Are your critical systems ready
for the NCA assessor?
Answer 15 questions across all 4 NCA CSCC domains. Get an instant maturity score for your critical-system protection, a domain breakdown, and a prioritised list of what to fix first — built for entities operating critical systems under NCA mandate.
How protected are your critical systems under NCA CSCC?
15 questions across 4 control domains. One at a time. Keyboard-driven. You'll get an instant maturity score and a prioritised remediation roadmap in under five minutes.
What happens when you finish
Your full results are instant — score, domain breakdown and priority gaps, no email required. Optionally enter your email on the results screen to receive the report in your inbox.
See your overall NCA CSCC readiness percentage and where you sit on the maturity scale — Initial, Developing, Defined, or Managed.
Understand which of the 4 critical-system control domains is your biggest assessment risk and where the regulator is most likely to find gaps.
Walk away with your top 3 critical-system gaps ranked by severity, with specific first steps you can act on before your next NCA assessment.
Ready to harden your critical systems for good?
GRC Vantage has NCA CSCC, NCA ECC and SAMA frameworks pre-mapped out of the box. Evidence collected once proves compliance across every framework that applies to your critical systems.
CSCC + ECC unified
Critical-system controls layered on top of the ECC baseline. Evidence proves both frameworks at once.
Critical-system inventory
Maintain a live critical-system inventory tied directly to controls, owners, and dependencies.
Continuous compliance
Automated evidence collection and corrective action tracking so you are assessment-ready every day, not just the week before.
Frequently asked questions
- What is the NCA CSCC Readiness Assessment?
- A free, interactive self-assessment that measures your organisation's critical-systems cybersecurity maturity against the NCA Critical Systems Cybersecurity Controls (CSCC – 1 : 2019). It covers 4 domains — Governance, Defense, Resilience, and Third-Party & Cloud — and returns your full results instantly — with an optional email report.
- Who needs CSCC compliance?
- Any Saudi entity operating critical systems — typically large banks, government agencies, energy and utility operators, telecommunications providers, healthcare systems, and transport operators. CSCC layers on top of NCA ECC and applies to systems whose disruption would carry national-level impact.
- How does CSCC differ from ECC?
- ECC is the cybersecurity baseline for all Saudi government entities and CNI. CSCC is a hardened extension that applies specifically to critical systems on top of ECC. Where ECC requires MFA on remote access, CSCC requires MFA on every access including internal. Where ECC requires backup, CSCC requires immutable / air-gapped backup. The assessment measures the hardened CSCC layer.
- How long does the assessment take?
- The assessment has 15 questions and takes approximately 4–5 minutes to complete. Your full results are instant.
Run another readiness assessment
Score your maturity against the other Saudi frameworks — same conversational format, same instant results.
NCA ECC Readiness
Score your cybersecurity maturity across the four NCA ECC-2:2024 domains.
Start AssessmentSAMA CSF Readiness
Score your cybersecurity maturity against the Saudi Central Bank Cyber Security Framework.
Start AssessmentSAMA Third-Party Risk
Score your outsourcing maturity against the SAMA Outsourcing Regulations.
Start AssessmentBCM Readiness
Score your business continuity maturity against ISO 22301 and the SAMA BCM Framework.
Start AssessmentPDPL Readiness
Score your privacy programme against the Saudi Personal Data Protection Law.
Start AssessmentInternal Audit Readiness
Score your internal audit function against the IIA Standards and Saudi regulated-review obligations.
StartStart your NCA CSCC assessment now — it takes under 5 minutes.
Free. Instant results. No commitment. Built for Saudi entities operating critical systems under NCA mandate.
Take the assessment