAR template prepared with SAMA SLA dates auto-computed
  • Branded PDF board pack rendered for next committee
FAQ

Frequently asked questions

Where is BCMStack data hosted?

+

Each customer gets a dedicated Postgres schema on Neon (EU jurisdiction by default; KSA-region pinning is on the roadmap for customers with strict residency requirements). File storage uses Cloudflare R2 with EU jurisdiction. Cross-tenant access is impossible by construction — different schemas, not row-level filters.

How does BCMStack handle KSA data residency?

+

Schema-per-tenant is the architectural foundation. EU jurisdiction is the default for the GCC region. For customers with explicit KSA-residency contractual obligations, we provision a dedicated Neon project in a KSA-adjacent region — talk to us before you sign.

Does BCMStack support Arabic?

+

English UI is shipping today. Arabic UI with RTL layout, Hijri-calendar support and SAMA-Arabic terminology is on the roadmap — typically 2-3 weeks of work to enable across the top 8 pages once a customer specifically requires it.

How does BCMStack pricing compare to Castellan and Fusion?

+

BCMStack targets $30-60K annual contract value for mid-market. Castellan and Fusion typically land at $80-250K including required platform seats and implementation services. Our pricing is published — theirs requires a sales call.

Can BCMStack replace our existing BCM software?

+

Yes — most customers are migrating from Castellan, Fusion or a 2015-era platform, or from a SharePoint + Excel setup. Migration takes 4-8 weeks: we import process and vendor lists via CSV, recreate BCPs in our §8.4.4 native shape, and run the first exercise on the new platform within the first month.

Book a 20-minute demo

Tell us your organisation, your regulator, and where your BCM workflow lives today. We’ll show you the platform working against a representative SAMA dataset and answer the questions your information security committee will ask.

Request a demo

We aim to respond within one business day.