Controls · Cybersecurity · Saudi Arabia
NCA ECC compliance means meeting the Essential Cybersecurity Controls set by Saudi Arabia's National Cybersecurity Authority. The current edition, ECC-2:2024, has 4 domains, 28 subdomains and 108 controls, and applies to government organisations, critical national infrastructure operators and the companies that serve them.
Government bodies, critical national infrastructure, and the organisations that serve them.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
NCA ECC requires in-scope organisations to govern cybersecurity through an independent function and approved policies, defend their systems with technical controls, build cybersecurity into business continuity, and manage third-party and cloud risk.
10 subdomains: strategy, function, policies, risk, audit, HR, training.
In QULDEX: Governance evidence mapped15 subdomains: access, systems, network, data, crypto, logs, incidents.
In QULDEX: Controls mapped to ISO 27001Cybersecurity in business continuity.
In QULDEX: BCP evidence reusedSupplier and cloud hosting security.
In QULDEX: Vendor registerIndependent reviews and NCA assessments.
In QULDEX: Audit workspaceThese 24 subdomains carry most of the work, grouped by ECC-2:2024 domain. Select any subdomain to see what it asks for, typical evidence and the matching ISO 27001 control.
Showing up to 6 per group. Search, filter, or open a group to see all 24.
1-1Cybersecurity strategyDefine, document and approve a cybersecurity strategy aligned with the organisation's objectives and national requirements.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
1-2Cybersecurity managementSet up a cybersecurity function, independent from IT, led by a full-time, qualified Saudi national.
In QULDEXThe function, its head and its reporting line are on record.
1-3Policies and proceduresDocument, approve and publish cybersecurity policies and procedures, and review them periodically.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
1-4Roles and responsibilitiesDefine and approve cybersecurity roles and responsibilities across the organisation.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
1-5Risk managementAssess and treat cybersecurity risks, including before new projects and major changes.
In QULDEXThe risk register holds assessments and treatments.
1-6Cybersecurity in IT projectsInclude cybersecurity requirements in project and change management, including secure development.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
1-7Compliance with laws and regulationsComply with national cybersecurity legislation and regulations.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
1-8Periodical review and auditReview the implementation of cybersecurity controls periodically, independently of the cybersecurity function.
In QULDEXReviews run in the audit workspace with findings into CAPA.
1-9Cybersecurity in human resourcesAddress cybersecurity before, during and after employment.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
1-10Awareness and trainingRun awareness programmes and specialised training.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
2-1Asset managementKeep an accurate, up-to-date inventory of information and technology assets.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
2-2Identity and access managementControl logical access with least privilege, MFA for remote and privileged access, and periodic reviews.
In QULDEXAccess reviews run as recurring tasks.
2-3Systems and processing facilities protectionProtect systems and devices with malware protection, patching, hardening and secure configuration.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
2-5Network security managementSegregate and protect networks, including internet browsing, wireless and DNS.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
2-7Data and information protectionProtect data according to its classification and applicable law.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
2-8CryptographyUse cryptographic solutions according to national cryptographic standards.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
2-9Backup and recovery managementBack up data and systems and test restoration periodically.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
2-10Vulnerability managementDetect and remediate technical vulnerabilities on time.
In QULDEXFindings become CAPA items with due dates.
2-11Penetration testingRun penetration tests periodically on external services and critical systems.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
2-12Event logs and monitoringCollect, analyse and monitor security event logs, with defined retention.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
2-13Incident and threat managementDetect, respond to and report cybersecurity incidents, and use threat intelligence.
In QULDEXIncidents run with timers and NCA reporting records.
3-1Resilience in business continuityInclude cybersecurity in business continuity management and test it.
In QULDEXContinuity evidence is reused from ISO 22301.
4-1Third-party cybersecurityAddress cybersecurity in contracts and relationships with third parties, including outsourcing.
In QULDEXEach third party is assessed and linked to its services.
4-2Cloud computing and hostingData residencyMeet cybersecurity requirements for cloud and hosting, including hosting data in the Kingdom where required.
In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.
Nothing matches that search.
Subdomain numbers follow ECC-2:2024. Summaries are QULDEX paraphrases; the NCA document is the authority.
