NCA ECC 2:2024: Compliance Guide for Saudi Entities

A practitioner's guide to the NCA Essential Cybersecurity Controls (ECC-2:2024) — scope, the four domains, what changed from ECC-1:2018, and assessment.

GRC Vantage TeamGRC Vantage Team2026-04-0811 min read

The National Cybersecurity Authority Essential Cybersecurity Controls — NCA ECC — is the baseline cybersecurity standard every Saudi government entity and critical national infrastructure (CNI) operator is measured against. Where SAMA CSF governs the financial sector, NCA ECC governs everything else that the Kingdom considers sensitive: ministries, public authorities, state-owned enterprises, telecommunications operators, energy and water utilities, transportation, healthcare systems and the private-sector CNI that underpins national services.

This guide is a practitioner walkthrough of what ECC requires, who has to comply, and what a credible compliance programme looks like in 2026 — against the current version, ECC – 2: 2024.

What the NCA ECC is

The National Cybersecurity Authority was established by Royal Order No. 6801 dated 11/02/1439H and, in 2018, published the Essential Cybersecurity Controls as ECC-1:2018. The current version is ECC – 2: 2024. ECC is deliberately called a baseline — it is the minimum cybersecurity posture the NCA expects from any in-scope entity, and sits under a wider NCA framework family that includes the Critical Systems Cybersecurity Controls (CSCC), Cloud Cybersecurity Controls (CCC), Operational Technology Cybersecurity Controls (OTCC), Data Cybersecurity Controls (DCC), Telework Cybersecurity Controls (TCC) and the National Framework for Cybersecurity Risk Management (NFCRM).

ECC-2:2024 is organised into four main domains:

  1. Cybersecurity Governance — strategy, management, policies, roles, risk management, cybersecurity in IT project management, compliance, periodical review and audit, human resources, awareness and training (subdomains 1-1 to 1-10).
  2. Cybersecurity Defence — asset management, identity and access, system and facilities protection, email protection, network security, mobile devices, data and information protection, cryptography, backup and recovery, vulnerability management, penetration testing, logging and monitoring, incident and threat management, physical security and web application security (subdomains 2-1 to 2-15).
  3. Cybersecurity Resilience — cybersecurity resilience aspects of business continuity management (subdomain 3-1).
  4. Third-Party and Cloud Computing Cybersecurity — cyber requirements flowing to suppliers, and to cloud and hosting providers (subdomains 4-1 and 4-2).
ComponentECC-1:2018ECC-2:2024
Main domains54
Subdomains2928
Main controls114108
Subcontrols20192

Each control is a cybersecurity outcome the NCA expects, and each in-scope entity must evidence implementation of every control applicable to it.

What changed in ECC-2:2024

Appendix C of the document lists the changes. The ones that alter a compliance programme:

ChangeRefWhat it means
Main domain 5 deletedDomain 5Industrial Control Systems Cybersecurity is removed from the ECC entirely. Its controls moved to the OTCC. OT-operating entities do not have less to do — the obligation moved to a deeper, level-tiered control set.
Saudisation widened1-2-2Was: the head of the cybersecurity function and related supervisory and critical positions must be full-time, experienced Saudi professionals. Now: all cybersecurity positions shall be filled with full-time and qualified Saudi cybersecurity professionals.
Scope clarifiedScope of WorkGovernment agencies now explicitly include their affiliated companies and entities, inside and outside the Kingdom.
In-Kingdom hosting subcontrol deleted4-2-3-3The requirement that information hosting and storage be inside the Kingdom was removed from the ECC and transferred to the National Data Management Office (NDMO) at SDAIA. Entities must refer to the NDMO on localisation before acting.
Data governance controls deleted2-7-3Data ownership, classification and labelling mechanisms, and data privacy moved to the NDMO. Control 2-7-2 was reworded so data protection requirements are implemented based on classification level.
Cryptography now points at the NCS2-8-3Cryptography requirements must include those in the National Cryptographic Standards, with the appropriate strength level chosen on data sensitivity and the entity's risk assessment.
DDoS protection added2-5-3-9A new subcontrol requiring protection against Distributed Denial of Service attacks.
Email authentication tightened2-4-3-5Domain validation was "e.g. using SPF"; it is now SPF, DKIM and DMARC explicitly.
Authentication becomes risk-driven2-2-3-2 · 2-4-3-2 · 2-15-3-5"MFA for remote access" is replaced by a requirement to define the authentication factors, their number and the techniques based on an impact assessment of authentication failure and bypass — for remote access, privileged accounts, webmail and web application users.
Compliance controls trimmed1-7-1 · 1-7-2The generic "comply with national cybersecurity laws" control was deleted, and the international-agreements control became conditional on such agreements existing.

