Cybersecurity compliance mapped to every framework.
Fiduca structures cybersecurity compliance as a single guided assessment. Define your scope, work through the controls that apply, and see exactly where you stand across every framework in scope, without duplicating effort.
From a set of frameworks to a scored, auditable cybersecurity posture.
Define your attack surface
Fiduca maps your organisation's profile (sector, size, activities, and technology footprint) to the cybersecurity controls that actually apply. You do not wade through controls built for organisations that operate nothing like yours.
One control, many frameworks
Shared requirements across NCA, SAMA, and regional cybersecurity frameworks are answered once. Fiduca carries the response forward so the second framework costs a fraction of the first.
Answer in the right shape
Cybersecurity controls range from binary (yes or no) to maturity-graded (level 1 through 5) to threshold-based. Fiduca presents each control in the correct format, so you answer precisely what the framework demands.
Gaps surface immediately
Any control that falls short of the required level is flagged as a potential gap, classified by severity, and mapped back to the framework and article that requires it. Nothing is buried in a raw score.
The frameworks that matter to your sector, in one assessment.
Fiduca covers the full NCA cybersecurity framework suite (ECC, CCC, DCC, TCC, CGIoT, and their implementation guides) alongside the SAMA Cyber Security Framework. As new requirements are published they are mapped to the existing control set, so adding a new framework rarely means starting from scratch.
Fiduca structures the NCA Essential Cybersecurity Controls (ECC) and its implementation guide (GECC) into a guided assessment. Each control is presented in plain language with the correct answer type, and your responses feed the findings register automatically.
The SAMA CSF and Cyber Threat Intelligence Principles are modelled as a distinct control layer for financial sector organisations. Shared controls with other NCA frameworks are answered once; SAMA-specific requirements are presented as their own items with the correct scoring model.
Cloud Cybersecurity Controls (CCC), Cloud Controls for Providers (GCCC-CSP) and Tenants (GCCC-CST), Data Cybersecurity Controls (DCC), Telework Controls (TCC), and IoT Guidelines (CGIoT) extend the assessment wherever your footprint demands. Fiduca activates each one based on your organisation's profile.
Every cybersecurity finding carries a severity rating derived from the framework's own classification or from the control's inherent risk level. You prioritise by what matters, not by what came first.
Every answer is timestamped and attributed to the user who provided it. Assessments are not just scores, they are evidence packages your team can present to an auditor or a regulator.