Own Your SIEM Solution for NCA ECC & SAMA CSF Compliance
Most enterprise SIEMs are built for generic global frameworks — your team ends up spending months retrofitting detection rules just to pass a local audit.
WhyCrew engineers fully owned SIEM architectures, pre-mapped to NCA ECC's Control 2-12 and SAMA CSF's subdomain 3.14 from day one. Custom log parsers, regulatory-aligned detection logic, audit-ready dashboards — built to your exact data requirements, not adapted from a template made for another market.
No recurring license bloat. No data sovereignty compromises. You own the infrastructure, the pipelines, and the detection code outright.
Built for the rule that applies to you
Built for the Rule That Applies to You
Same owned-platform approach, engineered around whichever framework governs your organization.
Why Control 2-12 Changes Everything for Saudi MSSPs
If you hold — or are working toward — an NCA Tier 1 or Tier 2 MSOC license in Saudi Arabia, Control 2-12 is the rule your platform has to meet.
Here's what it actually requires: your platform must run real SIEM tools, watch every log around the clock, and hold that log data for at least 12 months. If you monitor national critical systems, CSCC raises that retention window to 18 months.
WhyCrew builds that platform for you, engineered around Control 2-12 from day one — not adapted from something built for another market. At the end of the build, you get the full platform and the source code. This is real engineering work, not a checkbox to tick for your license.
Where generic platforms fail
Why Generic SIEM Platforms Fail NCA ECC and SAMA CSF
Per-GB pricing costs more right when Control 2-12 makes you keep more data.
12 months of logs, minimum — 18 if critical systems are in scope. A platform billed by data size punishes you for doing the rule right.
Generic SIEM products bolt on ECC as an afterthought.
Most SIEM platforms in this market were built for the world first. Saudi rules got mapped on top, later — not built for Control 2-12 from day one.
If you're the MSOC provider, you can't outsource your own platform.
Outsourcing the platform behind your own licensed service just moves the "rent, not own" problem up one level.
Outsourcing your event management platform doesn't shift who SAMA holds accountable.
SAMA's rules apply entity-wide, including for what your third parties do on your behalf. If an outsourced platform falls short of subdomain 3.14, that risk stays yours — not your vendor's.
The real cost
Rent, Outsource, or Own: Compare the Real Cost
| Licensed SIEM Product | Outsourced / White-Label | WhyCrew (Owned) | |
|---|---|---|---|
| Who owns it | The vendor | The platform provider | You |
| Pricing model | Per-GB, scales with log volume | Recurring platform fee | Fixed build cost, no recurring license |
| Built for Control 2-12 / SAMA 3.14 | Mapped on afterward | Depends on provider | Engineered around it directly |
| Roadmap control | Vendor's roadmap | Provider's roadmap | Yours |
| Retention cost as you scale | Grows with data volume | Often capped or tiered | Fixed infrastructure you control |
| Exit | Re-platform and migrate | Re-platform and migrate | Nothing to exit — you already own it |
Getting started
Two Ways to Get Started
Starting From Scratch?
For Saudi MSSPs building a custom SIEM for a first Tier 1 or Tier 2 MSOC license, or for SAMA-regulated financial institutions building out subdomain 3.14 event management capability from scratch. We build it around Control 2-12 or SAMA CSF, whichever applies to you, from the ground up — no off-the-shelf product, adapted after the fact.
Already Running a Licensed SIEM?
Splunk, Microsoft Sentinel, IBM QRadar, or similar — if you want to move to a platform you own without breaking your log history or your audit trail, we run the new platform next to your old one during the move. Your retention window stays whole through the switch.
How it works
How It Works
Build a new platform, or move an old one — for NCA ECC, SAMA CSF, or both. Either way, the steps are the same.
Get a fixed price before anything starts
We map your log volume, retention needs, and license or regulatory status against Control 2-12 or SAMA CSF 3.14, whichever applies to you. No surprises later.
Approve the blueprint, not a black box
You review and approve the architecture, detection logic, and retention plan — including how the platform will prove compliance for your own audits.
See it work on real data first
The platform runs on a live account before the full switch. Problems surface early, not after go-live.
Walk away owning everything
We hand over the full platform, the source code, and the records. Nothing stays licensed back to WhyCrew.
Global track record
Real Results From Real MSSPs
WhyCrew works with MSSPs worldwide — every result below is a real, published case study, not a projection.
