
PRAECEPTA CROSSWALK
Most GCC organisations of scale report against three or more cybersecurity frameworks — as separate exercises, each gathering substantially the same evidence.
This crosswalk maps where they converge, states how completely each requirement is satisfied, and documents the four plus two areas where they genuinely diverge and must not be conflated.
No form. No email required. 0.2 MB.

WHAT THIS EDITION COVERS
Version 0.9.1 — Structural Edition. This edition maps framework structures, convergence across eight control domains and twenty-four themes, the direction-of-fit method, and the six areas of genuine divergence.
Control-level mapping — across individual controls, sub-controls and contributing outcomes — is published in v1.0, November 2026. Working Pack subscribers receive it automatically.
Mapping granularity. The UAE IA Standard v2 is mapped at control level in v1.0. Sub-control detail follows in v1.1.
Coverage. Each edition publishes the percentage of assessable units mapped, per framework. A stated limitation is more useful than a silent one.
WHAT'S IN THE CROSSWALK
Included in v0.9:
✓ Framework structures compared — issuer, version, structure, assessment model and applicability model, side by side
✓ Convergence mapping across eight control domains and twenty-four themes
✓ Direction-of-fit method — Full, Partial, Supports, None
✓ Divergence register — six areas of genuine difference
✓ Seven common control themes where all four frameworks converge
✓ Source register — every figure traced to its issuing body, with retrieval dates
✓ Coverage percentages per framework
✓ Version control and quarterly review cycle
Also mapped:
✓ SAMA Cyber Security Framework — 4 domains; maturity model 0–5, Level 3 the general regulatory expectation
✓ NCA OTCC-1:2022 — for operators of Saudi critical infrastructure, including private-sector operators
Published in v1.0 (November 2026):
→ Control-level mapping across all four frameworks
→ Full evidence register with deduplication analysis
→ Framework-native reporting structure guidance
What it is not:
This is a mapping of control convergence. It is not a compliance certification, an assurance opinion, or a substitute for assessment against the frameworks themselves. Overlap is not equivalence — and the divergence register exists because treating these frameworks as interchangeable will fail an audit.
THE FRAMEWORKS TABLE ★
The UAE Information Assurance Standard v2 is issued by the UAE Cyber Security Council and supersedes the UAE Information Assurance Regulation v1.1 (TDRA), which comprised 188 controls prioritised P1–P4. Structural figures for v2 should be verified against the Cyber Security Council publication. Entities mid-transition should confirm which version applies to them — see the transition note below.
Framework hierarchies
CAF v4.0 objectives: A — Managing security risk · B — Protecting against cyber attack · C — Detecting cyber security events · D — Minimising the impact of incidents
ECC-2:2024 domains: Cybersecurity Governance · Cybersecurity Defence · Cybersecurity Resilience · Third-Party and Cloud Computing Cybersecurity
NIST CSF 2.0 functions: Govern · Identify · Protect · Detect · Respond · Recover
WHERE ALL FOUR CONVERGE
Different structures, different vocabularies, substantially the same underlying expectations. Every one of these frameworks requires:
-
Asset inventory — the precondition to everything else
-
Access control on least privilege, with periodic entitlement review
-
Logging and monitoring, with defined detection capability
-
Incident response that is defined, owned and exercised
-
Third-party risk assessment before onboarding and on an ongoing basis
-
Business continuity that has been tested, not merely documented
-
A cybersecurity function with defined authority and board-level visibility
The convergence is not coincidental. All four draw on the same body of established practice.
ALSO MAPPED IN THE FULL CROSSWALK
SAMA Cyber Security Framework
4 domains. Maturity model 0–5, with Level 3 the general regulatory expectation. As currently in force, including applicable circulars.
NCA OTCC-1:2022 — Operational Technology Cybersecurity Controls
4 main domains, 23 subdomains, 47 main controls, 122 subcontrols. Applies to industrial control systems in critical facilities owned or operated by government organisations, and to private-sector organisations that own, operate or host Critical National Infrastructure in the Kingdom.
Worth knowing: the The Industrial Control Systems domain present in ECC-1:2018 does not appear in ECC-2:2024; OT and ICS requirements are addressed by OTCC-1:2022. A structural decision, not an omission. — and it means OT requires a separate instrument.
WHY DIRECTION OF FIT MATTERS
Framework mapping is not symmetric. A control that fully satisfies one framework's requirement may satisfy its counterpart only partially — or may contribute without satisfying it at all.
Most published framework mappings omit this. Without it, a mapping is a similarity claim, not an assurance statement — and it will not survive an assessor's first question.
Every mapping in this crosswalk is marked:
This is the difference between a mapping you can use in an assessment and one you can only use in a presentation.
OVERLAP IS NOT EQUIVALENCE
Treating these frameworks as interchangeable will fail an audit. They diverge genuinely — and predictably — in six areas. The crosswalk documents each.
1. Data residency and cross-border transfer. The most consequential divergence. Requirements differ materially between jurisdictions, and a control adequate in one may be non-compliant in another.
2. Third-party and cloud provisions. ECC-2:2024 gives this an entire domain. Others distribute it across control families with differing depth and emphasis.
3. Incident reporting thresholds and timelines. What must be reported, to whom, within what period. These do not align, and the strictest applicable requirement governs.
4. Maturity, prioritisation and applicability models. SAMA operates a 0–5 maturity model with Level 3 as the general expectation. The UAE IA Standard v2 classifies controls as Always Applicable or Based on Risk. CAF assesses contributing outcomes against Indicators of Good Practice. NIST CSF 2.0 uses Organisational Profiles. No defensible arithmetic combines these, and any merged score would be misleading.
