Controls · Cybersecurity · Saudi Arabia

NCA ECC compliance: the 108 Essential Cybersecurity Controls explained

NCA ECC compliance means meeting the Essential Cybersecurity Controls set by Saudi Arabia's National Cybersecurity Authority. The current edition, ECC-2:2024, has 4 domains, 28 subdomains and 108 controls, and applies to government organisations, critical national infrastructure operators and the companies that serve them.

Key takeaways

What you need to know about NCA ECC

Four domainsGovernance, defence, resilience, and third-party and cloud security.
Saudi leadershipThe cybersecurity function must be led by a full-time, qualified Saudi national.
IndependentCybersecurity is separate from IT, and reviews are independent of both.
Suppliers in scopeThird parties serving in-scope organisations must meet the controls too.
One of severalCloud, data and OT have their own NCA control sets on top.

Who must comply with NCA ECC?

Government bodies, critical national infrastructure, and the organisations that serve them.

Government organisationsMinistries, authorities and public bodies in the Kingdom.
Critical national infrastructureOperators in energy, finance, health, telecom and other vital sectors.
Private suppliersCompanies providing services to government or CNI organisations.
Cloud and hosting providersServing in-scope organisations, with extra cloud controls.
Organisations seeking alignmentOthers use ECC as a national baseline.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the controls require

What does NCA ECC require?

NCA ECC requires in-scope organisations to govern cybersecurity through an independent function and approved policies, defend their systems with technical controls, build cybersecurity into business continuity, and manage third-party and cloud risk.

1 Govern

Cybersecurity governance

10 subdomains: strategy, function, policies, risk, audit, HR, training.

In QULDEX: Governance evidence mapped
2 Defend

Cybersecurity defence

15 subdomains: access, systems, network, data, crypto, logs, incidents.

In QULDEX: Controls mapped to ISO 27001
3 Resilience

Resilience

Cybersecurity in business continuity.

In QULDEX: BCP evidence reused
4 Third parties

Third-party and cloud

Supplier and cloud hosting security.

In QULDEX: Vendor register
Audit Assure

Periodic review

Independent reviews and NCA assessments.

In QULDEX: Audit workspace
Subdomain explorer

Which NCA ECC subdomains matter most?

These 24 subdomains carry most of the work, grouped by ECC-2:2024 domain. Select any subdomain to see what it asks for, typical evidence and the matching ISO 27001 control.

2018ECC-1 issued
2024ECC-2 issued
4domains
108controls

Showing up to 6 per group. Search, filter, or open a group to see all 24.

Governance 10

  1. 1-1Cybersecurity strategy

    Define, document and approve a cybersecurity strategy aligned with the organisation's objectives and national requirements.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    Approved strategy
    Maps to
    ISO 27001 5.1

  2. 1-2Cybersecurity management

    Set up a cybersecurity function, independent from IT, led by a full-time, qualified Saudi national.

    In QULDEXThe function, its head and its reporting line are on record.

    Typical evidence
    Organisation chart, appointment
    Maps to
    ISO 27001 5.3

  3. 1-3Policies and procedures

    Document, approve and publish cybersecurity policies and procedures, and review them periodically.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    Approved policies
    Maps to
    ISO 27001 A.5.1

  4. 1-4Roles and responsibilities

    Define and approve cybersecurity roles and responsibilities across the organisation.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    RACI
    Maps to
    ISO 27001 A.5.2

  5. 1-5Risk management

    Assess and treat cybersecurity risks, including before new projects and major changes.

    In QULDEXThe risk register holds assessments and treatments.

    Typical evidence
    Risk register
    Maps to
    ISO 27001 6.1

  6. 1-6Cybersecurity in IT projects

    Include cybersecurity requirements in project and change management, including secure development.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    Project security reviews
    Maps to
    ISO 27001 A.5.8

  7. 1-7Compliance with laws and regulations

    Comply with national cybersecurity legislation and regulations.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    Compliance register
    Maps to
    ISO 27001 A.5.31

  8. 1-8Periodical review and audit

    Review the implementation of cybersecurity controls periodically, independently of the cybersecurity function.

    In QULDEXReviews run in the audit workspace with findings into CAPA.

    Typical evidence
    Review reports
    Maps to
    ISO 27001 9.2

  9. 1-9Cybersecurity in human resources

    Address cybersecurity before, during and after employment.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    Screening, NDAs
    Maps to
    ISO 27001 A.6.1–A.6.5

  10. 1-10Awareness and training

    Run awareness programmes and specialised training.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    Training records
    Maps to
    ISO 27001 A.6.3

Defence 11

  1. 2-1Asset management

    Keep an accurate, up-to-date inventory of information and technology assets.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    Asset inventory
    Maps to
    ISO 27001 A.5.9

  2. 2-2Identity and access management

    Control logical access with least privilege, MFA for remote and privileged access, and periodic reviews.

