Skip to main content
Version: 1.0.0-beta

Scenario: NCA ECC Compliance Assessment

This walkthrough demonstrates how to conduct a compliance assessment against the Saudi National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC).

Scenario Context

Your organization needs to assess compliance with NCA ECC 2024. The IT Audit team will evaluate all 114 controls across 5 domains.

Step 1: Set Up the Framework

  1. Navigate to Compliance → Frameworks
  2. Click NCA ECC (pre-loaded)
  3. Review the 5 domains and 114 controls
  4. Click Start Assessment

Step 2: Create the Engagement

  1. Navigate to Engagements → + New → Use Wizard
  2. Select type: Compliance
  3. Link to: NCA ECC framework
  4. AI generates scope covering all 5 domains:
    • Cybersecurity Governance
    • Cybersecurity Defense
    • Cybersecurity Resilience
    • Third-Party Cybersecurity
    • Cloud Computing Cybersecurity

Step 3: Execute Testing

For each NCA ECC control:

  1. Open the control in the compliance framework view
  2. Click Create Workpaper for the control
  3. AI suggests test procedures based on the control requirement
  4. Execute the test procedure
  5. Rate compliance: Compliant, Partially Compliant, Non-Compliant
  6. Upload supporting evidence

Step 4: Gap Analysis

  1. Navigate to Compliance → NCA ECC → Gap Analysis
  2. View the compliance heatmap showing:
    • ✅ Compliant controls (green)
    • ⚠️ Partially compliant controls (amber)
    • ❌ Non-compliant controls (red)
  3. AI generates a gap analysis summary highlighting critical gaps
  4. Create findings for each non-compliant control

Step 5: Generate Compliance Report

  1. Navigate to Reports → + New → Compliance Report
  2. Select framework: NCA ECC
  3. AI generates:
    • Overall compliance percentage
    • Domain-by-domain breakdown
    • Critical gaps with remediation recommendations
    • Action plan timeline
  4. Export as branded PDF for NCA submission

Result

MetricValue
Total Controls114
Compliant87 (76%)
Partially Compliant19 (17%)
Non-Compliant8 (7%)
Findings Created27
Remediation Actions27