Guide

How NVector works

NVector is a governance, risk and compliance platform. It gives you one place to track the controls you are required to implement, hold the evidence that proves it, manage risk and incidents, and produce the reports a regulator, auditor or board asks for. This page is the short version.

The idea in three steps

Everything else in the platform follows from this one.

  1. The problem

    The same work, written up several times

    Most regulated organisations answer to more than one rulebook. Access control appears in ISO 27001, in NIST CSF, in NCA ECC and in SOC 2 — worded differently each time. Done in spreadsheets, that one piece of work gets tracked, evidenced and reported four separate times, and the four copies drift apart.

  2. The idea

    One control library underneath every framework

    NVector inverts it. You maintain one library of plain-language controls. Each control is mapped to the specific clause it satisfies in every framework you have switched on, and the mapping records whether that coverage is full or partial. You work the control, not the rulebook.

  3. The result

    Implement once, close everywhere

    Mark a control implemented and every requirement it fully satisfies closes with it, across every framework at once. Switching on a new framework starts partly complete, because the work behind it is already done and already evidenced.

What is in the platform

Eleven modules, each one feeding the same picture rather than keeping its own.

Evidence Vault

Proof attached to the control it proves, ready before the examiner asks.

Tasks

Every obligation becomes somebody’s job, with a date on it.

Asset Management

You cannot protect, or evidence, what you have not written down.

Audit

Turn examination season into a report, not a project.

Vulnerabilities

Findings that carry a deadline and an owner, not just a severity.

Reports

The board pack builds itself from the data you already keep.

See each module in detail

The frameworks it covers

All 8 ship with the product, requirement sets already mapped to the control library. Your own internal standards can sit alongside them.

  • NIST Cybersecurity Framework NIST · 2.0
  • ISO/IEC 27001 ISO/IEC · 2022
  • NCA Essential Cybersecurity Controls Saudi National Cybersecurity Authority · ECC
  • SOC 2 AICPA · Trust Services Criteria
  • CIS Controls Center for Internet Security · v8
  • HIPAA U.S. Department of Health and Human Services · Security & Privacy Rules
  • SAMA Cyber Security Framework Saudi Central Bank · 1.0
  • Aramco CCC Saudi Aramco · Cybersecurity Compliance Certificate

Read the framework library

What the first month looks like

A realistic shape, not a promise. Yours will move around depending on how much you already have written down.

  1. Week 1

    Switch on your frameworks

    Pick the frameworks you actually report against. Their full requirement sets load with the product — there is no content project — and you get a coverage position on day one, including the parts you have already done.

  2. Week 2

    Load what you already have

    Your existing policies, procedures and evidence go into the vault and get linked to the controls they support. Most teams arrive from spreadsheets; that baseline is the starting point, not something to throw away.

  3. Week 3

    Give the gaps an owner and a date

    Whatever is left open becomes a task against a named person with a deadline. Risks get scored and banded, assets get recorded, and the register stops being a document that is only accurate on the day of the meeting.

  4. Ongoing

    Keep it current, and prove it

    Evidence expires, policies come up for review, incidents start a clock, and reports build themselves from live data. The point is that examination season becomes a report rather than a project.

Common questions

Do I need to know a framework inside out to start?

No. The requirement sets and the control library ship with the product, written in plain language. You are choosing which frameworks apply and confirming what you already do — not authoring a control set from a standard document.

What if we only report against one framework today?

That works, and it is the common starting point. The value of the shared library shows up the first time somebody asks you for a second one — a customer wanting SOC 2, or a contract requiring a regional certification. The second framework starts partly complete.

Can we load our own internal standard?

Yes. Internal standards and group policies sit alongside the published frameworks and map to the same control library, so internal obligations are tracked the same way as regulatory ones.

Who in the team actually uses it day to day?

Compliance and risk staff live in it. Control owners across IT and the business get tasks and evidence requests rather than a login they have to learn. Auditors get a read-only view, and executives get the reports.

How long before it is useful?

Cloud deployments are usable the same day, because nothing has to be built first. A realistic answer for a full picture across several frameworks is a few weeks of loading what you already have.

See it against your own frameworks

Thirty minutes in the live platform, using the rulebooks you actually report against.