Yes. Collection is agentless and uses standard read privileges. Nothing is installed, no elevated privileges are required, and nothing changes in your environment.
Is Your Identity Infrastructure Compliant with NCA ECC & SAMA CSF?
Find out with a free Identity Compliance Report, ready in 1 day.
- No agents
- No elevated privileges
- No network disruption
- Zero operational risk
- Runs fully on-prem
What you get
One read-only scan, one report your security and GRC teams can act on.
Compliance score, control by control
Overall readiness for NCA ECC and SAMA CSF, with pass and fail status on every identity-relevant control.
Findings mapped to controls
Each misconfiguration is tied to the control it affects, with severity and a written rationale for auditors.
Prioritized remediation plan
A fix list ordered by risk, so your team closes the gaps that matter first.
Illustrative preview. Your report covers your environment, control by control.
From the report: an example finding
Kerberoastable privileged service account
Exposure Point 248.5Rationale: A service account holding privileged group membership exposes a Kerberos service ticket that can be cracked offline. Privileged credentials protected only by a user-chosen password fail the privileged access management requirements of both frameworks.
Illustrative example. Findings in your report reflect your environment.
From request to report in 3 steps
Request your slot
Fill in the 2-minute form. We confirm your slot within one business day.
We run a read-only assessment
Agentless collection from Active Directory, Microsoft Entra ID and Azure, AWS, or Google Cloud. Nothing is installed, nothing changes.
Get your report in 1 day
Compliance score, control-by-control findings, and a prioritized remediation plan, with an optional walkthrough call.
The identity controls behind the acronyms
Both frameworks treat identity and access management as a named control area. This assessment collects the evidence those controls ask for.
Subdomain 2-2, Identity and Access Management
- Multi-factor authentication for remote access and privileged accounts (2-2-3-2)
- Least Privilege and Segregation of Duties (2-2-3-3)
- Privileged access management (2-2-3-4)
- Periodic review of identities and access rights (2-2-3-5)
Control area 3.3.5, Identity and Access Management
- Joiner, mover, and leaver access management with a full audit trail
- Periodic review of user access rights, including privileged accounts
- Multi-factor authentication for sensitive systems, remote access, and privileged access
- Maturity level 3 or higher expected across controls
Every finding is mapped to the exact control it affects, with severity and a written rationale for auditors.
Also available on request: the same assessment reported against ISO/IEC 27001 and the UAE Information Assurance Regulation.
Control references follow the official ECC-2:2024 and SAMA Cyber Security Framework Version 1.0 publications. Confirm applicability with your regulator or auditor.
Who this assessment is for
Organizations running Active Directory, Microsoft Entra ID/Azure, AWS, or Google Cloud that answer to Saudi cybersecurity regulations.
Subject to NCA ECC
Government entities, critical national infrastructure, and organizations aligning with the National Cybersecurity Authority’s controls.
Regulated by SAMA
Banks, insurers, financing companies, and other institutions applying the Saudi Central Bank’s Cyber Security Framework.
Forestall is not affiliated with the NCA or SAMA. The report supports your compliance and audit preparation; it is not a formal certification.
Frequently asked questions
What security and GRC teams ask before requesting a slot.
Get your free Identity Compliance Assessment
Limited slots. Our team will contact you within one business day.
- Compliance score, control by control
- Findings mapped to controls, with rationale for auditors
- Ready in 1 day, with zero operational risk