NCA OTCC: OT and ICS Cybersecurity Controls Guide

A guide to NCA Operational Technology Cybersecurity Controls (OTCC) — the three facility levels, 122 subcontrols, and the OT zone and remote access rules.

GRC Vantage TeamGRC Vantage Team2026-08-2611 min read

The Operational Technology Cybersecurity Controls (OTCC – 1: 2022) are the NCA's control set for Industrial Control Systems, and they are the most operationally opinionated document the Authority publishes. Where the ECC tells you to segment networks, the OTCC tells you to put a hardened jump host in a DMZ, proxy machine-to-machine traffic, and prevent direct corporate-to-OT communication altogether.

They are also the only NCA control set that contains an explicit safety escape hatch — and understanding why it is there is the key to implementing them sensibly.

What the OTCC is

The OTCC is an extension to the ECC, developed after a study of national and international cybersecurity frameworks and a review of international OT/ICS guidance and standards. The NCA defines Industrial Control Systems broadly: all devices, systems or networks used to operate and/or automate industrial processes.

ComponentCount
Main domains4
Subdomains23
Main controls47
Subcontrols122

Compliance is mandated under item 3 of Article 10 of the NCA's mandate and Royal Decree No. 57231 dated 10/11/1439H, and ECC compliance is a mandatory prerequisite. The document addresses four pillars — Strategy, People, Process and Technology.

Who is in scope

The OTCC applies to Industrial Control Systems that reside in facilities deemed critical, owned and/or operated by:

  • Government organisations — ministries, authorities, establishments and others
  • Private sector organisations owning, operating or hosting Critical National Infrastructure (CNI)

— whether in the Kingdom or abroad. The NCA strongly encourages all other organisations to leverage the controls voluntarily.

Note the scope test carefully: it is the facility that is assessed for criticality, not the system. The NCA defines a critical facility as one whose destruction and/or dysfunction may lead to the disruption or discontinuity of the organisation's operation — an organisation-level test, distinct from the national-impact tests used in the CSCC.

The three levels

Unlike the ECC, the OTCC does not apply uniformly. Controls are tiered across three levels assigned to each critical facility, based on three criteria: criticality and consequence for the organisation's business and service availability; negative impact on Health, Safety and Environment (HSE); and negative impact on national economy, national security or social influence.

LevelFacility criticalityControls and subcontrols
L1High — severe or catastrophic effects on operations, assets, resources or HSE.151 (includes all L2 and L3 controls)
L2Moderate — significant effects on operations, assets, resources or HSE.117 (includes all L3 controls)
L3Low — moderate adverse effects on operations, assets, resources or HSE.56

The levels are cumulative: L1 is a superset of L2, which is a superset of L3. Moving a facility from L3 to L1 nearly triples the applicable control count.

The NCA publishes two tools for this. The OTCC-1:2022 Facility Level Identification Tool structures the process of assigning a level to each critical facility, and the OTCC-1:2022 Assessment and Compliance Tool structures the measurement of compliance against the assigned level. Level assignment is a formal exercise with its own instrument, not an internal judgement call.

The safety carve-out

The OTCC's Statement of Applicability contains a clause with no equivalent in the NCA's IT-facing control sets. Every in-scope organisation must comply with all applicable controls —

after ensuring that applying applicable controls will not jeopardize the continuity of the organization's operation.

This is the OTCC acknowledging the central fact of OT security: a control that trips a process, delays a safety function or forces an unplanned shutdown has not made the plant safer. Availability and safety are the primary objectives; the controls serve them.

That clause is not a compliance exit. It is an instruction to sequence and test control changes against operational reality — and to document the assessment when a control cannot be applied as written. An organisation that invokes it without an engineering rationale, a risk assessment on the NFCRM matrix and a compensating position has an unmanaged gap, not an exemption.

The four domains

DomainSubdomains
1 — Cybersecurity GovernancePolicies and procedures; roles and responsibilities; risk management; cybersecurity in ICS project management; change management; periodical review and audit; human resources; awareness and training programme.
2 — Cybersecurity DefenseAsset management; identity and access management; system and processing facility protection; network security management; mobile device security; data and information protection; cryptography; backup and recovery; vulnerability management; penetration testing; event logs and monitoring; incident and threat management; physical security.
3 — Cybersecurity ResilienceCyber resilience aspects of business continuity management.
4 — Third-Party CybersecurityThird-party cybersecurity.

