This table shows the 18 compliance areas where Saudi NCA ECC and NIST CSF controls overlap. When you mark a control as implemented in either framework, Venvera automatically propagates the status to the equivalent control in the other.

Compliance AreaNCA ECCNIST CSF
Cybersecurity GovernanceECC-1-1, ECC-1-2GV.OC-01, GV.RR-01
Cybersecurity StrategyECC-1-5, ECC-1-6GV.OC-02, GV.SC-01
Asset IdentificationECC-2-1, ECC-2-2ID.AM-01, ID.AM-02
Asset ClassificationECC-2-3, ECC-2-4ID.AM-05
Identity & Access ManagementECC-3-1, ECC-3-2PR.AA-01, PR.AA-05
Privileged AccessECC-3-3, ECC-3-4PR.AA-05
Authentication & MFAECC-3-5, ECC-3-6PR.AA-03
Network SecurityECC-4-1, ECC-4-2PR.IR-01
Data ProtectionECC-4-3, ECC-4-4PR.DS-01, PR.DS-02
CryptographyECC-4-5, ECC-4-6PR.DS-01
Physical & Environmental SecurityECC-5-1, ECC-5-2PR.AA-02
Vulnerability ManagementECC-6-1, ECC-6-2ID.RA-01, PR.PS-01
Patch ManagementECC-6-3, ECC-6-4PR.PS-01
Security MonitoringECC-7-1, ECC-7-2DE.CM-01, DE.AE-02
Incident ResponseECC-7-3, ECC-7-4RS.MA-01, RS.AN-03
Incident ReportingECC-7-5RS.CO-02
Business Continuity & ResilienceECC-8-1, ECC-8-2RC.RP-01, RC.RP-02
Security AwarenessECC-9-1, ECC-9-2PR.AT-01, PR.AT-02
ℹ️
For details on how propagation works, thresholds, and the auto-mapped badge, see the Cross-Framework Control Propagation overview article.