Two of the deletions look like relief and are not. Removing the in-Kingdom hosting subcontrol and the data governance controls did not remove the obligations — it moved them to SDAIA's National Data Management Office, which the ECC now tells you to consult before acting.

The authentication change is the one most likely to create a finding. ECC-1 asked for MFA on remote access; ECC-2 asks you to justify your authentication design with an impact assessment of what happens when authentication fails or is bypassed. Turning MFA on is no longer sufficient evidence — the assessment behind the choice is now part of the control.

Scope: who has to comply

ECC applies in three tiers. The first is all government entities in Saudi Arabia — every ministry, public authority, commission, bureau and agency. The second is private-sector organisations that operate critical national infrastructure — telecoms, energy, water, healthcare systems, transport, banking infrastructure, and organisations that process sensitive national data. The third is entities that hold, process or exchange national-level sensitive information regardless of sector.

The practical rule of thumb is: if an NCA compliance letter arrives, you are in scope. In-scope private-sector organisations are often surprised at how broadly "critical infrastructure" is interpreted by the NCA, and the cost of under-scoping is a finding at first assessment.

How NCA ECC differs from SAMA CSF

The two most important Saudi cybersecurity frameworks serve different audiences and behave differently in practice.

SAMA CSF is principle-led, maturity-scored, and sector-specific to the Saudi Central Bank's supervised population. It expects year-on-year improvement against a five-level maturity model and treats governance and third-party depth as distinct domains.

NCA ECC is more prescriptive and control-oriented. Each subcontrol is a stated expectation, and the assessment is primarily about whether the control exists and operates — with evidence. The NCA assesses entities through a combination of self-assessment, submission of evidence, and targeted on-site checks.

In short: CSF asks "how mature is your programme?"; ECC asks "do you have these controls operating, and can you prove it?" Both are compatible with a single unified control library, but teams running both frameworks simultaneously need to understand that the evidence format and the assessment cadence differ.

The four domains in practical terms

Cybersecurity Governance (domain 1). ECC expects a documented cybersecurity strategy approved at the highest level, a defined organisational structure with a dedicated cybersecurity function, a risk management approach, policies that are reviewed and approved on a cadence, and internal audit of the cybersecurity programme. The governance domain also includes cyber awareness and training expectations that go beyond a single annual e-learning module.

Cybersecurity Defence (domain 2). With 15 of the 28 subdomains, this is by far the largest domain and covers the day-to-day technical controls: asset and inventory management, identity and access management, privileged access, network security, system hardening, email and browsing security, encryption, backup, vulnerability management, penetration testing and continuous logging and monitoring. A credible ECC programme needs evidence that these controls are not just implemented but operating — patch compliance metrics, penetration test reports with remediation tracking, vulnerability scan results with SLAs, and so on.

Cybersecurity Resilience (domain 3). Where SAMA CSF treats business continuity as adjacent, NCA ECC folds cybersecurity resilience directly into the core framework. Entities must show that cybersecurity requirements are embedded in the BCM lifecycle, that cyber events are considered in business impact analysis, and that recovery plans cover cyber scenarios.

Third-Party and Cloud Cybersecurity (domain 4). ECC expects a formal third-party cybersecurity programme: due diligence before onboarding, contractual cybersecurity requirements, ongoing monitoring and termination controls. Cloud arrangements carry their own expectations, and for in-scope entities the Cloud Cybersecurity Controls (CCC) apply in addition to ECC when cloud is used.

What happened to domain 5

ECC-1:2018 carried a fifth domain, Industrial Control Systems Cybersecurity, applying to entities operating ICS — utilities, energy, manufacturing, certain transport operators. ECC-2:2024 deleted it, and the NCA's stated rationale is that the controls moved to the Operational Technology Cybersecurity Controls (OTCC).

For an OT-operating entity this is an increase, not a reduction. Domain 5 was a single subdomain of high-level expectations; the OTCC is 4 domains, 23 subdomains, 47 main controls and 122 subcontrols, tiered across three facility levels, with its own assessment tool and a separate Facility Level Identification Tool. Anything that used to be evidenced against ECC domain 5 now needs evidencing against a much deeper control set — and the level assigned to each critical facility determines whether that means 56, 117 or 151 controls.