    In QULDEXAccess reviews run as recurring tasks.

    Typical evidence
    Access reviews
    Maps to
    ISO 27001 A.5.15–A.5.18

  3. 2-3Systems and processing facilities protection

    Protect systems and devices with malware protection, patching, hardening and secure configuration.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    Hardening baselines
    Maps to
    ISO 27001 A.8.7–A.8.9

  4. 2-5Network security management

    Segregate and protect networks, including internet browsing, wireless and DNS.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    Network diagrams
    Maps to
    ISO 27001 A.8.20–A.8.22

  5. 2-7Data and information protection

    Protect data according to its classification and applicable law.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    Classification policy
    Maps to
    ISO 27001 A.5.12

  6. 2-8Cryptography

    Use cryptographic solutions according to national cryptographic standards.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    Crypto standard
    Maps to
    ISO 27001 A.8.24

  7. 2-9Backup and recovery management

    Back up data and systems and test restoration periodically.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    Restore tests
    Maps to
    ISO 27001 A.8.13

  8. 2-10Vulnerability management

    Detect and remediate technical vulnerabilities on time.

    In QULDEXFindings become CAPA items with due dates.

    Typical evidence
    Scan reports
    Maps to
    ISO 27001 A.8.8

  9. 2-11Penetration testing

    Run penetration tests periodically on external services and critical systems.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    Pen test reports

  10. 2-12Event logs and monitoring

    Collect, analyse and monitor security event logs, with defined retention.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    SIEM evidence
    Maps to
    ISO 27001 A.8.15–A.8.16

  11. 2-13Incident and threat management

    Detect, respond to and report cybersecurity incidents, and use threat intelligence.

    In QULDEXIncidents run with timers and NCA reporting records.

    Typical evidence
    Incident reports
    Maps to
    ISO 27001 A.5.24–A.5.26

Resilience 1

  1. 3-1Resilience in business continuity

    Include cybersecurity in business continuity management and test it.

    In QULDEXContinuity evidence is reused from ISO 22301.

    Typical evidence
    BCP tests
    Maps to
    ISO 22301

Third party and cloud 2

  1. 4-1Third-party cybersecurity

    Address cybersecurity in contracts and relationships with third parties, including outsourcing.

    In QULDEXEach third party is assessed and linked to its services.

    Typical evidence
    Third-party assessments
    Maps to
    ISO 27001 A.5.19–A.5.22

  2. 4-2Cloud computing and hostingData residency

    Meet cybersecurity requirements for cloud and hosting, including hosting data in the Kingdom where required.

    In QULDEXQULDEX gives this subdomain an owner, evidence requests and a review date, and maps it to ISO 27001 so one programme serves both.

    Typical evidence
    Cloud assessments
    Maps to
    ISO 27017

Subdomain numbers follow ECC-2:2024. Summaries are QULDEX paraphrases; the NCA document is the authority.

Compliance path

How do you comply with NCA ECC?

Confirm you are in scope, set up an independent cybersecurity function, close the gaps against the 108 controls and evidence them for NCA. Most organisations need 6 to 12 months, less with ISO 27001 in place.

  1. Confirm scope

    Check whether you are a government body, CNI operator or a supplier to one.

  2. Set up the cybersecurity function

    Independent from IT, led by a qualified Saudi national, with an approved strategy.

    1–2 monthsRisk register →
  3. Gap assessment against ECC-2:2024

    Assess all 108 controls, reusing ISO 27001 evidence.

  4. Close the gaps

    Policies, technical controls, logging, testing and third-party clauses.

  5. Self-assessment and NCA review

    Submit the self-assessment and support NCA audits with evidence.

  6. Keep it current

    PeriodicIndependent review
    YearlyPolicy and risk review
    On changeRe-assess risk

Durations are QULDEX planning ranges.

Records to keep

Which documents does NCA ECC need?

Assessors ask for these records.

DocumentSubdomainWhere it lives in QULDEX
Cybersecurity strategy1-1Policy library
Function charter and head appointment1-2Policy library
Policies and procedures1-3Policy library
Risk assessments1-5Risk register
Periodic review reports1-8Audit workspace
Training records1-10Evidence vault
Asset inventory2-1Risk register
Access reviews2-2Evidence vault
Vulnerability and pen test reports2-10, 2-11CAPA automation
Incident reports2-13CAPA automation
Third-party and cloud assessments4-1, 4-2Vendor register

Subdomain numbers follow ECC-2:2024.

Time and cost

How long does NCA ECC take and what drives the effort?

Most organisations need 6 to 12 months. The cybersecurity function, logging and third-party contracts usually take longest.

