Skip to content

Own Your SIEM Solution for NCA ECC & SAMA CSF Compliance

Most enterprise SIEMs are built for generic global frameworks — your team ends up spending months retrofitting detection rules just to pass a local audit.

WhyCrew engineers fully owned SIEM architectures, pre-mapped to NCA ECC's Control 2-12 and SAMA CSF's subdomain 3.14 from day one. Custom log parsers, regulatory-aligned detection logic, audit-ready dashboards — built to your exact data requirements, not adapted from a template made for another market.

No recurring license bloat. No data sovereignty compromises. You own the infrastructure, the pipelines, and the detection code outright.

100%
You own the platform and the code when we hand it over
12 wks
Typical time to launch
12–18 mo
NCA ECC log retention, built in from day one — 12 months base, 18 for critical systems under CSCC
0
Ongoing per-GB fees

Built for the rule that applies to you

Built for the Rule That Applies to You

Same owned-platform approach, engineered around whichever framework governs your organization.

Why Control 2-12 Changes Everything for Saudi MSSPs

If you hold — or are working toward — an NCA Tier 1 or Tier 2 MSOC license in Saudi Arabia, Control 2-12 is the rule your platform has to meet.

Here's what it actually requires: your platform must run real SIEM tools, watch every log around the clock, and hold that log data for at least 12 months. If you monitor national critical systems, CSCC raises that retention window to 18 months.

WhyCrew builds that platform for you, engineered around Control 2-12 from day one — not adapted from something built for another market. At the end of the build, you get the full platform and the source code. This is real engineering work, not a checkbox to tick for your license.

Where generic platforms fail

Why Generic SIEM Platforms Fail NCA ECC and SAMA CSF

PROBLEM 01

Per-GB pricing costs more right when Control 2-12 makes you keep more data.

12 months of logs, minimum — 18 if critical systems are in scope. A platform billed by data size punishes you for doing the rule right.

PROBLEM 02

Generic SIEM products bolt on ECC as an afterthought.

Most SIEM platforms in this market were built for the world first. Saudi rules got mapped on top, later — not built for Control 2-12 from day one.

PROBLEM 03

If you're the MSOC provider, you can't outsource your own platform.

Outsourcing the platform behind your own licensed service just moves the "rent, not own" problem up one level.

PROBLEM 04

Outsourcing your event management platform doesn't shift who SAMA holds accountable.

SAMA's rules apply entity-wide, including for what your third parties do on your behalf. If an outsourced platform falls short of subdomain 3.14, that risk stays yours — not your vendor's.

The real cost

Rent, Outsource, or Own: Compare the Real Cost

Licensed SIEM ProductOutsourced / White-LabelWhyCrew (Owned)
Who owns itThe vendorThe platform providerYou
Pricing modelPer-GB, scales with log volumeRecurring platform feeFixed build cost, no recurring license
Built for Control 2-12 / SAMA 3.14Mapped on afterwardDepends on providerEngineered around it directly
Roadmap controlVendor's roadmapProvider's roadmapYours
Retention cost as you scaleGrows with data volumeOften capped or tieredFixed infrastructure you control
ExitRe-platform and migrateRe-platform and migrateNothing to exit — you already own it

Getting started

Two Ways to Get Started

Build New

Starting From Scratch?

For Saudi MSSPs building a custom SIEM for a first Tier 1 or Tier 2 MSOC license, or for SAMA-regulated financial institutions building out subdomain 3.14 event management capability from scratch. We build it around Control 2-12 or SAMA CSF, whichever applies to you, from the ground up — no off-the-shelf product, adapted after the fact.

Migrate

Already Running a Licensed SIEM?

Splunk, Microsoft Sentinel, IBM QRadar, or similar — if you want to move to a platform you own without breaking your log history or your audit trail, we run the new platform next to your old one during the move. Your retention window stays whole through the switch.

How it works

How It Works

Build a new platform, or move an old one — for NCA ECC, SAMA CSF, or both. Either way, the steps are the same.

01

Get a fixed price before anything starts

We map your log volume, retention needs, and license or regulatory status against Control 2-12 or SAMA CSF 3.14, whichever applies to you. No surprises later.

02

Approve the blueprint, not a black box

You review and approve the architecture, detection logic, and retention plan — including how the platform will prove compliance for your own audits.

03

See it work on real data first

The platform runs on a live account before the full switch. Problems surface early, not after go-live.

04

Walk away owning everything

We hand over the full platform, the source code, and the records. Nothing stays licensed back to WhyCrew.

Global track record

Real Results From Real MSSPs

WhyCrew works with MSSPs worldwide — every result below is a real, published case study, not a projection.

