NCA ECC
The National Cybersecurity Authority's baseline controls for protecting Saudi Arabia's information and technology assets, structured into five domains.
Why it matters
Mandatory for government bodies and critical national infrastructure in the Kingdom, with subdomains that map cleanly to ISO 27001.
Who it's for
Government organisations, critical national infrastructure and the entities that operate on their behalf.
How you get to NCA ECC
- 1ScopeAssets in the KSA
- 2Gap assessmentAgainst the ECC
- 3RemediateClose the gaps
- 4ImplementAll five domains
- 5Compliance reviewEvaluate posture
- 6MaintainContinuous compliance
NCA ECC, worked in the platform
Get the evidence you need
The AI recommends which evidence answers each NCA ECC control, ready to confirm.
See what's missing
Gaps and missing artifacts surface on their own, not the week of the audit.
Create from templates
Spin up policies, assessments and charters from standard templates, then tailor them to your scope.
Collected once, reused
One artifact satisfies this framework and every other it maps to.
Get NCA ECC-ready on your own stack.
Demos are scoped to your frameworks. Pick a slot and we'll run NCA ECC live.