NCA ECC 2:2024 Compliance Checklist (Free Template)

A free NCA ECC-2:2024 compliance checklist — every domain, control and evidence requirement Saudi government and CNI operators need, free to download.

GRC Vantage TeamGRC Vantage Team2026-04-089 min read

The National Cybersecurity Authority Essential Cybersecurity Controls — currently ECC – 2: 2024 — is the baseline cybersecurity standard every Saudi government entity and critical national infrastructure (CNI) operator is measured against. Unlike SAMA CSF, which is principle-led and maturity-scored, NCA ECC is closer to a structured compliance check: each sub-control either operates with evidence or it does not. That makes a clean checklist particularly useful — the question is binary, and the team needs an organised way to answer it.

This post is the structured NCA ECC compliance checklist, organised by the framework's four domains as they stand in ECC-2:2024. A downloadable working copy is available at the end.

How to use this checklist

For each line item:

  1. Mark the current state — compliant, partially compliant, or non-compliant.
  2. Identify the owner (named individual, not a function).
  3. Note the evidence reference.
  4. Record the date the assessment was made.
  5. Identify the gap and the action required to close it.

The NCA assessment process collects evidence against each sub-control. A working checklist updated in real time produces the submission almost as a by-product; one filled in retrospectively is the source of most submission delays.

Domain 1 — Cybersecurity Governance

The Governance domain establishes the management foundation.

1-1 Cybersecurity strategy. Documented cybersecurity strategy approved at the highest level (typically the CEO or equivalent), aligned to the organisation's overall strategy and to national cybersecurity priorities.

1-2 Cybersecurity management. Defined cybersecurity function with named leadership reporting independently of the IT function. Documented roles and responsibilities. Resourcing appropriate to risk. ECC-2:2024 change: control 1-2-2 now requires all cybersecurity positions to be filled with full-time and qualified Saudi cybersecurity professionals — widened from the head of function and related supervisory and critical positions.

1-3 Cybersecurity policies and procedures. Documented cybersecurity policy approved at appropriate level, communicated to all relevant staff, supported by sub-policies. Defined review cadence (annual minimum).

1-4 Cybersecurity roles and responsibilities. Documented roles and responsibilities for cybersecurity. Job descriptions reflect the responsibilities.

1-5 Cybersecurity risk management. Documented risk management approach covering identification, analysis, evaluation and treatment. Risk register maintained.

1-6 Cybersecurity in IT projects. Documented requirement to consider cybersecurity in IT projects from the design phase.

1-7 Compliance with cybersecurity standards, laws and regulations. Documented identification of applicable requirements and tracking of compliance. ECC-2:2024 change: the generic control requiring compliance with national cybersecurity laws (1-7-1) was deleted, and 1-7-2 became conditional — where nationally approved international agreements or commitments include cybersecurity requirements, the entity must identify and comply with them.

1-8 Periodic cybersecurity review and audit. Documented internal audit programme covering cybersecurity. Findings tracked to closure.

1-9 Cybersecurity in human resources. Cybersecurity considerations in joiners-movers-leavers. Background screening commensurate with role. Acceptable use agreements.

1-10 Cybersecurity awareness and training. Documented awareness programme with role-based training, completion tracking and refresher cadence.

Domain 2 — Cybersecurity Defence

This is the largest domain by control count and covers the day-to-day technical controls.

Asset management (2-1)

Asset inventory covering hardware, software, systems and data. Owners assigned. Classification applied. Updated as assets change. Secure disposal of media at end of life.

Identity and access management (2-2)

User access management lifecycle (joiners-movers-leavers) with documented SLAs. Privileged access management with least privilege, time-bounded sessions where appropriate, monitoring of privileged actions. Periodic access review (typically quarterly for privileged, annually for general).

ECC-2:2024 change: authentication is now risk-driven rather than prescriptive. Subcontrol 2-2-3-1 covers single-factor authentication by username and password; 2-2-3-2 requires multi-factor authentication and the definition of suitable authentication factors, their number and the techniques used — based on an impact assessment of authentication failure and bypass for remote access and privileged accounts. Evidence now includes that impact assessment, not just the MFA configuration.

