Waaqi maps your organization to every domain of Saudi Arabia's Essential Cybersecurity Controls (ECC-1:2018 and its updates), turning a mandatory national requirement into a governed, evidence-backed workflow.
Control library, gap assessment, risk register, and audit packs ship ready on day one.
The NCA's Essential Cybersecurity Controls apply to every Saudi government entity, critical national infrastructure operator, and any organization handling government data. Unlike SAMA CSF, which targets financial institutions, ECC casts a wider net, and non-compliance carries direct regulatory consequences under Saudi Arabia's national cybersecurity mandate.
Organizations managing ECC compliance manually face fragmented evidence across departments, unclear control ownership, and audit fatigue when NCA assessments arrive. Waaqi turns ECC from a reactive scramble into a continuous, governed workflow.
Framework-aligned scoring against every NCA ECC control with prioritized remediation recommendations and automated policy generation for identified gaps.
Auto-generate a defensible SoA mapped to NCA ECC control domains, maintained continuously as your compliance posture evolves.
A user-initiated risk register linked directly to control test results, so every risk treatment decision is traceable to evidence.
Continuous control monitoring against NCA ECC operational requirements, with exception workflows that trigger when posture drifts from target state.
Evidence pack exports formatted for NCA assessment, Arabic and English audit trails, and a complete remediation history for regulator review.
Regional Cloud (KSA) or on-premises deployment ensures your compliance data stays within Saudi jurisdiction, meeting the NCA's data localization expectations.
If your organization also carries SAMA CSF obligations, ISO 27001 certification, or KSA PDPL requirements, Waaqi's configurable control library lets you map shared controls once and reuse the evidence across every applicable framework, cutting duplicate assessment cycles significantly.
See how the two national frameworks overlap in practice: NCA ECC vs SAMA CSF: Key Differences for Saudi Organizations.
Regional workspaces come pre-loaded with national control libraries and reporting views.
All 114 ECC controls pre-loaded across 5 domains, with self-assessment workflows and maturity scoring.
Open workspaceFor financial institutions: full CSF library, maturity scoring, and board reporting packs.
Open workspaceAll 15 national data management domains with PDPL-aligned personal data protection specifications.
Open workspaceOperationalize Saudi privacy obligations alongside your cyber controls, sharing evidence where requirements overlap.
Open workspaceBook a session with our team and we will walk through the 114-control library, maturity scoring, and NCA evidence pack in a sandbox tenant.