Two subdomains stand out against the ECC's shape. Governance carries a dedicated awareness and training programme subdomain — OT operators need role-specific training that IT awareness modules do not provide. And physical security sits inside Cybersecurity Defense rather than as an afterthought, because in an OT environment physical access to a controller is logical access.

The network architecture the OTCC prescribes

Subdomain 2-4 (Network Security Management) is where the OTCC stops describing outcomes and starts specifying an architecture. The requirements read like a zone-and-conduit design brief:

  • 2-4-1-1 — the OT/ICS environment must be segmented logically or physically from other environments and networks.
  • 2-4-1-2 — different zones within the OT/ICS environment must be segmented according to each zone's level, isolating data flows and directing traffic to choke points.
  • 2-4-1-3Safety Instrumented Systems (SIS) must be segmented logically or physically from other OT/ICS networks.
  • 2-4-1-4 / 2-4-1-5 — wireless technologies (Wi-Fi, Bluetooth, cellular, satellite) must be restricted to cases meeting a specific business requirement, properly secured, and segmented from other OT/ICS networks.
  • 2-4-1-6 — communications, services and connection points between zones limited to the minimum needed for operations, maintenance and safety.
  • 2-4-1-8 — only authorised business-critical services accessible from internal OT/ICS networks, with access to services carrying known vulnerabilities limited as far as possible.
  • 2-4-1-9direct communication between the corporate zone and OT/ICS zones must be prevented, with all required connections routed through a dedicated, secured and hardened jump host in the DMZ.
  • 2-4-1-11proxies between corporate and OT/ICS zones for all machine-to-machine traffic.
  • 2-4-1-12 / 2-4-1-13 — dedicated gateways segmenting OT/ICS from corporate, and a dedicated DMZ hosting any system that needs corporate-zone services.
  • 2-4-1-14 — strict limitation on enabling and using industrial protocols and ports.

SIS appears repeatedly across the document — segmented at 2-4-1-3, protected at 2-3-1-5, monitored for detection at 2-11-1-5, in scope for incident handling at 2-12-1-5, and physically restricted at 2-13-1-5. Safety systems are treated as a distinct asset class with their own thread of controls.

Remote access to OT is exceptional, not routine

Subcontrol 2-2-1-7 is the one to read to your OEM and integrator contacts. Remote access to OT/ICS networks must be restricted and exceptionally enabled when necessary and justified, and every grant requires:

  • a cybersecurity risk assessment conducted before access is granted, with the resulting risks monitored and managed;
  • a trusted multi-factor authenticated and encrypted channel;
  • a defined time period and limited privilege, both set in line with that risk assessment;
  • the session monitored and recorded.

Where the remote access point sits in the DMZ, 2-4-1-10 adds that it must not be connected to OT/ICS networks unless needed, with the session multi-factor authenticated, recorded and time-bounded. And 2-2-1-6 requires dual approval and explicit privilege escalation for sensitive actions inside the OT/ICS environment.

How the NCA assesses compliance

The NCA evaluates OTCC compliance through self-assessment by the organisation and/or audit field visits by the NCA or designated third parties, using the mechanisms it approves. The Assessment and Compliance Tool organises the measurement. As with the CSCC, expect the level assignment itself — and the reasoning behind it — to be examined alongside the control evidence.

An OTCC readiness sequence

  1. Inventory facilities, then assign levels. Use the NCA's Facility Level Identification Tool. The level determines whether you owe 56 or 151 controls, so this step sizes the entire programme.
  2. Confirm the ECC baseline. The OTCC extends the ECC, and the Methodology and Mapping Annex documents that relationship against ECC-1:2018's domain 5. Since ECC-2:2024 removed that domain, do not expect to find ICS controls in your current ECC assessment — everything OT is evidenced here.
  3. Map the current zone architecture — zones, conduits, data flows, connectivity and interdependencies — before designing changes. Most OTCC network controls are unimplementable without an accurate current-state diagram.
  4. Attack remote access first. It is the highest-risk gap, it usually requires contract renegotiation with OEMs and integrators, and it has the longest lead time.
  5. Separate SIS explicitly, in the network design and in the asset register. The controls treat safety systems as a distinct class; your documentation should too.
  6. Test control changes against operations. Use the Statement of Applicability clause properly: assess operational continuity before applying a control, document the assessment, and where a control cannot be applied as written, record the risk and the compensating position rather than the exemption alone.

