Tag · framework

NCA ECC

NCA Essential Cybersecurity Controls — the baseline for KSA entities.

Internal Audit Checklist for Saudi Arabia (Free Template)

A free internal audit checklist for Saudi functions — charter, universe, annual plan, engagement, reporting, QAIP, and the SAMA and NCA review obligations.

2026-08-26 · 6 min
NCA CCC Compliance Checklist (Free Template)

A free NCA CCC-2:2024 compliance checklist — the provider and tenant control sets, all four classification levels, and the evidence each subdomain needs.

2026-08-26 · 6 min
NCA CCC: Cloud Cybersecurity Controls Explained

A guide to NCA Cloud Cybersecurity Controls (CCC-2:2024) — the CSP and CST control sets, four classification levels, and the data localisation change.

2026-08-26 · 12 min
NCA CGIoT: Internet of Things Security Guidelines

A guide to the NCA Cybersecurity Guidelines for Internet of Things (CGIoT-1:2024) — four domains, 81 guidelines, and eleven principles for IoT manufacturers.

2026-08-26 · 10 min
NCA CSCC Compliance Checklist (Free Template)

A free NCA CSCC compliance checklist — the seven criticality criteria, all 21 subdomains, and the review, patching and testing cadences inspectors ask for.

2026-08-26 · 6 min
NCA CSCC: Critical Systems Cybersecurity Controls

A guide to NCA Critical Systems Cybersecurity Controls (CSCC) — the seven identification criteria, 32 controls, and the in-Kingdom access and hosting rules.

2026-08-26 · 11 min
NCA E-Commerce Cybersecurity Guidelines Explained

A guide to the NCA e-commerce cybersecurity guidelines — the seven CGESP categories for SME and SoHo sellers, and the consumer-facing CGEC companion document.

2026-08-26 · 9 min
NCA Toolkits and Implementation Guides Explained

A guide to the NCA Cybersecurity Toolkits and Implementation Guides — around 90 free policy, standard and procedure templates, and how to use them properly.

2026-08-26 · 9 min
NCA DCC Compliance Checklist (Free Template)

A free NCA DCC-1:2022 compliance checklist — the four classification levels, every control by data lifecycle stage, and the third-party sharing rules.

2026-08-26 · 6 min
NCA DCC: Data Cybersecurity Controls Explained

A guide to NCA Data Cybersecurity Controls (DCC-1:2022) — four classification levels, 19 controls across the data lifecycle, and third-party sharing rules.

2026-08-26 · 11 min
NCA National Cryptographic Standards (NCS) Guide

A guide to the NCA National Cryptographic Standards (NCS-1:2020) — the MODERATE and ADVANCED levels, accepted algorithms, TLS and PKI rules, and key lifetimes.

2026-08-26 · 11 min
NCA NFCRM: The National Cybersecurity Risk Framework

A practitioner's guide to the NCA National Framework for Cybersecurity Risk Management — scope, the four-phase methodology, the 5x5 matrix and Haseen reporting.

2026-08-26 · 19 min
NCA OSMACC: Social Media Account Security Controls

A guide to NCA OSMACC-1:2021 — the 15 controls protecting official Saudi social media accounts, from MFA and dedicated devices to impersonation monitoring.

2026-08-26 · 10 min
NCA OTCC: OT and ICS Cybersecurity Controls Guide

A guide to NCA Operational Technology Cybersecurity Controls (OTCC) — the three facility levels, 122 subcontrols, and the OT zone and remote access rules.

2026-08-26 · 11 min
NCA TCC: Telework Cybersecurity Controls Guide

A guide to NCA Telework Cybersecurity Controls (TCC-1:2021) — the 21 controls across three domains, BYOD and MDM rules, and offshore remote access monitoring.

2026-08-26 · 9 min
SCyWF: The Saudi Cybersecurity Workforce Framework

A guide to the NCA Saudi Cybersecurity Workforce Framework (SCyWF v1.5) — five categories, twelve specialty areas, forty job roles and the new competency areas.

2026-08-26 · 10 min
SAMA CSF & NCA Self-Assessment: A CISO's Guide

How Saudi CISOs run the periodic SAMA CSF and NCA ECC self-assessment in 2026 — the maturity model, evidence, control mapping and turning two assessments into one.