5. Operational technology scope. Largely outside the core four. The Industrial Control Systems domain present in ECC-1:2018 does not appear in ECC-2:2024; OT and ICS requirements are addressed by OTCC-1:2022. A structural decision, not an omission.. Saudi operators should note OTCC separately — including private-sector organisations that own, operate or host Critical National Infrastructure in the Kingdom.
6. Compliance model — checklist versus continuous effectiveness. The UAE IA Standard v2 moved from checklist-style compliance toward continuous improvement with effectiveness measurement and performance indicators. Evidence demonstrating that a control is designed may satisfy a control-based framework and fail an effectiveness-based one. This is the divergence most often discovered late.
The correct model is shared evidence with framework-native reporting, and every divergence documented rather than smoothed over.
A NOTE ON THE UAE INFORMATION ASSURANCE TRANSITION
The UAE Information Assurance framework changed substantially. The IA Standard v2, issued by the UAE Cyber Security Council, supersedes the IA Regulation v1.1 issued by TDRA.
What changed is not cosmetic:
Version
v1.1 TDRA
v2 (Cyber Security Council)
Issuer
TDRA
UAE Cyber Security Council
Structure
188 controls · 60 management + 128 technical
15 families · 47 sub-families · 134 controls · 449 Sub-controls
Applicability
Priority tiers P1–P4, P1 mandatory
Always Applicable (70) / Based on Risk (64)
Compliance Model
Checklist-style
Continuous improvement with effectiveness measurement
Scope
Government and critical infrastructure, broadly
Narrower — confirm CSC supervision applies to you
Why this matters beyond the UAE.
A different issuer, a different structure, and a different applicability model — in a single revision.
Any assessment programme built around a framework's structure had to be rebuilt. An assessment programme built around the underlying evidence needed only a remapping.
That is the argument for this crosswalk, demonstrated rather than asserted.
If you are mid-transition: confirm with qualified counsel which version applies to your entity, and whether CSC supervision extends to you. The v2 scope is narrower than v1.1's. We do not offer that determination — it is a legal question.

NEED TO ACTUALLY USE IT?
The PDF is the reference. The Working Pack is the toolkit.
📊 Editable crosswalk spreadsheet — filterable by framework, control domain, theme and direction of fit. Add your own controls and evidence references.
📋 Evidence register template — structured by control question rather than by framework, with mapping columns for each framework, plus fields for owner, refresh cycle and evidence depth (design / implemented / operating effectively).
⚠️ Divergence register — the six areas of genuine difference, with guidance on addressing each in framework-native reporting.
📐 Reporting structure guidance — how to produce framework-native outputs from one shared evidence set, and why merged scores fail.
🔄 v1.0 on release — Working Pack subscribers receive the control-level edition automatically in November 2026, at no cost.
HOW THIS GETS USED
Consolidating Assessment Cycles
Restructure evidence gathering around the underlying control question rather than each framework's running order. Gather once, map outward, report natively. In organisations reporting against three or more frameworks, duplicated evidence work is frequently the largest single line item in the compliance budget — and produces no incremental assurance.
Scoping and Proposals
Consultancies and integrators use the crosswalk to scope multi-framework engagements accurately and price them defensibly. If you would like it in your bid library, use it — attribution appreciated.
Board and Audit Committee Reporting
Explaining why the organisation holds several different maturity scores, what they do and do not have in common, and why a single blended figure is not available. Boards ask this. Executives struggle to answer it well.
Version 0.9.1 Structure · September 2026 · Reviewed Quarterly
Sources. All structural figures are verified against primary publications from their issuing bodies: the NCSC Cyber Assessment Framework v4.0 and its changelog; the NCA Essential Cybersecurity Controls ECC-2:2024 and Operational Technology Cybersecurity Controls OTCC-1:2022; the UAE Information Assurance Standard published by the UAE Cyber Security Council; the SAMA Cyber Security Framework; and NIST Cybersecurity Framework 2.0. The full source register, with retrieval dates, is included in the crosswalk document.
Verify before you rely on it. Frameworks are revised — and, as the UAE transition demonstrates, sometimes substantially. Figures are correct as at the version date above. Confirm the current issue of any framework against its issuing body before relying on this mapping for an assessment or a regulatory submission.
A note on secondary sources. Published third-party summaries of these frameworks frequently disagree with the issuing bodies' own figures. Where a discrepancy exists, this crosswalk uses the issuer's published figure.
Scope. This document constitutes security architecture guidance, not legal advice. Framework applicability is jurisdiction- and entity-specific. Engage qualified legal counsel for binding interpretation of any regulatory obligation, including whether a given framework — or which version of it — applies to your organisation.
Declared interests. PRAECEPTA holds declared technology partnerships. No product is named or recommended in this crosswalk, and no partner benefits from its content. Our full Declaration of Interests is at praecepta.co/declaration.
Corrections welcome. If you find an error in the mapping, tell us: [ops@praecepta.ae]. Corrections are incorporated at the next quarterly review with acknowledgement.
Licence. © 2026 PRAECEPTA CYBERSECURITY LLC. This document is licensed Creative Commons Attribution 4.0 International (CC BY 4.0) — you may share and adapt it, including commercially, with attribution. Third-party framework rights reserved as set out above. Attribution: "PRAECEPTA GCC Framework Crosswalk v0.9, PRAECEPTA CYBERSECURITY LLC, CC BY 4.0."
IF THE MAPPING RAISES QUESTIONS
PRAECEPTA is a specialist security architecture practice in Dubai. We design multi-framework assessment programmes, Zero Trust and data security architectures, and regulatory assurance for organisations across the Middle East and Africa.
If you are consolidating assessment cycles, working through a framework transition, or trying to reconcile several frameworks into one coherent programme, that is the work we do.
Or read more about our approach →
Our advisory work carries no product economics. Our fee is unaffected by what you subsequently buy — including if you buy nothing.
