NCA TCC: Telework Cybersecurity Controls Guide
A guide to NCA Telework Cybersecurity Controls (TCC-1:2021) — the 21 controls across three domains, BYOD and MDM rules, and offshore remote access monitoring.
The Telework Cybersecurity Controls (TCC – 1: 2021) are the NCA's minimum requirements for organisations that let people work away from the office. They are the smallest of the NCA's control extensions — 21 main controls — and the easiest to under-scope, because most organisations read "telework" as "the VPN" when the NCA defines it considerably more broadly.
The trigger is also broader than teams expect. The TCC applies to every in-scope organisation that allows telework. There is no threshold, no minimum headcount, and no exemption for occasional remote work.
What the TCC covers
The NCA's definition of telework systems is the place to start, because it sets the scope of everything else:
Any technical systems, means or tools and its related components which are used by the organization to enable employees to perform their job duties in a place other than the official workplace. Examples include: virtual meeting systems, collaboration systems, file sharing, virtual private network (VPN), remote access systems, and other systems used in the work environment.
Virtual meeting platforms, collaboration suites and file sharing are named explicitly. An organisation that scopes its TCC assessment around the VPN and the remote-desktop gateway, and leaves Teams, SharePoint and the file-transfer tool out, has assessed a fraction of its telework estate.
| Component | Count |
|---|---|
| Main domains | 3 |
| Subdomains | 16 |
| Main controls | 21 |
| Subcontrols | 42 |
The three domains are Cybersecurity Governance (policies and procedures, risk management, awareness and training), Cybersecurity Defense (asset management through incident and threat management), and Cloud Computing and Hosting Cybersecurity. Appendix A of the document shows that telework controls were added to sixteen ECC subdomains and to none of the remaining thirteen.
Who is in scope
The TCC applies to government organisations in the Kingdom — ministries, authorities, establishments and others, along with their companies and entities — and to private sector organisations owning, operating or hosting Critical National Infrastructure. The NCA strongly encourages every other organisation in the Kingdom to adopt the controls voluntarily.
Applicability within the document depends on what the organisation actually uses. The NCA's own example: subdomain 3-1 (Cloud Computing and Hosting Cybersecurity) applies to organisations currently using or planning to use cloud and hosting services.
As with every NCA extension, continuous ECC compliance is a prerequisite, and the TCC's executive summary adds a second dependency: where critical systems are used in telework, the Critical Systems Cybersecurity Controls must be taken into account as well.
The controls that matter in practice
Identity and access
- 2-2-1-1 — telework access rights must be managed on need, factoring in system sensitivity, the level of access rights, and the type of device the employee uses.
- 2-2-1-2 — restrict concurrent logins: the same user must not hold remote access from multiple computers at the same time.
- 2-2-1-3 — secure standards for managing identities and passwords in telework systems.
- 2-2-2 — telework identities and access rights reviewed at least annually.
Concurrent-login restriction is the control most often missing. It is straightforward to implement in most access gateways and is a direct control against shared or stolen credentials — a session in Riyadh and a session elsewhere on the same account is precisely the signal it is designed to prevent.
Endpoint, mobile and BYOD
Subdomain 2-5 addresses mobile devices — laptops, smartphones and tablets — and explicitly contemplates Bring Your Own Device, with the objective of ensuring secure handling of the organisation's information, including sensitive information, under a BYOD policy:
- 2-5-1-1 — central management of mobile devices and BYODs using a Mobile Device Management (MDM) system.
- 2-5-1-2 — updates and security patches applied to mobile devices at least monthly.
The TCC therefore does not ban BYOD; it conditions it. Personal devices are permitted provided they are centrally managed and patched on a monthly cycle, which in practice means enrolment is a precondition of access.
System and network hardening
| Requirement | Frequency | Control |
|---|---|---|
| Telework risk assessment | At least annually | 1-2-1-1 |
| Access rights review | At least annually | 2-2-2 |
| Patching telework systems | At least every 3 months | 2-3-1-1 |
| Patching mobile devices | At least monthly | 2-5-1-2 |
| Configuration and hardening review | At least annually | 2-3-1-2 |
| Firewall rules and configuration review | At least annually | 2-4-1-2 |
| Event log retention | Minimum 12 months | 2-11-2 |
Beyond the cadence, three hardening subcontrols are worth naming: 2-3-1-3 requires reviewing and changing default configurations and ensuring removal of hard-coded, backdoor and default passwords; 2-3-1-4 requires secure session management covering authenticity, lockout and timeout; and 2-3-1-5 restricts activation of telework system features and services to what is needed, with cyber risks analysed where a feature must be enabled.
On the network side, 2-4-1-1 restricts the services, protocols and ports usable for remote access — specifically to internal systems, opened only on need — and 2-4-1-3 and 2-4-1-4 require protection against DDoS and against Advanced Persistent Threats at the network layer.
Monitoring: around the clock, with an offshore lens
Subdomain 2-11 is where the TCC's design intent becomes clearest:
- 2-11-1-1 — cybersecurity event logs activated on all technical components of telework systems.
- 2-11-1-2 — User Behaviour Analytics (UBA) — monitoring and analysing user behaviour to detect harmful or unusual activity.
- 2-11-1-3 — telework system events monitored around the clock.
- 2-11-1-4 — 24/7 monitoring procedures updated and implemented to include remote access operations, especially remote access from outside the Kingdom of Saudi Arabia, after checking their authenticity.
