Feature

Cybersecurity compliance mapped to every framework.

Fiduca structures cybersecurity compliance as a single guided assessment. Define your scope, work through the controls that apply, and see exactly where you stand across every framework in scope, without duplicating effort.

How cybersecurity assessment works

From a set of frameworks to a scored, auditable cybersecurity posture.

01 · Scope

Define your attack surface

Fiduca maps your organisation's profile (sector, size, activities, and technology footprint) to the cybersecurity controls that actually apply. You do not wade through controls built for organisations that operate nothing like yours.

02 · Map

One control, many frameworks

Shared requirements across NCA, SAMA, and regional cybersecurity frameworks are answered once. Fiduca carries the response forward so the second framework costs a fraction of the first.

03 · Assess

Answer in the right shape

Cybersecurity controls range from binary (yes or no) to maturity-graded (level 1 through 5) to threshold-based. Fiduca presents each control in the correct format, so you answer precisely what the framework demands.

04 · Review

Gaps surface immediately

Any control that falls short of the required level is flagged as a potential gap, classified by severity, and mapped back to the framework and article that requires it. Nothing is buried in a raw score.

Framework coverage

The frameworks that matter to your sector, in one assessment.

Fiduca covers the full NCA cybersecurity framework suite (ECC, CCC, DCC, TCC, CGIoT, and their implementation guides) alongside the SAMA Cyber Security Framework. As new requirements are published they are mapped to the existing control set, so adding a new framework rarely means starting from scratch.

NCA Essential Cybersecurity Controls (ECC and GECC)

Fiduca structures the NCA Essential Cybersecurity Controls (ECC) and its implementation guide (GECC) into a guided assessment. Each control is presented in plain language with the correct answer type, and your responses feed the findings register automatically.

SAMA Cyber Security Framework and threat intelligence

The SAMA CSF and Cyber Threat Intelligence Principles are modelled as a distinct control layer for financial sector organisations. Shared controls with other NCA frameworks are answered once; SAMA-specific requirements are presented as their own items with the correct scoring model.

NCA cloud, data, telework, and IoT controls

Cloud Cybersecurity Controls (CCC), Cloud Controls for Providers (GCCC-CSP) and Tenants (GCCC-CST), Data Cybersecurity Controls (DCC), Telework Controls (TCC), and IoT Guidelines (CGIoT) extend the assessment wherever your footprint demands. Fiduca activates each one based on your organisation's profile.

Severity-graded findings register

Every cybersecurity finding carries a severity rating derived from the framework's own classification or from the control's inherent risk level. You prioritise by what matters, not by what came first.

Evidence and audit trail

Every answer is timestamped and attributed to the user who provided it. Assessments are not just scores, they are evidence packages your team can present to an auditor or a regulator.

Your privacy matters.

Fiduca uses necessary cookies to run the platform and optional analytics cookies to understand how it is used in aggregate. By accepting, you agree to the use of these cookies. To learn more, view our Cookie Policy & Privacy Notice.

Fiduca · Compliance, simplified.