Skip to content
Tenant Excellence

Applies toSaudi Arabia

NCA ECC

Essential Cybersecurity Controls (ECC-2:2024) of Saudi Arabia’s National Cybersecurity Authority, evaluated from tenant and subscription configuration.

From Complete

Scope as evaluated

  • Identity and access management, MFA and privileged accounts
  • Email protection, data protection and cryptography
  • Logging, monitoring and cloud-security controls

Read from the tenant

  • Entra ID authentication and access policies
  • SPF, DKIM, DMARC and Defender settings
  • Azure Defender for Cloud and activity-log retention

Sample controls

  • 2-2 Identity and access management
  • 2-4 Email protection
  • 2-12 Event logs and monitoring
Results are configuration indications drawn from your tenant. They are not an audit opinion or a certification.

In depth

Give the auditor a link, not a folder

Every covered control shows the data Microsoft Graph returned and the endpoint it came from. One click creates a read-only snapshot for one framework; it needs no account and expires after 24 hours.

  • Structured proof per control, with its Graph or ARM source
  • Scoped to one framework, read-only, no sign-in for the auditor
  • Expires after 24 hours; creation is written to the audit log
Learn more

Questions

Questions about NCA ECC

Does this cover ECC-2:2024?

Yes. The catalogue follows the 2024 revision; controls that require organisational evidence show as not assessed.

Is the auditor view usable for an NCA compliance review?

It is a read-only, 24-hour snapshot of control status with tenant-sourced proof. Whether it satisfies a reviewer is their decision.

Is Arabic supported?

The product, the reports and the auditor view are available in Arabic, with right-to-left layout.

Request a demo

Which frameworks do you report against?

Tell us in the demo request and we will show the matching controls on a demo tenant.

0 / 2,000