How GRC Vantage supports OTCC compliance

GRC Vantage's compliance module carries the OTCC library with the L1/L2/L3 flags on every control, so assigning a facility its level produces exactly the applicable set — 56, 117 or 151 items — rather than the full document. Facilities are held as first-class scoping objects with their level assignment and the rationale behind it recorded, which is the artefact an NCA field visit asks for alongside the control evidence.

Where a control cannot be applied without jeopardising operational continuity, the platform records the operational assessment, links the resulting risk into the register scored on the NFCRM matrix, and tracks the compensating position — so the Statement of Applicability clause is evidenced as a managed decision. OTCC controls are linked to their ECC parents, and third-party obligations under domain 4 run through the same vendor workflow as your other supplier assurance.

For the wider family, see the NCA frameworks pillar guide. To scope an OTCC programme across a multi-site estate, talk to our team.

Want to see this in the platform?

Book a demo with the GRC Vantage team in Riyadh or Dammam.

See Compliance Management

Frequently asked questions

What is the NCA OTCC?

The Operational Technology Cybersecurity Controls (OTCC – 1: 2022) are the NCA's cybersecurity control set for Industrial Control Systems in critical facilities. They contain 4 main domains, 23 subdomains, 47 main controls and 122 subcontrols, and extend the Essential Cybersecurity Controls, which are a mandatory prerequisite.

Who must comply with the OTCC?

Organisations owning or operating Industrial Control Systems in facilities deemed critical: government organisations (ministries, authorities, establishments and others) and private sector organisations owning, operating or hosting Critical National Infrastructure — whether in the Kingdom or abroad.

How many OTCC controls apply to my facility?

It depends on the facility's assigned level. Level 1 facilities must implement 151 controls and subcontrols, Level 2 facilities 117, and Level 3 facilities 56. The levels are cumulative and are assigned using the NCA's OTCC Facility Level Identification Tool, based on criticality, HSE impact, and impact on the national economy, national security or society.

Does the OTCC allow remote access to OT networks?

Only exceptionally. Subcontrol 2-2-1-7 requires remote access to be restricted and enabled only when necessary and justified, with a cybersecurity risk assessment conducted beforehand, access via a trusted multi-factor authenticated and encrypted channel, for a defined period with limited privilege, and with the session monitored and recorded.

Can I skip a control that would disrupt operations?

The OTCC's Statement of Applicability requires compliance "after ensuring that applying applicable controls will not jeopardize the continuity of the organization's operation." That is an instruction to assess and document operational impact before applying a control — not a blanket exemption. Where a control cannot be applied as written, the residual risk still needs assessing, recording and managing.


Sources & References
Primary regulatory documents, international standards and guidance cited in this article
  • 1
    Primary Regulation — NCA
    National Cybersecurity Authority (NCA), Kingdom of Saudi Arabia, 2022
    Source for the control counts (4 domains, 23 subdomains, 47 controls, 122 subcontrols), scope of work, the three facility levels and their control counts (151/117/56), the Statement of Applicability operational-continuity clause, network segmentation subcontrols 2-4-1-1 to 2-4-1-14, and remote access subcontrols 2-2-1-6 and 2-2-1-7.
  • 2
    Primary Regulation — NCA
    National Cybersecurity Authority (NCA), 2022
    Part of the OTCC document. Contains the design principles, the relationship between OTCC and ECC Domain 5, mappings to international standards, and the methodology for defining control levels.
  • 3
    Primary Regulation — NCA
    National Cybersecurity Authority (NCA), 2022
    Published 02/06/2022, last updated 29/10/2025. Hosts the main document, the Methodology and Mapping Annex, and the OTCC Assessment and Compliance Tool.
GRC Vantage Team
GRC Vantage Team
Saudi GRC Practitioners

The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.