Confirm you are in scope, set up an independent cybersecurity function, close the gaps against the 108 controls and evidence them for NCA. Most organisations need 6 to 12 months, less with ISO 27001 in place.
Check whether you are a government body, CNI operator or a supplier to one.
Independent from IT, led by a qualified Saudi national, with an approved strategy.
Assess all 108 controls, reusing ISO 27001 evidence.
Policies, technical controls, logging, testing and third-party clauses.
Submit the self-assessment and support NCA audits with evidence.
Durations are QULDEX planning ranges.
Assessors ask for these records.
| Document | Subdomain | Where it lives in QULDEX |
|---|---|---|
| Cybersecurity strategy | 1-1 | Policy library |
| Function charter and head appointment | 1-2 | Policy library |
| Policies and procedures | 1-3 | Policy library |
| Risk assessments | 1-5 | Risk register |
| Periodic review reports | 1-8 | Audit workspace |
| Training records | 1-10 | Evidence vault |
| Asset inventory | 2-1 | Risk register |
| Access reviews | 2-2 | Evidence vault |
| Vulnerability and pen test reports | 2-10, 2-11 | CAPA automation |
| Incident reports | 2-13 | CAPA automation |
| Third-party and cloud assessments | 4-1, 4-2 | Vendor register |
Subdomain numbers follow ECC-2:2024.
Most organisations need 6 to 12 months. The cybersecurity function, logging and third-party contracts usually take longest.
Bars show the upper end of each range on one scale (12 months = full width).
Check these eight things first. Nothing you enter leaves this page.
ISO 27001 covers most ECC controls; SAMA CSF applies on top for financial institutions; the PDPL governs personal data. One control set can serve all of them.
| NCA ECC-2:2024 | ISO 27001:2022 | SAMA CSF | Saudi PDPL | Shared evidence |
|---|---|---|---|---|
| 1-2 Function | 5.3 | 3.1.2 Organisation | — | Appointments |
| 1-5 Risk management | 6.1 | 3.2.1 | Art. 19 security | Risk register |
| 2-2 Access | A.5.15–A.5.18 | 3.3.5 | — | Access reviews |
| 2-7 Data protection | A.5.12 | 3.3.8 | Data handling | Classification |
| 2-12 Logs | A.8.15 | 3.3.14 | — | Logs |
| 2-13 Incidents | A.5.24–A.5.26 | 3.3.15 | Breach notice | Incident reports |
| 4-1 Third parties | A.5.19–A.5.22 | 3.4 | Processor contracts | Vendor register |
Indicative mapping for planning; SAMA CSF and PDPL references are approximate section labels. The full crosswalk is in the QULDEX control library.
QULDEX is NCA ECC compliance and audit management software built from EGV Group's audit delivery, used by in-scope organisations, their advisors and the auditors who review them. Pick your role to see who does what.
For government bodies, CNI operators and suppliers.
For cybersecurity consultants and internal audit.
For independent reviewers and NCA assessments.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →The Essential Cybersecurity Controls issued by Saudi Arabia's National Cybersecurity Authority. The current edition, ECC-2:2024, sets 108 controls in 4 domains for government organisations, critical national infrastructure and their suppliers.
The 2024 edition reorganises the controls into 4 domains, 28 subdomains and 108 controls with 92 subcontrols, and updates requirements on areas such as third-party and cloud security. Industrial control systems are covered by the separate OTCC.
Government organisations, critical national infrastructure operators, and private companies that own, operate or host critical systems or provide services to them.
Much of it, but ECC adds Saudi-specific requirements, such as a cybersecurity function led by a qualified Saudi national and national cryptography and data hosting rules.
Financial institutions regulated by SAMA follow the SAMA Cyber Security Framework; where they are also in NCA scope, both apply and most evidence overlaps.
NCA ECC, SAMA CSF, UAE IAS and Gulf data protection laws.
blog.quldex.comA file-naming scheme reviewers can follow.
blog.quldex.comHow many samples auditors look at.
blog.quldex.comHow auditors grade findings.
Reviewed by
Answer a short readiness check and get a gap summary by domain. No sales call needed to see the result.