Where the time goes

Scoping1–2 wk
Function and strategy1–2 mo
Gap assessment3–6 wk
Closing gaps3–8 mo
Review1–2 mo

Bars show the upper end of each range on one scale (12 months = full width).

What changes the effort

  • Existing ISO 27001: covers much of Domain 2
  • Saudization of leadership: the function head must be a Saudi national
  • Third parties: contracts need cybersecurity clauses
  • Cloud use: adds data residency and cloud controls
  • Other NCA sets: CCC, DCC or OTCC may apply too
Readiness check · 2 minutes

How ready are you for NCA ECC?

Check these eight things first. Nothing you enter leaves this page.

1-1Do you have an approved cybersecurity strategy?
1-2Is the cybersecurity function independent from IT and led by a qualified Saudi national?
1-5Are cybersecurity risks assessed and treated?
2-1Is your asset inventory complete and current?
2-2Is MFA in place for remote and privileged access?
2-12Are security logs collected and monitored?
2-13Can you detect, respond to and report incidents?
4-1Do third-party contracts include cybersecurity requirements?
Crosswalk

How NCA ECC maps to ISO 27001, SAMA CSF and the Saudi PDPL

ISO 27001 covers most ECC controls; SAMA CSF applies on top for financial institutions; the PDPL governs personal data. One control set can serve all of them.

Saudi crosswalk

NCA ECC-2:2024ISO 27001:2022SAMA CSFSaudi PDPLShared evidence
1-2 Function5.33.1.2 Organisation—Appointments
1-5 Risk management6.13.2.1Art. 19 securityRisk register
2-2 AccessA.5.15–A.5.183.3.5—Access reviews
2-7 Data protectionA.5.123.3.8Data handlingClassification
2-12 LogsA.8.153.3.14—Logs
2-13 IncidentsA.5.24–A.5.263.3.15Breach noticeIncident reports
4-1 Third partiesA.5.19–A.5.223.4Processor contractsVendor register

Indicative mapping for planning; SAMA CSF and PDPL references are approximate section labels. The full crosswalk is in the QULDEX control library.

Where QULDEX fits

How QULDEX runs NCA ECC from scoping to NCA review

QULDEX is NCA ECC compliance and audit management software built from EGV Group's audit delivery, used by in-scope organisations, their advisors and the auditors who review them. Pick your role to see who does what.

For government bodies, CNI operators and suppliers.

  1. ScopeConfirm scopeScope and status record
  2. GovernSet the functionStrategy and appointments recorded
  3. DefendClose control gaps108 controls mapped to evidence
  4. Third partiesAssess suppliersVendor register with clauses
  5. ReviewRun periodic reviewsReview schedule
  6. ReportAnswer NCAControlled evidence sharing
Without one systemWith QULDEX
ECC tracked in a spreadsheet per year108 controls with live evidence
Supplier clauses checked onceThird-party status tracked
ISO 27001 and ECC run separatelyOne control set mapped to both
Reviews arranged ad hocA periodic review schedule
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

NCA ECC questions people ask

What is NCA ECC?

The Essential Cybersecurity Controls issued by Saudi Arabia's National Cybersecurity Authority. The current edition, ECC-2:2024, sets 108 controls in 4 domains for government organisations, critical national infrastructure and their suppliers.

What changed in ECC-2:2024?

The 2024 edition reorganises the controls into 4 domains, 28 subdomains and 108 controls with 92 subcontrols, and updates requirements on areas such as third-party and cloud security. Industrial control systems are covered by the separate OTCC.

Who must comply with NCA ECC?

Government organisations, critical national infrastructure operators, and private companies that own, operate or host critical systems or provide services to them.

Does ISO 27001 certification cover NCA ECC?

Much of it, but ECC adds Saudi-specific requirements, such as a cybersecurity function led by a qualified Saudi national and national cryptography and data hosting rules.

How does NCA ECC relate to SAMA CSF?

Financial institutions regulated by SAMA follow the SAMA Cyber Security Framework; where they are also in NCA scope, both apply and most evidence overlaps.

Sources

References

  1. National Cybersecurity Authority, Essential Cybersecurity Controls ECC-2:2024. nca.gov.sa
  2. NCA, Essential Cybersecurity Controls ECC-1:2018 (superseded). nca.gov.sa
  3. NCA Cloud Cybersecurity Controls (CCC) and Data Cybersecurity Controls (DCC). nca.gov.sa
  4. ISO/IEC 27001:2022. iso.org

Reviewed by

Ankit Tiwari

Framework reviewer · QULDEX

Reviewed this page against NCA ECC-2:2024: domains, subdomains and who must comply.

Page history
  • : Page first built on ECC-2:2024: subdomain explorer, readiness check and Saudi crosswalk

Find your NCA ECC gaps before the next review

Answer a short readiness check and get a gap summary by domain. No sales call needed to see the result.

Schedule
Book a Demo