SIEM & SOAR · MSSP & White-Label
Scaling MSSP Engineering Without Scaling Headcount
A growing MSSP had one engineer covering work that realistically needed three or four. An embedded WhyCrew engineering pod consolidated detection, ingestion, and automation under one team, shipping production work in 10 days.
Read the case study →SIEM & SOAR · Platform Ownership
Replacing a Rented Threat-Intel Feed With an Owned Pipeline
A regional SOC paid $40K a year for a commercial threat-intel feed that still left analysts checking domains and hashes by hand. An owned ingestion and enrichment pipeline cut manual triage by 80%.
Read the case study →Platform Ownership · SIEM & SOAR
Bringing Identity Monitoring In-House to Escape a Capped Vendor
A cybersecurity provider paid $180K a year for dark-web monitoring capped by API limits and delayed alerts. A proprietary collection pipeline, deployed in six weeks, removed the caps entirely.
Read the case study →SIEM & SOAR · Platform Ownership
From SIEM Rent to an Owned Security Platform
A growing MSSP was paying more for its SIEM with every client it won. Moving to an owned, multi-tenant platform removed the per-gigabyte pricing curve and returned $270K across 24 months.
Read the case study →Said plainly
What's Not Included
WhyCrew builds the platform. WhyCrew does not hold, grant, or apply for your NCA MSOC license, and does not act as your SAMA-regulated entity's compliance officer or auditor. The NCA and SAMA each issue their own approvals directly.
The request, the audit, and the approval stay between you and your regulator. WhyCrew builds the platform that meets the rules — like Control 2-12 or SAMA CSF subdomain 3.14 — that those approvals depend on.
Frequently asked questions
NCA ECC & SAMA CSF, answered
Both. WhyCrew builds SIEM platforms engineered around NCA ECC's Control 2-12 and around SAMA CSF's subdomain 3.14, Cyber Security Event Management. They are two separate frameworks with their own domains and controls, and WhyCrew scopes your build against whichever one applies to you — or both, if your organization sits under both regulators.
Subdomain 3.14, Cyber Security Event Management, requires a SIEM that aggregates every security event in one place, a SOC team providing round-the-clock response, and log storage that meets SAMA's retention expectations. SAMA typically holds this subdomain to Level 4 on its 0-to-5 maturity scale — its highest bar for most domains.
No. We build the platform whether you already hold a Tier 1 or Tier 2 MSOC license or are still working toward one. The license itself is issued by the NCA directly to your organization — WhyCrew builds the platform your application and your audits depend on.
12 months is the NCA ECC baseline. If NCA has designated any of your systems as critical infrastructure, CSCC raises that requirement to 18 months. SAMA CSF doesn't set a fixed number — it ties retention to your risk classification instead.
12 weeks is the typical timeline from kickoff to a platform in production, whether you're building new or migrating off an existing SIEM. Exact timing depends on log volume and how many systems are in scope.
SAMA CSF applies to entities the Saudi Central Bank directly supervises — conventional and Islamic banks, insurers and reinsurers, financing companies, payment service providers, money exchange businesses, credit bureaus, and SAMA-licensed fintechs. Firms operating near financial services without a SAMA license usually fall outside its scope, though NCA ECC may still apply.
Yes. Every platform WhyCrew builds under this service is engineered around Control 2-12 from day one — continuous SIEM-based log monitoring and a minimum 12-month retention window, extended to 18 months for systems in scope under CSCC — rather than a generic SIEM with Saudi controls mapped on afterward.
Yes. We run the new platform alongside your existing one during the move, so your retention window and log history stay intact throughout the switch. Nothing in your audit trail goes dark while the migration is in progress.
Wherever your data residency requirements call for. WhyCrew engineers the platform around your infrastructure rather than routing your logs through a vendor's own hosting, so there's no compromise on where your data actually sits.
Everything: the platform, the full source code, the detection logic, and the compliance records generated along the way. Nothing stays licensed back to WhyCrew, and there's no recurring fee tied to keeping it running.
Own Your SIEM. Stop Retrofitting Someone Else's.
Talk to WhyCrew's engineers about a build or a move for your MSSP or SAMA-regulated institution in Saudi Arabia — fixed price, before any work starts.
Fixed price before any work starts · Full platform ownership at handover