- 2-11-2 — event log retention of at least 12 months, in line with legislative and regulatory requirements.
For ordinary telework the NCA does not prohibit access from outside the Kingdom — it requires you to know about it, authenticate it, and watch it around the clock. For critical systems, the CSCC removes the option entirely. The two documents draw the line in different places, and which one applies depends on the system, not the worker.
The 24/7 requirement is the resourcing question hiding in a short document. Continuous monitoring of telework systems with UBA implies a SOC capability — in-house or managed — and 12 months of retained logs implies the storage and licensing to match. Organisations without an existing 24/7 capability should size this before the rest of the programme, because it is the item with real cost attached.
How the NCA assesses compliance
The NCA evaluates TCC compliance through self-assessments by the organisation and/or External Compliance Assessment. Compliance is mandated under item 3 of article 10 of the NCA's mandate and Royal Decree No. 57231 dated 10/11/1439H, and — the document is explicit — can only be achieved by also achieving continuous ECC compliance where applicable.
A TCC readiness sequence
- Inventory telework systems against the NCA's definition — VPN and remote access, but also virtual meetings, collaboration platforms and file sharing. This is where scope is won or lost.
- Identify which telework-accessible systems are critical. Those attract CSCC obligations, including the prohibition on remote access from outside the Kingdom.
- Fix concurrent logins and MDM enrolment. Both are configuration-level changes with immediate risk reduction, and both are commonly missing.
- Size the 24/7 monitoring and 12-month retention requirement before committing to a compliance date.
- Put the frequencies into a schedule — quarterly telework patching, monthly mobile patching, annual access, hardening and firewall reviews, annual telework risk assessment.
- Fold telework risks into the main register and score them on the NFCRM matrix rather than keeping a separate telework risk list.
How GRC Vantage supports TCC compliance
GRC Vantage's compliance module carries the TCC library mapped to its ECC parents, so a telework assessment reuses ECC evidence rather than re-collecting it, and flags where a telework-accessible system is also classified critical — surfacing the CSCC obligations that attach to it before the access design is finalised.
The recurring items — quarterly and monthly patch cycles, annual access, hardening and firewall reviews, the annual telework risk assessment — run as scheduled, evidence-bearing tasks with owners, so the cadence is demonstrable to a self-assessment or an external compliance assessment. Telework risks flow into the same register as the rest of the programme, scored on the NFCRM matrix, and the platform is deployed inside the Kingdom with teams in Riyadh and Dammam.
For the full framework family, see the NCA frameworks pillar guide. To scope a TCC assessment, talk to our team.
Book a demo with the GRC Vantage team in Riyadh or Dammam.
See Compliance Management →Frequently asked questions
What is the NCA TCC?
The Telework Cybersecurity Controls (TCC – 1: 2021) are the NCA's minimum cybersecurity requirements for organisations that allow remote work. They comprise 3 main domains, 16 subdomains, 21 main controls and 42 subcontrols, and extend the Essential Cybersecurity Controls, which are a prerequisite.
What counts as a telework system?
Any technical system, means or tool used to let employees do their jobs away from the official workplace — the NCA names virtual meeting systems, collaboration systems, file sharing, VPN and remote access systems, and includes other systems used in the work environment.
Does the TCC allow BYOD?
Yes, subject to controls. Subdomain 2-5 explicitly contemplates BYOD, requiring central management of mobile devices and BYODs through a Mobile Device Management system (2-5-1-1) and monthly application of updates and security patches (2-5-1-2).
Can employees work remotely from outside Saudi Arabia?
The TCC does not prohibit it, but subcontrol 2-11-1-4 requires around-the-clock monitoring procedures that specifically cover remote access from outside the Kingdom, after checking authenticity. Where a critical system is involved, CSCC subcontrol 2-2-1-1 prohibits remote access from outside the Kingdom altogether.
How long must telework logs be retained?
At least 12 months, in accordance with relevant legislative and regulatory requirements (2-11-2), with event logs activated on all technical components of telework systems and monitored around the clock.
- 1Primary Regulation — NCANational Cybersecurity Authority (NCA), Kingdom of Saudi Arabia, 2021Source for the control counts (3 domains, 16 subdomains, 21 controls, 42 subcontrols), the telework systems definition, scope of work, the concurrent-login restriction 2-2-1-2, MDM and BYOD subcontrols 2-5-1-1 and 2-5-1-2, monitoring subcontrols 2-11-1-1 to 2-11-1-4, the 12-month log retention in 2-11-2, and the review and patching frequencies.
- 2Primary Regulation — NCANational Cybersecurity Authority (NCA), 2022Published 02/06/2022, last updated 15/05/2025. Hosts the main document and the TCC-1:2021 Assessment and Compliance Tool.
- 3Primary Regulation — NCANational Cybersecurity Authority (NCA), 2019Referenced in the TCC executive summary for cases where critical systems are used in telework. Subcontrol 2-2-1-1 prohibits remote access to critical systems from outside the Kingdom.

The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.
Related articles
A practitioner's guide to the NCA National Framework for Cybersecurity Risk Management — scope, the four-phase methodology, the 5x5 matrix and Haseen reporting.
A guide to NCA Critical Systems Cybersecurity Controls (CSCC) — the seven identification criteria, 32 controls, and the in-Kingdom access and hosting rules.
A guide to NCA Operational Technology Cybersecurity Controls (OTCC) — the three facility levels, 122 subcontrols, and the OT zone and remote access rules.