top of page

ONE EVIDENCE BASE. EVERY FRAMEWORK YOU REPORT AGAINST.

The problem

 

A GCC organisation with regional operations may be reporting against NCA ECC-2:2024, the UAE Information Assurance Standard v2, the SAMA Cyber Security Framework and an internal NIST CSF 2.0 baseline — simultaneously.

 

In most organisations these run as separate exercises. Different teams, different cycles, different consultants, producing several maturity positions that nobody can reconcile. And each one gathers substantially the same evidence.

 

The overlap between these frameworks is significant. The structures differ, the vocabularies differ, the assessment models differ — but the underlying control expectations converge heavily. That overlap is exploitable, and very few organisations exploit it.

 

There is a second problem. Maturity scores do not tell a board anything actionable. "We are at 2.7 against a target of 3" is a statement about a document, not about risk, and it cannot be compared against any other investment the board is considering.

 

What we are, and what we are not

 

We are direct about this because the distinction matters.

 

We are not a certification body. PRAECEPTA does not issue certificates and does not perform accredited certification audits. Where you require certification — ISO/IEC 27001, or an accredited scheme under a national programme — that is delivered by an accredited certification body, and we will tell you so and help you select one.

 

We are not your internal audit function. We can support it, provide technical assessment for it, and prepare evidence for it. Internal audit independence is a governance matter for your organisation.

 

What we do is assessment and assurance review. Independent, evidence-based technical and control assessment against the frameworks you are accountable to — producing a defensible position, a prioritised gap analysis, and a roadmap you can act on. Where the objective is certification, we deliver the readiness work that precedes it.

OUR APPROACH

  1. Scope by framework, and get it signed. Which frameworks apply, to which entities, in which jurisdictions. Applicability is entity-specific — and, as the UAE Information Assurance transition demonstrated, sometimes version-specific. Where applicability is a legal question, we say so and recommend counsel.

  2. Gather evidence once. A single structured evidence set organised around the underlying control question rather than around any one framework's chapter headings. One asset inventory exercise. One access review. One logging assessment.

  3. Assess against outcomes, not checkboxes. We use the outcome-based logic of the NCSC Cyber Assessment Framework as our internal assessment engine — it produces materially better findings than checklist scoring — and report against whichever framework you are accountable to.

  4. Report natively, per framework. SAMA in SAMA's maturity model. NCA in ECC-2 structure. The UAE IA Standard v2 in its Always Applicable and Based on Risk classification. Each output stands alone and is defensible to its own regulator. We do not produce a merged score, because the assessment models are not arithmetically combinable — and a blended figure would not survive regulatory scrutiny.

  5. Document the divergences explicitly. Overlap is not equivalence. Where the frameworks genuinely differ — data residency, third-party depth, incident reporting timelines, applicability models, OT scope, and design-versus-effectiveness evidence standards — each difference is documented and addressed rather than smoothed over.

  6. Quantify the material gaps financially. Using Open FAIR methodology, priority gaps are expressed as probable annualised loss ranges. Once gaps carry monetary values, sequencing becomes an investment decision rather than a negotiation.

ENGAGEMENTS

AS-01 Multi-Framework Gap Assessment

Typical duration: 15-25 days

Single evidence-gathering exercise producing framework-native outputs across multiple frameworks, plus a divergence report

AS-02 Single-Framework Assessment

Typical duration: 10-18 days

Full assessment against one framework, with prioritised gap analysis and roadmap

AS-03 Certification Readiness Review

Typical duration: 10-15 days

Pre-certification gap assessment and remediation plan ahead of an accredited body's audit

AS-04 Internal Audit Technical Support

Typical duration: 5-12 days

Technical assessment and evidence preparation supporting your internal audit function

AS-05 Regulatory Change Impact Assessment

Typical duration: 5-10 days

The impact of a new or amended framework version on your control estate and evidence base

AS-06 Cyber Resilience Assessment

Typical duration: 12-20 days

Outcome-based resilience review of essential functions and recovery capability

AS-07 Third-Party Assurance Review

Typical duration: 12-20 days

Vendor tiering model, assurance framework, SBOM strategy, aligned to NIST SP 800-161r1

Cyber risk quantification and board reporting are delivered under our Regulatory Assurance & Cyber Risk practice.

THE METHOD IS PUBLISHED

We publish the framework crosswalk that underpins this work — mapping NCSC CAF v4.0, NCA ECC-2:2024, the UAE Information Assurance Standard v2 and NIST CSF 2.0, with direction-of-fit notation on every mapping and a register of the six areas where the frameworks genuinely diverge.

 

It is free, ungated, and you are welcome to use it whether or not you engage us.

FRAMEWORKS APPLIED

Regional: NCA ECC-2:2024 · NCA OTCC-1:2022 · NCA CSCC · UAE Information Assurance Standard v2 (UAE Cyber Security Council) · SAMA Cyber Security Framework · CBUAE · QCB · CBB · ADHICS
International: NIST CSF 2.0 · ISO/IEC 27001:2022 · NCSC CAF v4.0 · CSA CCM v4.1 · IEC 62443 · Open FAIR · NIST SP 800-161r1

bottom of page