Frameworks we cover
What each framework is, who it binds, the control domains and the evidence a regulator or certification body asks for — all mapped natively in GRCorb, with Arabic and English reporting.
NCA ECC
The Essential Cybersecurity Controls (ECC-2:2024), their four domains, and how compliance is assessed for Saudi entities.
ECC-2:2024 · 108 controlsSAMA CSF
The Saudi Central Bank framework, its maturity model, and what level 3 looks like in evidence.
4 domains · maturity 0–5PDPL
Saudi personal data protection duties: lawful basis, cross-border transfer, breach notification and the DPO role.
SDAIA enforcedAramco CCC / SACS-002
Third-party cybersecurity certification for Aramco suppliers, and the assessment path for SMEs.
CCC certificationNDMO standards
National data management and governance standards across fifteen domains.
SDAIA · NDMOISO/IEC 27001:2022
Annex A's 93 controls in four themes, the 2024 climate-change amendment, and what a Stage 1 audit actually checks.
93 controls · 4 themesEssential Eight
The ASD mitigation strategies and the three maturity levels, with what ML2 evidence looks like in practice.
ML1 · ML2 · ML3Privacy Act & NDB
Notifiable data breach duties, the serious-harm test, and penalties now reaching AU$50m or 30% of domestic turnover.
13 APPs · OAICSOCI Act 2018
Risk management programs, reporting timeframes and the asset classes captured by the 2024 amendments.
RMP · annual reportAPRA CPS 234 & CPS 230
Information security capability, third-party risk and operational resilience for APRA-regulated entities.
Penalties to AU$31.3mIRAP & the ISM
Assessment against the Information Security Manual for organisations handling government data.
OFFICIAL · PROTECTEDBuilt for your regulator, not translated for it
Your obligations are mapped natively in GRCorb — NCA ECC, SAMA CSF and PDPL in the Gulf, Essential Eight, the ISM, SOCI and the Privacy Act in Australia, plus ISO 27001, SOC 2 and PCI DSS globally — with the evidence each assessor actually asks for.
| Framework | Who it binds | Obligations mapped | Platform coverage |
|---|---|---|---|
| NCA ECC | All Saudi government entities and critical national infrastructure | ECC-2:2024 · 4 domains · 108 controls | Full |
| SAMA Cyber Security Framework | Banks, insurers and financial institutions regulated by SAMA | 4 domains · maturity levels 0–5 | Full |
| PDPL | Any entity processing personal data of individuals in KSA | Consent · transfer · DPO | Full |
| Aramco CCC (SACS-002) | Third parties connecting to or serving Saudi Aramco | Supplier certification | In build |
| NDMO data standards | Entities handling national data under SDAIA governance | 15 domains | In build |
| ISO/IEC 27001:2022 | Voluntary — commonly contractually required | 93 controls | Full |
| Essential Eight (ML1–ML3) | Federal agencies mandatory; strongly recommended for all | 8 strategies · 3 levels | Full |
| ISM / IRAP | Suppliers handling Australian Government data | 1,100+ controls | Full |
| SOCI Act 2018 | Designated critical infrastructure operators | RMP + reporting | Full |
| Privacy Act 1988 & NDB | Turnover above AU$3m, all health providers | 13 APPs | Full |
| APRA CPS 234 / CPS 230 | Banks, insurers, superannuation funds | Info security + op risk | In build |
NCA ECC-2:2024 — an example assessment viewEssential Eight maturity level 2 — an example assessment view
An illustration of how GRCorb presents a control assessment — control by control, with the evidence an assessor will ask for. Statuses shown are examples, not a client's results.
| Control area | Reference | Evidence an assessor asks for | Status |
|---|---|---|---|
| Cybersecurity governance | ECC 1-1 | Approved strategy, governance structure and evidence of periodic review by the authorising official | Evidenced |
| Asset management | ECC 2-1 | Complete asset inventory with ownership and classification, reconciled against external discovery | Partial |
| Identity & access management | ECC 2-2 | MFA for privileged and remote access, access review records, joiner-mover-leaver evidence | Evidenced |
| Vulnerability management | ECC 2-10 | Scan cadence, remediation SLAs by severity and evidence of closure for critical findings | Partial |
| Third-party cybersecurity | ECC 4-1 | Supplier register, contractual security requirements and periodic supplier assessments | Gap |
Find out where you stand before the assessor does
Tell us the framework and the deadline. We will come back with a readiness conversation grounded in your actual external exposure — not a generic gap template.
Talk to us about readiness