شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Govern & comply

Compliance assessmentKnow where you stand against the controls before the regulator does

We measure your actual state control by control against ECC, CSCC, SAMA CSF and PDPL, and hand you a remediation roadmap ordered by impact and effort.

At a glance

Frameworks

  • NCA ECC
  • NCA CSCC
  • NCA CCC
  • SAMA CSF
  • PDPL
  • CST CRF
  • NCA DCC

Deliverables

  • Gap report per framework with implementation level and evidence
  • Phased remediation roadmap with owners
  • Senior management briefing
  • Organised evidence file for audit
  • Regulatory reporting templates

The challenge

The NCA requires periodic self-assessment against the Essential Cybersecurity Controls (ECC) and Critical Systems Cybersecurity Controls (CSCC), and SAMA requires maturity measurement against its Cyber Security Framework (CSF). The Personal Data Protection Law (PDPL) and its implementing regulations impose obligations on every organisation that processes personal data.

Self-assessment by the same teams tends to be optimistic: a control counts as implemented because a policy exists, not because the evidence does. At a real audit the gap between what is written and what is practised shows.

We provide an independent, evidence-based assessment rather than a questionnaire, and turn the results into a realistic remediation plan with owners and phases, fit for regulatory reporting and investment decisions.

How we work

  1. 1

    Scope and frameworks

    We define the systems and units in scope, the applicable frameworks (ECC, CSCC, CCC, SAMA CSF, PDPL, CST CRF), the people to interview and the evidence required.

  2. 2

    Evidence collection and assessment

    Interviews, document review and sampling of configurations and logs, then a documented implementation and maturity rating for every control.

  3. 3

    Report and remediation roadmap

    A gap report ordered by severity, a phased remediation roadmap with owners and effort estimates, a senior management briefing, and templates ready for regulatory reporting.

What is included

  • ECC and CSCC assessment

    Full assessment across the four ECC-2:2024 domains and the additional CSCC controls, in a format compatible with the NCA assessment and compliance tool.

  • SAMA CSF maturity assessment

    Maturity scoring of every sub-control in the SAMA framework, compared with the target level and gaps identified.

  • PDPL compliance assessment

    Review of lawful bases, consent, records of processing, data subject rights, cross-border transfers and breach notification.

  • Other sector frameworks

    CST CRF for telecom and technology providers, NCA Data Cybersecurity Controls (DCC), and ISO 27001 on request.

  • Evidence-based rating

    Every control is rated with attached evidence (document, configuration capture, log sample) that an auditor can later verify.

  • Prioritised remediation roadmap

    Initiatives grouped by impact, effort and dependency, with owners and realistic phases set by your teams.

  • Reassessment

    A follow-up assessment that documents progress after remediation, used for periodic compliance reporting.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • NCA ECC
  • NCA CSCC
  • NCA CCC
  • SAMA CSF
  • PDPL
  • CST CRF
  • NCA DCC

Frequently asked questions

How is this different from an audit?

The assessment is done for you, so you can find and fix gaps before an audit. An audit is performed by the regulator or an independent auditor to reach a verdict. Our results do not replace a formal audit.

Can several frameworks be assessed in one project?

Yes. Evidence is collected once and rated against every applicable framework, which reduces the load on your teams.

How long does an assessment take?

It depends on the number of systems and frameworks and how readily evidence is available. The schedule is agreed after the scoping session.

Do you help implement the roadmap?

Yes. Our teams can deliver the initiatives through advisory, solutions and SOC services, or support your teams while they implement.

Which frameworks apply to us: ECC, SAMA CSF or PDPL?

ECC-2:2024 applies to government entities, including their affiliated companies inside and outside the Kingdom, and to private-sector organisations that own, operate or host critical national infrastructure; the NCA strongly encourages all other organisations to use it. SAMA CSF applies to banks, insurance and reinsurance companies, financing companies, credit bureaus and financial market infrastructure regulated by SAMA. PDPL applies to any processing of personal data in the Kingdom, and to processing of Kingdom residents' data by any party outside it. We confirm which frameworks apply to you in the scoping session.

What should we prepare before the assessment starts?

Your current policies and procedures, the asset inventory and list of critical systems, the organisation chart, and the results of any earlier assessment or audit, including the NCA assessment and compliance tool if you have used it. Nominate an overall coordinator and a contact for each control area, and give us access to a shared evidence folder. The more evidence is ready at the start, the less time your teams spend in interviews.

How is this different from GRC advisory?

A compliance assessment measures where you stand today and identifies what is missing, control by control, with evidence. Our GRC Advisory service builds what is missing: strategy, policies, risk management, roles and governance committees. A common sequence is to run the assessment first and use its remediation roadmap to scope the advisory work.

  • Govern & comply

    GRC advisory

    Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.

  • Govern & comply

    Third-party risk & GRC platform

    Vendor assessment and compliance management on a single platform.

  • Assess & test

    Penetration testing

    Application, network and infrastructure testing with recognised methodologies and an actionable report.

  • Solutions & infrastructure

    Data security

    Data classification, loss prevention and encryption aligned with PDPL.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.