Three Romanian entrepreneurs are expanding their Dubai-based compliance technology company, Mizan Comply, across the Gulf Cooperation Council (GCC), following the platform’s presentation at GISEC Global 2026
Following GISEC Global 2026, Three Romanian Entrepreneurs Accelerate Mizan Comply’s Expansion Across the GCC.
Romanian entrepreneurs Simona Biță, Andrei Buiu and Ion Sapoval are developing Mizan Comply in Dubai, a compliance automation platform built specifically for organisations operating across the Gulf Cooperation Council (GCC) region. Following the platform’s presentation at GISEC Global 2026, the company is entering a new phase of commercial development, with a focus on the United Arab Emirates, Saudi Arabia and the wider GCC market.
Romanian entrepreneurs Simona Biță, Andrei Buiu and Ion Sapoval are developing Mizan Comply from their base in Dubai. The compliance automation platform is designed for organisations operating across the Gulf Cooperation Council (GCC) region — the United Arab Emirates, Saudi Arabia, Bahrain, Kuwait, Oman and Qatar.
The company is positioning Mizan Comply as a regional technology platform designed from the outset around the cybersecurity, data protection, governance and audit requirements faced by organisations operating across GCC markets.
Mizan Comply was presented at GISEC Global 2026, held from 16 to 18 September at the Dubai Exhibition Centre, Expo City Dubai. The event provided the team with an opportunity to demonstrate the platform to cybersecurity professionals, organisations and potential regional partners. GISEC describes itself as the Middle East and Africa’s largest cybersecurity event.
Simona Biță — Co-Founder & Chief Operating Officer (COO); Andrei Buiu — Co-Founder & Chief Executive Officer (CEO), Mizan Comply; and Ion Sapoval — Co-Founder & Chief Technology Officer (CTO), Mizan Comply.
Following discussions held during GISEC, Mizan Comply is now focusing on expanding its client base and building a network of commercial and technology partners across the GCC.
One Platform for an Increasingly Complex Compliance Landscape
Organisations across the GCC operate in an increasingly complex regulatory environment, with cybersecurity, data protection, governance and audit requirements varying between jurisdictions and industries.
When these processes are managed through spreadsheets, documents and disconnected tools, compliance can become costly, difficult to track and heavily dependent on manual work.
Mizan Comply brings controls, responsibilities, policies, documents and compliance evidence together within a single platform.
The platform currently supports six key frameworks and standards: NESA IAS (the UAE Information Assurance Standards), ADHICS (the Abu Dhabi Healthcare Information and Cyber Security Standard), NCA ECC (Saudi Arabia’s Essential Cybersecurity Controls), PDPL (Saudi Arabia’s Personal Data Protection Law), ISO 27001 (the international standard for information security management systems) and CIS Controls v8 (a set of prioritised cybersecurity safeguards and best practices).
Its architecture is designed to support the addition of further regulatory and compliance requirements relevant to organisations operating across GCC markets.
From Manual Processes to Continuous Compliance
Mizan Comply aims to transform compliance from a fragmented, periodic and predominantly manual exercise into a continuous operational process.
The platform provides real-time compliance monitoring, allowing organisations to track controls, responsibilities, deadlines and supporting evidence from a centralised environment.
It also provides centralised evidence management with audit trails and expiry tracking, AI-assisted policy generation, structured audit reporting, secure auditor access and continuous compliance monitoring.
One of the platform’s key capabilities is the ability to collect evidence once and reuse it across multiple frameworks where requirements and controls overlap. This can reduce repetitive administrative work for organisations managing several compliance obligations simultaneously.
Compliance data is hosted in the United Arab Emirates, an important consideration for organisations for which regional data residency and sovereignty are priorities.
“Built for the GCC, Not Adapted for It”
The founders see Mizan Comply’s regional focus as one of the company’s main differentiators.
Rather than developing a global product and subsequently adapting it for the Middle East, the team chose to build the platform in the region, starting with the regulatory requirements and operational realities of GCC organisations.
“We built Mizan here because we want to solve the compliance challenges faced by organisations operating here. The UAE is our base, but the market we are addressing is the entire GCC region. Companies need more than a collection of documents and checklists. They need a system that allows them to continuously demonstrate where they stand from a compliance perspective and clearly understand what still needs to be done.”
— Andrei Buiu, Co-Founder and CEO, Mizan Comply
GISEC Global 2026: Taking Mizan Comply to the Regional Market
GISEC Global 2026 represented an important step in bringing Mizan Comply directly to the region’s cybersecurity ecosystem.
During the event, the team demonstrated how the platform centralises compliance controls and evidence, generates policies, monitors progress and structures the information required for audit processes.
The event is designed to bring cybersecurity companies and startups into direct contact with buyers, decision-makers, investors and potential strategic partners, making it a relevant platform for Mizan Comply’s regional commercial development.