Information system and information processing facilities protection (2-3)

System hardening to documented standards. Anti-malware controls in place. Patch management with documented SLAs by criticality. Configuration management.

Email protection (2-4)

Email gateway protections in place — anti-spam, anti-phishing, attachment scanning, link inspection. SPF, DKIM and DMARC all configured — subcontrol 2-4-3-5 was tightened in ECC-2:2024 from "e.g. using SPF" to naming all three explicitly. User reporting mechanism for suspected phishing. Remote and webmail access carries the same impact-assessment-driven authentication requirement as 2-2-3-2 (subcontrol 2-4-3-2).

Networks security management (2-5)

Documented network architecture with appropriate segmentation between corporate, production, management and (where applicable) industrial networks. Firewall rule reviews. Wireless network security. Remote access security (VPN with MFA, defined access controls, session monitoring). New in ECC-2:2024: subcontrol 2-5-3-9 requires protection against Distributed Denial of Service (DDoS) attacks to limit the risks arising from them.

Mobile devices security (2-6)

Mobile device management for organisation-owned devices. Defined controls for personal devices accessing corporate data (BYOD policy where applicable). Encryption at rest. Remote wipe capability.

Data and information protection (2-7)

Data classification scheme. Controls implemented based on the data's classification level — control 2-7-2 was reworded to make classification the driver. Data loss prevention controls where appropriate. Encryption of sensitive data at rest and in transit.

ECC-2:2024 change: control 2-7-3 — data and information ownership, classification and labelling mechanisms, and data privacy — was deleted from the ECC and transferred to the National Data Management Office (NDMO) at SDAIA. Those obligations still exist; they are simply no longer assessed as ECC controls. Refer to the NDMO before acting.

Cryptography (2-8)

Cryptographic requirements must now include those set out in the National Cryptographic Standards (NCS) published by the NCA — control 2-8-3 was rewritten in ECC-2:2024 to point at them directly. The appropriate strength level (MODERATE or ADVANCED) must be selected on the nature and sensitivity of the data, systems and networks being protected and the entity's risk assessment. Approved cryptographic systems and their technical and regulatory restrictions, secure key management across the lifecycle, and encryption of data in transit and at rest per classification. Key inventory maintained.

Backup and recovery management (2-9)

Documented backup approach for critical data. Regular backup execution. Off-site backup retention. Periodic restoration testing. RPO defined per system criticality.

Vulnerabilities management (2-10)

Vulnerability scanning on defined cadence. Documented patch SLAs by vulnerability criticality (typically 24h for critical, 7d for high, 30d for medium). Evidence of compliance with SLAs.

Penetration testing (2-11)

External penetration testing on defined cadence. Findings tracked to closure with documented remediation evidence.

Cybersecurity event logs and monitoring management (2-12)

Centralised log collection from in-scope systems. Defined retention period (typically 12 months minimum). Integrity protection on logs. Security monitoring with defined use cases. SIEM in place. Documented alert response SLAs.

Note for NCA-obligated entities: the National Policy for Managed Security Operations Centers requires government entities and CNI operators to carry out their SOC work through a Tier 1 licensed MSOC provider, and to report their current SOC status and a corrective plan to the NCA. If you are satisfying 2-12 with an in-house SOC, that arrangement itself now needs reviewing.

Cybersecurity incident and threat management (2-13)

Documented incident response plan with severity classification, escalation paths and runbooks. Incident detection capability. Notification process to NCA and other relevant authorities. Post-incident review.

Physical security (2-14)

Physical security controls for facilities housing in-scope systems. Access control to data centres and equipment rooms. Environmental controls. CCTV and monitoring.

Web application security (2-15)

Documented secure web application standards. OWASP Top 10 considered. Web application firewall where appropriate. Security testing before production deployment. ECC-2:2024 change: subcontrol 2-15-3-5 moved from "multi-factor authentication for users' access" to defining user authentication factors, their number and techniques based on an impact assessment of authentication failure and bypass.