SIEM & SOAR · MSSP & White-Label

Scaling MSSP Engineering Without Scaling Headcount

Engineering output vs. one hire
10 days
To first production ship

A growing MSSP had one engineer covering work that realistically needed three or four. An embedded WhyCrew engineering pod consolidated detection, ingestion, and automation under one team, shipping production work in 10 days.

Read the case study →

SIEM & SOAR · Platform Ownership

Replacing a Rented Threat-Intel Feed With an Owned Pipeline

$40K
Annual licensing eliminated
80%
Reduction in manual triage

A regional SOC paid $40K a year for a commercial threat-intel feed that still left analysts checking domains and hashes by hand. An owned ingestion and enrichment pipeline cut manual triage by 80%.

Read the case study →

Platform Ownership · SIEM & SOAR

Bringing Identity Monitoring In-House to Escape a Capped Vendor

$180K
Annual vendor bill eliminated
6 wks
Transition timeline

A cybersecurity provider paid $180K a year for dark-web monitoring capped by API limits and delayed alerts. A proprietary collection pipeline, deployed in six weeks, removed the caps entirely.

Read the case study →

SIEM & SOAR · Platform Ownership

From SIEM Rent to an Owned Security Platform

$270K
Saved across 24 months
$110K
Year-1 direct savings

A growing MSSP was paying more for its SIEM with every client it won. Moving to an owned, multi-tenant platform removed the per-gigabyte pricing curve and returned $270K across 24 months.

Read the case study →

Said plainly

What's Not Included

WhyCrew builds the platform. WhyCrew does not hold, grant, or apply for your NCA MSOC license, and does not act as your SAMA-regulated entity's compliance officer or auditor. The NCA and SAMA each issue their own approvals directly.

The request, the audit, and the approval stay between you and your regulator. WhyCrew builds the platform that meets the rules — like Control 2-12 or SAMA CSF subdomain 3.14 — that those approvals depend on.

Frequently asked questions

NCA ECC & SAMA CSF, answered

Both. WhyCrew builds SIEM platforms engineered around NCA ECC's Control 2-12 and around SAMA CSF's subdomain 3.14, Cyber Security Event Management. They are two separate frameworks with their own domains and controls, and WhyCrew scopes your build against whichever one applies to you — or both, if your organization sits under both regulators.

Subdomain 3.14, Cyber Security Event Management, requires a SIEM that aggregates every security event in one place, a SOC team providing round-the-clock response, and log storage that meets SAMA's retention expectations. SAMA typically holds this subdomain to Level 4 on its 0-to-5 maturity scale — its highest bar for most domains.

No. We build the platform whether you already hold a Tier 1 or Tier 2 MSOC license or are still working toward one. The license itself is issued by the NCA directly to your organization — WhyCrew builds the platform your application and your audits depend on.

12 months is the NCA ECC baseline. If NCA has designated any of your systems as critical infrastructure, CSCC raises that requirement to 18 months. SAMA CSF doesn't set a fixed number — it ties retention to your risk classification instead.

12 weeks is the typical timeline from kickoff to a platform in production, whether you're building new or migrating off an existing SIEM. Exact timing depends on log volume and how many systems are in scope.

SAMA CSF applies to entities the Saudi Central Bank directly supervises — conventional and Islamic banks, insurers and reinsurers, financing companies, payment service providers, money exchange businesses, credit bureaus, and SAMA-licensed fintechs. Firms operating near financial services without a SAMA license usually fall outside its scope, though NCA ECC may still apply.

Yes. Every platform WhyCrew builds under this service is engineered around Control 2-12 from day one — continuous SIEM-based log monitoring and a minimum 12-month retention window, extended to 18 months for systems in scope under CSCC — rather than a generic SIEM with Saudi controls mapped on afterward.

Yes. We run the new platform alongside your existing one during the move, so your retention window and log history stay intact throughout the switch. Nothing in your audit trail goes dark while the migration is in progress.

Wherever your data residency requirements call for. WhyCrew engineers the platform around your infrastructure rather than routing your logs through a vendor's own hosting, so there's no compromise on where your data actually sits.

Everything: the platform, the full source code, the detection logic, and the compliance records generated along the way. Nothing stays licensed back to WhyCrew, and there's no recurring fee tied to keeping it running.

Own Your SIEM. Stop Retrofitting Someone Else's.

Talk to WhyCrew's engineers about a build or a move for your MSSP or SAMA-regulated institution in Saudi Arabia — fixed price, before any work starts.

Fixed price before any work starts · Full platform ownership at handover