Skip to main content

Free 30-min security demo Book Now

GRC · Kingdom of Saudi Arabia · النسخة العربية

GRC platform for Saudi Arabia, built on the official NCA and SAMA texts

Offensive360 GRC manages NCA ECC-2:2024, SAMA CSF, PDPL and NCA CCC programs in Arabic and English, runs in-Kingdom on infrastructure you control, and takes evidence straight from the security testing your teams already run.

Framework packs for the Kingdom

  • NCA ECC-2:2024
    The 2024 edition of the Essential Cybersecurity Controls: 4 domains, 28 subdomains and 108 controls, loaded from the official Arabic and English text with implementation guidance per control.
  • SAMA CSF
    Saudi Central Bank Cyber Security Framework with maturity levels 3.1 to 3.4 and level-3 considerations, for banks, insurers and financing companies under SAMA supervision.
  • PDPL
    Personal Data Protection Law obligations for controllers and processors, including records of processing, consent, breach notification and cross-border transfer conditions.
  • NCA CCC
    Cloud Cybersecurity Controls for cloud service providers and tenants, cross-mapped to the ECC controls they extend.
  • ISO/IEC 27001
    Annex A controls for organizations that certify, cross-mapped to ECC and SAMA so one piece of evidence serves several programs.
  • Your own frameworks
    Import sector circulars, internal standards or CST and SDAIA requirements from CSV as custom packs with the same workflows.

Why regulated organizations in the Kingdom choose it

Built from the official texts

Controls carry the regulator’s Arabic wording alongside the English translation, so audit evidence, reports and regulator submissions use the terminology assessors expect.

In-Kingdom hosting, your infrastructure

The platform is delivered as a container stack you run in your own data centre or in a Saudi cloud region. No data leaves the Kingdom unless you decide it should.

Arabic first, not translated later

Right-to-left interface, Arabic reports for boards and regulators, English for international auditors, switchable per user.

Evidence from real testing

ECC controls on secure development and vulnerability management are satisfied with findings that flow in directly from Offensive360 SAST and DAST, not with screenshots of spreadsheets.

One record for risk, audit and compliance

A failed control raises a risk, opens an audit finding and appears on the board dashboard without re-keying. Obligations track deadlines for NCA, SAMA and SDAIA reporting.

Multi-tenant for groups and providers

Holding companies, government clusters and managed service providers run one platform with separate organizations, roles and single sign-on through OpenID Connect.

Questions from Saudi compliance teams

Does the platform include the current NCA ECC-2:2024 controls?

Yes. The ECC-2:2024 pack contains all 108 controls across 4 domains and 28 subdomains, with the official Arabic text and English translation, implementation guidance and evidence checklists. The 2018 edition is kept for organizations still reporting against it.

Can we host it inside Saudi Arabia?

Yes. Offensive360 GRC ships as a container stack that runs on your own servers or in a Saudi cloud region, so data residency requirements under PDPL and sector regulations are met by design. Offensive360 can also host it in the EU if you prefer.

Is the interface in Arabic?

The user interface, framework content, notifications and reports are available in Arabic with right-to-left layout, and in English. Each user chooses their language.

How does it help with SAMA CSF maturity assessments?

Each SAMA CSF control is scored against maturity levels 3.1 to 3.4 with level-3 considerations, evidence attached per control, and a gap report that shows what is missing to reach the target level.

Can findings from security testing be used as evidence?

Yes. Findings from Offensive360 SAST and DAST attach automatically to the ECC and SAMA controls on secure development, vulnerability management and penetration testing, with the technical evidence behind them.

How do we start?

Offensive360 GRC is in early access. Contact [email protected] or book a demo; we provision a tenant with the packs you need, import your current risk register and controls from CSV, and connect your scans.

See your ECC-2 gap report in one session

Bring your current control list; we import it, map it to ECC-2:2024 and SAMA CSF, and show the gaps and the evidence still missing.