NCA · ECC · CSCC · CCC · OTCC · DCC · TCC

NCA compliance services, for every NCA control set.

The National Cybersecurity Authority supervises through a family of control sets, not one framework. We help Saudi organisations determine which apply, map the requirements to controls and owners, and build the evidence posture the NCA's self-assessment cycle expects — on the platform, with advisory support where you need it.

How we help

Platform and advisory, working as one

01 · Platform

Run compliance on GRC Vantage

Every NCA control set is pre-loaded in GRC Vantage as a structured library: self-assessment workflows per sub-control, evidence templates, ownership and review cycles, and submission-ready reporting. Hosted inside the Kingdom for data residency, or fully on-premise.

02 · Advisory

Bring in our practitioners

Our practitioners run NCA readiness reviews, determine which control sets apply to your environment, build remediation roadmaps sequenced by supervisory priority, and author the policies and governance structures the controls require — in Arabic and English.

What engagements deliver
  • Applicability analysis across the NCA control-set family
  • Requirements mapping to controls, owners and evidence
  • Readiness reviews with prioritised remediation roadmaps
  • Self-assessment execution support with maintained evidence
  • Policy and governance documentation aligned with NCA requirements
  • Bilingual Arabic and English delivery from Riyadh and Dammam
FAQ

Frequently asked questions

Which NCA control sets apply to my organisation?

It depends on your sector, systems and data. ECC is the baseline for every in-scope entity; CSCC adds requirements where systems are classified critical; CCC applies when you provide or consume cloud services; OTCC covers industrial control systems; DCC and TCC apply to data handling and telework respectively. Our first step in any engagement is an applicability analysis that tells you exactly which sets — and which controls within them — your environment is accountable for.

Do you support the NCA self-assessment and submission cycle?

Yes. The platform structures the self-assessment per sub-control with evidence attached to each response, and our advisors can support the review cycle — evidence quality checks, gap remediation and the documentation the submission expects. The result is a posture you maintain year-round rather than rebuild before each cycle.

Can our NCA compliance data stay inside Saudi Arabia?

Yes. GRC Vantage can be hosted inside the Kingdom, and for classified or air-gapped environments the platform deploys fully on-premise in your own infrastructure — see our platform delivery services.

Is delivery available in Arabic?

Yes — assessments, policies, reports and training are delivered in Arabic and English as standard, from our teams in Riyadh and Dammam.

Talk to us

Find out exactly what the NCA expects of you

Book a working session with our advisors. We'll map which NCA control sets apply to your environment, review where you stand, and outline a practical route to a defensible self-assessment.