All insights
ArticleArticle · NCA ECCin the NCA ECC Business Continuity Requirements series

The NCA ECC Resilience Evidence Reviewers Ask For First

A practical checklist of the business continuity evidence that satisfies the NCA ECC Cybersecurity Resilience domain — what to have ready, what makes an artefact defensible, and the four gaps that turn a good programme into a finding.

The BCM DeskBCMStack Editorial · Riyadh
28 July 20267 min read

Reviewers do not assess your continuity capability. They assess the artefacts you can produce that describe it. Those are different things, and the distance between them is where most findings live.

This is the evidence set that answers the NCA ECC Cybersecurity Resilience domain, in roughly the order it gets asked for.

What makes any artefact defensible

Before the list — the test every item has to pass. A continuity artefact is credible when it is:

  • Dated. With a review date, not just a creation date.
  • Owned. A named role, not a department.
  • Approved. Through whatever governance body your policy says approves it.
  • Current. Consistent with the organisation as it exists now, not as it was at the last reorganisation.
  • Traceable. Connected to the thing it derives from — plans to BIA, objectives to impact analysis, actions to findings.

An artefact failing any of those reads as a draft, regardless of quality. Most findings are not "you don't have a BCP" — they are "your BCP references a system you decommissioned last year."

The evidence set

1. Scope and critical service inventory

What is in the continuity programme and what isn't, with the reasoning. Reviewers test the boundary — an inventory that covers everything equally suggests nothing has been prioritised, and one that omits an obviously critical service invites the question of why.

Have ready: the critical service list, the criteria used to designate criticality, and the approval record for the scope.

2. Business impact analysis with cyber scenarios

The BIA is the foundation everything else derives from, and the first place a reviewer probes for the cyber lens.

Have ready: impact-over-time analysis per critical service, recovery objectives with the reasoning behind them, dependency mapping, and — the differentiator under ECC — evidence that compromise-driven disruption was assessed, not just physical loss. Dependency mapping covers the technique.

The question to pre-empt: "Does this RTO account for containment and clean rebuild, or only for restoring service?"

3. Continuity and disaster recovery plans

Plans that a competent person could execute under pressure without the author present.

Have ready: continuity plans per critical service, DR plans for supporting infrastructure, named cyber-specific recovery paths (ransomware, isolated restore, clean-environment rebuild), invocation criteria, and role assignments with current names.

4. Backup integrity and tested restoration

The single most probed area, because it is the one where cyber framing most changes the answer.

Have ready: backup architecture including immutability or offline provisions, restoration test records with dates and measured recovery times, and evidence that restoration was tested from a known-clean copy rather than the most recent set.

5. Recovery-environment assurance

The step most DR runbooks skip: how you establish that the environment you are recovering into is clean.

Have ready: the documented verification step in the recovery sequence, who performs it, and what evidence they produce before service is declared restored.

6. Exercise records

Evidence that the capability has been tested, not just documented.

Have ready: the exercise calendar, records per exercise (scenario, date, participants, injects, observations), at least one cyber-scenario exercise per cycle, and the findings each produced. After-action reporting covers the record format.

The pattern reviewers look for: exercises that produced findings. An exercise with no findings is read as either trivially scoped or unrecorded.

7. The incident-response-to-continuity handoff

Where security incident handling becomes a continuity invocation.

Have ready: the declaration threshold, who holds authority to declare, the escalation path, and the handoff of command between security and continuity leadership. Crisis activation criteria covers how to write thresholds that hold up.

8. Crisis communication with out-of-band provision

Have ready: the stakeholder matrix, notification templates, and the alternative communication path for scenarios where primary channels are unavailable or untrusted — including an offline contact roster. The crisis communications playbook covers the structure.

9. Governance and management review

Have ready: the BCM policy with approval record, committee terms of reference, meeting minutes showing continuity was actually discussed, and management review outputs. Management review records that show decisions carry more weight than attendance lists.

10. The improvement register

Where everything closes the loop. Findings from exercises, incidents, reviews and prior assessments, with owners, target dates and closure evidence.

This is the artefact that most distinguishes a live programme from a documented one. An open finding with a credible plan is a healthier signal than an empty register.

The four gaps that produce findings

Across the programmes we see, the same four:

  1. Untested restoration. Backups exist; nobody has restored from them under realistic conditions.
  2. Physical-only scenarios. A complete, well-maintained BCP that never contemplates compromise.
  3. A missing handoff. Security owns incidents, BCM owns continuity, and no document says where one becomes the other.
  4. An open-loop register. Findings raised and never closed — or worse, exercises that never raised any.

Each is fixable in weeks. None is fixable during a review.

Sequencing a readiness push

If you are working to a date, the order that recovers the most ground per week:

  1. 1

    Fix ownership and dates across every artefact

    Cheapest credibility win available. One pass, a few days, removes an entire category of finding.

  2. 2

    Run a restoration test and record it

    Longest lead time of anything on this list, and the most probed. Start it first even though it lands later.

  3. 3

    Add cyber scenarios to the BIA for critical services

    Not all services — the critical ones. Partial coverage with clear reasoning beats a blanket update nobody reviewed.

  4. 4

    Write the declaration threshold

    Usually a single page, usually genuinely missing, and it closes a gap reviewers reliably find.

  5. 5

    Run one cyber-scenario tabletop and capture findings

    A tabletop with a real findings list is worth more than a technical test with none.

  6. 6

    Close what you can, plan the rest

    Nobody expects a register with no open items. They expect owners and dates on the ones that remain.

Where tooling helps

The difference between assembling this pack in a day and assembling it over three weeks is whether the evidence lives in one system or is reconstructed from shared drives and inboxes. The NCA ECC resilience controls page maps each of these evidence types to the module that holds it — and is explicit about the ECC domains outside a BCM platform's scope.

For institutions also under Saudi Central Bank supervision, NCA ECC vs SAMA BCM covers assembling both packs from one artefact set.

Frequently asked questions

How far back should evidence go?

Far enough to show a working cycle — typically the last full annual cycle of exercises, reviews and improvement actions. A single point-in-time snapshot cannot demonstrate that the programme operates continuously, which is the underlying question.

Is an open finding a problem?

An open finding with a named owner and a target date is a sign of a functioning programme. An empty improvement register on a programme that runs exercises is the answer that invites scrutiny — it suggests exercises are not producing honest observations.

Do we need Arabic documentation?

Requirements vary by supervisor and entity type, and SAMA-regulated institutions face expectations that differ from general ECC scope. Confirm the language requirement for your specific obligations rather than assuming either way.

Related reading

BCMStack platform

Put what you've just read into practice.

Native ISO 22301 §8.4.4 plans, ISO 22398 exercise programme, SAMA-mapped reporting. Built for KSA & GCC continuity teams.

Request access