NCA CSCC Compliance Checklist (Free Template)
A free NCA CSCC compliance checklist — the seven criticality criteria, all 21 subdomains, and the review, patching and testing cadences inspectors ask for.
CSCC compliance has two halves, and most programmes underestimate the first. Implementing 32 controls across 21 subdomains is the visible work. Deciding which systems are critical is the step that determines everything else — and it is the first thing an NCA assessment asks about.
This is the structured NCA CSCC compliance checklist. It starts with the identification exercise, then works through the four domains, and ends with the recurring cadences that catch programmes out. A downloadable working copy is available at the end.
Section 0 — Critical systems identification
Do this as a scored, documented assessment with the seven criteria as explicit columns. "We discussed it and agreed on these five" is a materially weaker answer than a scored assessment showing why each system did or did not qualify.
A system is a candidate if its compromise would cause:
| # | Criterion |
|---|---|
| 1 | Negative impact on national security |
| 2 | Negative impact on the Kingdom's reputation and public image |
| 3 | Significant financial losses — more than 0.01% of GDP |
| 4 | Impact on services to more than 5% of the population |
| 5 | Loss of lives |
| 6 | Unauthorised disclosure of data classified Top Secret or Secret |
| 7 | Impact on the operations of one or more vital sectors |
0.1 Every candidate system scored against all seven criteria, with reasoning recorded for inclusions and exclusions.
0.2 Each identified system expanded to its ten components — network (routers, switches, gateways, firewalls, IDS/IPS, APT protection), databases, storage, middleware, servers and operating systems, applications, encryption devices, peripherals including printers and scanners, the people in supporting roles, and the documentation covering all of it.
0.3 ECC baseline confirmed on those systems. Continuous ECC-2:2024 compliance is a prerequisite for CSCC compliance.
How to use this checklist
- Mark the current state — compliant, partially compliant, or non-compliant.
- Record which critical system the line applies to; CSCC is assessed per system, not per organisation.
- Note the evidence reference and the assessment date.
- Identify the gap and the action required.
Domain 1 — Cybersecurity Governance
1-1 Cybersecurity strategy. The organisation's cybersecurity strategy explicitly prioritises protection of critical systems.
1-2 Cybersecurity risk management. Risk assessment on critical systems at least annually; a critical-systems risk register reviewed at least monthly.
1-3 Cybersecurity in IT project management. Source code access, storage and release secured; authenticated APIs secured; secure, trusted migration from test to production with test data, IDs and passwords removed beforehand.
1-4 Periodical cybersecurity review and audit. CSCC implementation reviewed by the cybersecurity function at least annually, and by independent parties outside that function at least every three years.
1-5 Cybersecurity in human resources. Screening or vetting of candidates working on critical systems. Technical support and development positions filled with experienced Saudi professionals.
Domain 2 — Cybersecurity Defence
2-1 Asset management. Critical systems asset inventory updated at least annually, with owners identified and involved in the lifecycle.
2-2 Identity and access management. The subdomain with the most operating-model impact:
- Remote access from outside the Kingdom is prohibited.
- Remote access from inside the Kingdom restricted, each attempt verified by the SOC, activity continuously monitored.
- MFA for all users, and again for privileged users and the systems used to manage critical systems.
- High-standard password policy; secure storage and processing using hashing.
- Service accounts securely managed with interactive login disabled.
- Direct database access prohibited for all users except DBAs — everyone else reaches data through applications, with solutions limiting visibility of classified data even to administrators.
- Access reviewed at least every three months.
2-3 Information system and processing facilities protection. Security patches applied at least monthly for external and internet-connected critical systems, and at least every three months otherwise.
2-4 Networks security management. Firewall rules and access lists reviewed at least every six months.
2-5 Mobile devices security. Controls for devices used with critical systems.
2-6 Data and information protection. Protection aligned to classification.
2-7 Cryptography. Aligned to the National Cryptographic Standards.
2-8 Backup and recovery management. Recovery testing at least every three months to confirm critical systems can be restored.
2-9 Vulnerabilities management. Vulnerability scanning of technical components at least monthly.
2-10 Penetration testing. Penetration tests at least every six months, scope covering all technical components of the critical systems, conducted by a qualified team.
2-11 Cybersecurity event logs and monitoring management. Logging and monitoring across every critical-system component.
2-12 Web application security and 2-13 Application security. Secure standards and testing before production.
Domain 3 — Cybersecurity Resilience
3-1 Cybersecurity resilience aspects of BCM. Critical systems covered explicitly in continuity planning and testing.
Domain 4 — Third-Party and Cloud Computing Cybersecurity
4-1 Third-party cybersecurity. Screening or vetting of outsourcing and managed-service companies and their personnel working on critical systems. Outsourcing and managed services for critical systems must rely on Saudi companies and organisations, in line with relevant legislative and regulatory requirements.
4-2 Cloud computing and hosting cybersecurity. Hosting of critical systems and any part of their technical components must be inside the organisation, or within cloud services provided by government organisations or Saudi companies compliant with the NCA CCC — taking the classification of the hosted data into account.
The cadence calendar
Put these in a calendar with named owners. They are the items an assessment tests as operating, not merely documented.
| Frequency | Activity |
|---|---|
| Monthly | Risk register review · patching of external and internet-connected systems · vulnerability scanning |
| Quarterly | Access review · recovery testing · patching of internal systems |
| Half-yearly | Penetration testing · firewall rule and access list review |
| Annually | Risk assessment · asset inventory update · CSCC implementation review by the cybersecurity function |
| Every 3 years | Independent review by parties outside the cybersecurity function |
Six-monthly penetration testing across every technical component of every critical system is the line that most often forces a change in testing budget and vendor arrangements. Plan it early.
Get the downloadable checklist
The full checklist — a working spreadsheet with the seven identification criteria as a scoring sheet, the component expansion per system, and state, owner, evidence and target date columns — is available on request. Contact us to receive a copy.
For the framework in depth, read NCA CSCC: Critical Systems Cybersecurity Controls. For the wider family, see the NCA frameworks complete list, and for the baseline the NCA ECC 2:2024 checklist.
Book a demo with the GRC Vantage team in Riyadh or Dammam.
See Compliance Management →
The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.
Related articles
A guide to NCA Critical Systems Cybersecurity Controls (CSCC) — the seven identification criteria, 32 controls, and the in-Kingdom access and hosting rules.
A free NCA CCC-2:2024 compliance checklist — the provider and tenant control sets, all four classification levels, and the evidence each subdomain needs.
A guide to NCA Cloud Cybersecurity Controls (CCC-2:2024) — the CSP and CST control sets, four classification levels, and the data localisation change.