Ion Sapoval — Co-Founder & Chief Technology Officer (CTO)
For Mizan Comply, discussions held during GISEC generated new conversations with potential clients and regional partners. The company is now focusing on turning that interest into commercial projects and long-term partnerships.
Alongside direct enterprise customers, Mizan Comply is seeking collaborations with auditors, cybersecurity consultants, security companies and specialised service providers that could use the platform to manage compliance programmes for their own clients.
Three Romanian Founders with Complementary Expertise
Behind Mizan Comply are Simona Biță, Andrei Buiu and Ion Sapoval, three Romanian entrepreneurs whose backgrounds combine business operations, cybersecurity and technology.
The three founders first worked together between 2017 and 2020 at a Dutch company specialising in digital advertising technology, where they collaborated across technology, operations and business development.
They later founded another company together, which they developed and subsequently sold.
For their next entrepreneurial venture, they chose Dubai as their base and the GCC as their primary market.
Andrei Buiu, Co-Founder and Chief Executive Officer, has more than a decade of experience in cybersecurity and secure technology development. He leads the company’s strategy and product direction.
Simona Biță, Co-Founder and Chief Operating Officer, has experience in building, developing and managing companies. She oversees operational strategy, financial management, team development and business scaling.
Ion Sapoval, Co-Founder and Chief Technology Officer, is a software architect and technology leader with experience in technology and product development, as well as building engineering teams. He oversees Mizan Comply’s technical architecture and the evolution of the platform.
The Next Step: Expanding Across the Six GCC Markets
Following GISEC Global 2026, Mizan Comply is focusing on expanding its commercial presence across the six Gulf Cooperation Council markets: the United Arab Emirates, Saudi Arabia, Bahrain, Kuwait, Oman and Qatar, with Dubai serving as the company’s regional base.
The company is targeting both organisations building structured compliance programmes for the first time and companies already managing multiple standards, regulations and audit processes.
Another area of growth is collaboration with auditors, consultants and cybersecurity service providers that can use Mizan Comply to manage compliance processes for their own clients.
The company’s objective is to establish Mizan Comply as a regional compliance technology platform combining GCC-specific regulatory knowledge, automation and continuous audit readiness.
Organisations interested in the platform can request a demonstration and contact the team through Mizan Comply.
About Mizan Comply
Mizan Comply is a compliance automation platform developed in Dubai for organisations operating across the Gulf Cooperation Council (GCC) region — the United Arab Emirates, Saudi Arabia, Bahrain, Kuwait, Oman and Qatar.
The platform centralises controls, responsibilities, policies, documents and compliance evidence, helping organisations manage regulatory requirements and audit preparation more efficiently.
Mizan Comply currently supports NESA IAS, ADHICS, NCA ECC, PDPL, ISO 27001 and CIS Controls v8, while compliance data is hosted in the United Arab Emirates.
About Nine O’Clock
Nine O’Clock, Romania’s first English-language daily newspaper, celebrated its 34th anniversary with an elite event dedicated to diplomacy, leadership, and international dialogue: “Voices of Diplomacy and Leadership,” organized in partnership with the Embassy of the Hellenic Republic in Bucharest. The event took place at the Embassy of the Hellenic Republic in Bucharest on Tuesday, 11 November 2025, starting at 3:00 PM. It also marked the launch of the book “Top Interviews, Messages & Speeches from Ambassadors and CEOs – Second Edition, 2025”, a volume gathering strategic perspectives from global leaders.
Follow Nine O’Clock on LinkedIn, Facebook, Instagram and X for the latest updates on diplomacy, business and international affairs. Join our community of 8,000+ followers.
Explore our Digital Edition archives available in more than 150 countries (2024–2025–2026)
Nine O’Clock Daily (Romania) Online Archive | Back Issues 2024 – 2025 – 2026
Nine O’Clock Weekly (Romania) Online Archive | Back Issues 2024 – 2025 -2026
Nine O’Clock Yearbook (Romania) Online Archive | Back Issues 2024 – 2025
The diplomatic daily newspaper Nine O’Clock does not assume responsibility for the information received and published on the public website. The responsibility for the content lies solely with the issuer of the press release.
The diplomatic daily newspaper Nine O’Clock cannot be held accountable for false information transmitted by the recipients of the press releases/announcements.
The diplomatic daily newspaper Nine O’Clock reserves the right not to publish press releases that contain inappropriate expressions or accusations and violations of the rights of other individuals, guaranteed by the Constitution of Romania.
The content of the website www.nineoclock.ro is intended for public information. Copying, reproduction, recompilation, modification, as well as any form of content exploitation from this website are prohibited. The use of the Comments section signifies your agreement to abide by the terms and conditions regarding the publication of comments on www.nineoclock.ro.