How the NCA assesses compliance

The NCA evaluates compliance through self-assessment by the entity, periodic reports from the compliance tool, and/or field auditing visits, by whichever mechanism it considers appropriate. It issues an ECC-2:2024 Assessment and Compliance Tool to organise the exercise. Entities are expected to submit evidence against each applicable ECC control, and the NCA has a well-defined process for rating each control as compliant, partially compliant or non-compliant. Non-compliance carries remediation obligations with defined deadlines, and persistent non-compliance can escalate to formal enforcement.

Two things make the assessment experience much better: first, having evidence organised against control IDs before the NCA asks, not after; second, having a unified view of governance, technical and third-party controls so that evidence can be produced without a scramble across seven different teams.

A practical 2026 readiness roadmap

Phase 0 — confirm your version. If your control library was built before 2025, it is almost certainly ECC-1:2018. Re-baseline onto ECC-2:2024 first: retire domain 5, add the new DDoS subcontrol, rewrite the authentication controls around impact assessment, and re-point cryptography at the National Cryptographic Standards.

Phase 1 — scoping and gap. Confirm which NCA frameworks apply — ECC always, plus CSCC/CCC/OTCC/DCC/TCC/OSMACC where relevant, and the NFCRM methodology for the risk register. Run a structured gap assessment against every applicable control.

Phase 2 — governance uplift. Approve the cybersecurity strategy at the highest level, formalise the cybersecurity organisation, write or refresh the policy stack, and make sure internal audit has a cybersecurity audit plan.

Phase 3 — technical depth. Close the defence-domain gaps that matter most to operational resilience: identity and privileged access, vulnerability management, logging and monitoring, backup and recovery.

Phase 4 — third-party and cloud. Build the vendor lifecycle, apply ECC-derived contract clauses to new and renewed contracts, and — if cloud is in use — assess against CCC. Resolve data localisation with the NDMO separately, since it is no longer an ECC control.

Phase 5 — evidence and submission. Collect evidence against every control in a single platform, using the ECC-2:2024 Assessment and Compliance Tool the NCA issues to structure the measurement, so that the submission is produced from live data rather than a manual scramble.

Government entities that run this programme on a connected platform typically reach a defensible ECC position in six to nine months from baseline. Entities running it on document libraries and spreadsheets routinely take twice as long.

How GRC Vantage helps with NCA ECC

GRC Vantage's compliance module ships with the full ECC-2:2024 control library — all 108 main controls and 92 subcontrols across the four domains, pre-mapped to SAMA CSF, ISO 27001 and NIST CSF so that evidence is captured once and presented in the format each audience expects. The platform supports the NCA evidence-submission workflow, runs the gap assessment, manages the third-party lifecycle against ECC-tagged controls, and — critically — can be deployed inside Saudi Arabia on sovereign infrastructure to satisfy data residency expectations. Our delivery teams are based in Riyadh and Dammam and routinely work with Saudi government entities and CNI operators running their first NCA submission.

For the full picture of the NCA framework family — ECC, CSCC, CCC, OTCC, DCC and TCC — read our pillar guide on NCA frameworks, and see the ECC checklist for a working line-by-line template. If you are preparing for your next NCA assessment, book a demo and we will walk through how Saudi organisations use GRC Vantage to run a unified NCA compliance programme.


Sources & References
Primary regulatory documents, international standards and guidance cited in this article
  • 1
    Primary Regulation — NCA
    National Cybersecurity Authority (NCA), Kingdom of Saudi Arabia, 2024
    Source for the current structure (4 main domains, 28 subdomains, 108 main controls, 92 subcontrols), the scope of work, the assessment and compliance mechanism, and the Appendix C list of updates against ECC-1:2018 — including the deletion of main domain 5, control 1-2-2 on Saudi cybersecurity professionals, the deletion of subcontrol 4-2-3-3 and control 2-7-3, the new DDoS subcontrol 2-5-3-9, and the revised authentication and cryptography controls.
  • 2
    Primary Regulation — NCA
    National Cybersecurity Authority (NCA), 2025
    Hosts ECC-2:2024 and the Guide to Essential Cybersecurity Controls (ECC) Implementation. Published 31/07/2025.
  • 3
    Primary Regulation — NCA
    National Cybersecurity Authority (NCA), 2022
    The control set that ECC-2:2024's deleted main domain 5 was moved into — 4 domains, 23 subdomains, 47 main controls and 122 subcontrols across three facility levels.
  • 4
    Primary Regulation — SDAIA
    SDAIA, 2024
    The authority to which ECC-2:2024 transferred data localisation (subcontrol 4-2-3-3) and the data governance controls previously in 2-7-3.
GRC Vantage Team
GRC Vantage Team
Saudi GRC Practitioners

The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.