GRC · Early access
Governance, risk and compliance for regulated organizations
Offensive360 GRC brings compliance programs, the risk register, policies, audits, incidents, vendors and regulatory obligations into one platform, in Arabic and English, on infrastructure you control. It ships with the frameworks Gulf and EU regulators actually ask for, and it takes evidence straight from the Offensive360 testing engines.
Saudi Arabia edition: NCA ECC-2, SAMA CSF and PDPL in detail · العربية
Last updated: 9 September 2026
Framework packs included
- NCA ECC-2:2024Saudi Essential Cybersecurity Controls, official 2024 edition, Arabic and English
- SAMA CSFSaudi Central Bank Cyber Security Framework, maturity levels 3.1 to 3.4
- PDPLSaudi Personal Data Protection Law
- NCA CCCSaudi Cloud Cybersecurity Controls
- ISO/IEC 27001Information security management
- Custom frameworksImport your own requirements and controls from CSV
Modules
Every module writes to the same record of controls, risks, evidence and findings, so a control failing an audit shows up in the risk register and on the board dashboard without re-keying.
Compliance programs
Framework packs with requirements and controls, cross-mapping between frameworks, control ownership, evidence collection and gap analysis per program.
Risk management
Enterprise risk register with likelihood and impact scoring, treatment plans, risk owners, review cycles and heat-map reporting.
Policy and document control
Policy lifecycle with versions, approvals, attestations and scheduled reviews, linked to the controls they satisfy.
Internal audit
Audit plans, fieldwork, findings and corrective actions, tracked to closure with evidence attached to every step.
Incident, BCM and crisis
Incident intake and workflow, business-impact analysis, continuity plans, exercises and crisis-mode communications.
Third-party and asset risk
Vendor inventory, questionnaires, tiering and contract obligations; asset register linked to risks, controls and findings.
Obligations and strategy
Regulatory obligations with deadlines and owners; objectives and initiatives tied to the controls and risks they depend on.
Tasks, reports and dashboards
Assignments, notifications and webhooks; executive dashboards and exportable reports for boards, auditors and regulators.
Built for the Gulf and the EU
Official NCA ECC-2:2024 controls with Arabic source text, SAMA CSF maturity levels and PDPL obligations, alongside ISO/IEC 27001. Reports read the way regulators expect.
Evidence from the testing engines
SAST and DAST findings from Offensive360 attach to the controls they affect. Auditors see the scan, the finding and the fix, not a screenshot of a spreadsheet.
Your infrastructure, your data
A container stack you run on-premise or in-Kingdom, with OpenID Connect single sign-on, role-based access per organization and a full audit trail of who changed what.
Frequently asked questions
What is Offensive360 GRC?
Offensive360 GRC is a governance, risk and compliance platform for regulated organizations. It manages compliance programs mapped to frameworks, an enterprise risk register, policies, internal audits, incidents and business continuity, third-party and asset risk, regulatory obligations and strategy, with dashboards and reports for boards, auditors and regulators.
Which frameworks are included?
The platform ships with framework packs for NCA ECC-2:2024, SAMA CSF, the Saudi PDPL, NCA CCC and ISO/IEC 27001, each with requirements and controls in English and Arabic. Additional frameworks are added continuously, and any framework can be imported from CSV as a custom pack. Controls can be cross-mapped so one piece of evidence satisfies several frameworks.
Is the interface available in Arabic?
Yes. The user interface, framework content and reports are available in Arabic and English, with right-to-left layout throughout.
Where does the platform run?
Offensive360 GRC is delivered as a container stack you run on your own infrastructure, including in-Kingdom hosting for Saudi organizations, or hosted by Offensive360 in the EU. Data stays in the environment you choose.
How does it connect to application security testing?
Findings from Offensive360 SAST and DAST flow into the GRC platform as evidence and open findings against the controls they relate to, so technical testing and compliance reporting share one record instead of two spreadsheets.
Does it support single sign-on and multiple organizations?
Yes. The platform is multi-tenant with organization-level roles, and supports single sign-on through OpenID Connect. Platform administrators can create organizations and invite owners who configure their own programs.
How do I get access?
Offensive360 GRC is in early access. Contact [email protected] or book a demo and we will set up a tenant with the framework packs you need.
Join the early-access program
We set up a tenant with your frameworks, import your existing risk register and controls from CSV, and connect your Offensive360 scans. Pricing is quote-based.