Domain 3 — Cybersecurity Resilience

NCA ECC folds cybersecurity resilience directly into the core framework, unlike many international standards.

3-1 Cybersecurity in business continuity management. Cybersecurity requirements embedded in the BCM lifecycle. Cyber scenarios considered in business impact analysis. Recovery plans cover cyber scenarios. Exercises include cyber scenarios.

Domain 4 — Third-Party and Cloud Computing Cybersecurity

4-1 Third-party cybersecurity. Documented third-party cybersecurity programme. Due diligence at onboarding. Contractual cybersecurity requirements. Ongoing monitoring. Termination controls.

4-2 Cloud computing and hosting cybersecurity. Cybersecurity requirements applied to cloud arrangements. For in-scope entities using cloud, the NCA Cloud Cybersecurity Controls (CCC) apply in addition to ECC and impose more detailed requirements.

ECC-2:2024 changes in this subdomain:

  • Subcontrol 4-2-3-1 was rewritten from "classification of data prior to hosting" to protection of the entity's data by cloud and hosting providers in accordance with its classification level, plus return of data in a usable format on service completion.
  • Subcontrol 4-2-3-3 — "entity's information hosting and storage must be inside the Kingdom of Saudi Arabia" — was deleted, with data localisation transferred to the National Data Management Office (NDMO) at SDAIA. Localisation may still be required; it is no longer required by the ECC. Note that CSCC subcontrol 4-2-1-1 still imposes in-Kingdom hosting for critical systems.
  • The subdomain 4-1 objective and control 4-1-3 were reworded to name IT outsourcing, cybersecurity outsourcing and managed services explicitly.

Domain 5 no longer exists

ECC-1:2018 had a fifth main domain, Industrial Control Systems Cybersecurity, for entities operating ICS — utilities, energy, manufacturing, certain transport operators. ECC-2:2024 deleted it, and the NCA moved its controls into the Operational Technology Cybersecurity Controls (OTCC).

If you operate OT, remove domain 5 from your ECC checklist and open a separate OTCC assessment. That is a larger exercise, not a smaller one: the OTCC has 4 domains, 23 subdomains, 47 main controls and 122 subcontrols, tiered across three facility levels — 56 controls at Level 3, 117 at Level 2 and 151 at Level 1 — with a Facility Level Identification Tool used to assign the level.

Frameworks that often apply alongside ECC

Many in-scope entities are subject to additional NCA frameworks based on the data they handle and the systems they operate:

  • CSCC — Critical Systems Cybersecurity Controls, for systems classified as critical national systems.
  • CCC — Cloud Cybersecurity Controls, for cloud arrangements.
  • OTCC — Operational Technology Cybersecurity Controls, for OT/ICS estates — now carrying the controls formerly in ECC domain 5.
  • DCC — Data Cybersecurity Controls.
  • TCC — Telework Cybersecurity Controls.
  • OSMACC — Organizations' Social Media Accounts Cybersecurity Controls.
  • NFCRM — the National Framework for Cybersecurity Risk Management, which now supplies the mandatory risk methodology and matrix behind ECC subdomain 1-5.

A complete compliance posture for a Saudi government entity or CNI operator usually includes ECC plus one or more of these supplementary frameworks. The checklist below covers ECC as the baseline; the supplementary frameworks are documented separately.

Get the downloadable checklist

The full checklist — formatted as a working spreadsheet with state, owner, evidence reference and target date columns — is available on request. Contact us to receive a copy.

For the wider regulatory context, read our NCA frameworks guide and our deep-dive NCA ECC compliance guide, which sets out the full list of ECC-2:2024 changes. The NCA also publishes an ECC-2:2024 Assessment and Compliance Tool and around 90 free policy and standard templates in its Cybersecurity Toolkits. To see the same checklist running as a live, audit-trailed control library inside a unified GRC platform — with evidence collected once and presented in NCA submission format — read about GRC Vantage's compliance module, supported from our offices in Riyadh and Dammam.

GRC Vantage Team
GRC Vantage Team
Saudi GRC Practitioners

The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.