2026-06-30 · 12 min
Third-Party Risk Assessment in Saudi Arabia: SAMA & PDPL

How Saudi organisations run third-party and vendor risk assessment in 2026 — tiering, due diligence, right-to-audit clauses and monitoring under SAMA, NCA ECC and PDPL.

2026-06-30 · 14 min
SAMA, NCA & PDPL Incident Notification: Deadlines & Duties

Cyber incident classification, escalation and regulatory notification for Saudi Arabia — SAMA CSF, NCA ECC and PDPL/SDAIA obligations unified in one runbook.

2026-05-25 · 20 min
NCA ECC vs SAMA CSF: Saudi Arabia's Two Cybersecurity Frameworks Compared

The definitive comparison of NCA ECC and SAMA CSF — who must comply, control counts, assessment models, the 40% overlap, and how to satisfy both with unified evidence.

2026-05-25 · 6 min
Internal Audit Management Software in Saudi Arabia

How to choose internal audit management software in Saudi Arabia — the selection criteria that decide it, IIA/IPPF alignment, and a capability scorecard.

2026-04-08 · 9 min
Compliance Audit Saudi Arabia: SAMA, NCA & PDPL

A practical playbook for compliance audit in Saudi Arabia — scoping, evidence, fieldwork and reporting against SAMA CSF, NCA ECC, PDPL and ISO 27001 in 2026.

2026-04-08 · 8 min
GRC Software for Saudi Arabia: A 2026 Buyer's Guide

A 2026 buyer's guide to GRC software for Saudi Arabia — what to look for in SAMA, NCA, PDPL and ISO 27001 coverage, data residency and bilingual support.

2026-04-08 · 8 min
Risk Management Software Saudi Arabia: Buyer's Guide

A practical buyer's guide to risk management software for Saudi enterprises — methodology, integration, KRIs and alignment with SAMA CSF, NCA ECC and ISO 27005.

2026-04-08 · 7 min
Cyber Risk Register: SAMA CSF and NCA ECC Alignment

How to build a cyber risk register for Saudi Arabia aligned to SAMA CSF and NCA ECC — taxonomy, scoring, control linkage, KRIs and inspector-ready evidence.

2026-04-08 · 7 min
GRC Software vs Spreadsheets: Cost for Saudi Teams

GRC software vs spreadsheets for Saudi compliance teams — audit prep time, evidence integrity, SAMA and NCA inspection readiness and the real total cost.

2026-04-08 · 7 min
Internal Audit Universe Template: IIA-Aligned Guide

A free IIA-aligned internal audit universe template for Saudi internal audit functions — auditable units, risk rating, planning columns, downloadable Excel.

2026-04-08 · 6 min
ISO 27001 Certification Saudi Arabia: Step-by-Step

A step-by-step ISO 27001:2022 certification roadmap for Saudi organisations — scope, Annex A controls, Stage 1 and Stage 2 audits, and SAMA CSF alignment.

2026-04-08 · 8 min
NCA ECC 2:2024 Compliance Checklist (Free Template)

A free NCA ECC-2:2024 compliance checklist — every domain, control and evidence requirement Saudi government and CNI operators need, free to download.

2026-04-08 · 9 min
NCA ECC 2:2024: Compliance Guide for Saudi Entities

A practitioner's guide to the NCA Essential Cybersecurity Controls (ECC-2:2024) — scope, the four domains, what changed from ECC-1:2018, and assessment.

2026-04-08 · 11 min
On-Premise GRC Software Saudi Arabia: Data Residency

On-premise GRC software for Saudi Arabia — when sovereignty matters, deployment options, PDPL data residency, NCA CCC and SAMA outsourcing implications.

2026-04-08 · 7 min
Risk-Based Internal Audit in Saudi Arabia: 2026 Guide

How to run a risk-based internal audit program in Saudi Arabia — IIA-aligned audit universe, risk rating, planning, fieldwork and committee reporting.

2026-04-08 · 8 min
SAMA CSF vs NCA ECC: Differences and How They Align

A factual comparison of SAMA CSF and NCA ECC — issuer, scope, structure, control counts, assessment methodology and how Saudi organisations manage both.

2026-04-08 · 8 min