NCA TCC: Telework Cybersecurity Controls Guide

A guide to NCA Telework Cybersecurity Controls (TCC-1:2021) — the 21 controls across three domains, BYOD and MDM rules, and offshore remote access monitoring.

GRC Vantage TeamGRC Vantage Team2026-08-269 min read

The Telework Cybersecurity Controls (TCC – 1: 2021) are the NCA's minimum requirements for organisations that let people work away from the office. They are the smallest of the NCA's control extensions — 21 main controls — and the easiest to under-scope, because most organisations read "telework" as "the VPN" when the NCA defines it considerably more broadly.

The trigger is also broader than teams expect. The TCC applies to every in-scope organisation that allows telework. There is no threshold, no minimum headcount, and no exemption for occasional remote work.

What the TCC covers

The NCA's definition of telework systems is the place to start, because it sets the scope of everything else:

Any technical systems, means or tools and its related components which are used by the organization to enable employees to perform their job duties in a place other than the official workplace. Examples include: virtual meeting systems, collaboration systems, file sharing, virtual private network (VPN), remote access systems, and other systems used in the work environment.

Virtual meeting platforms, collaboration suites and file sharing are named explicitly. An organisation that scopes its TCC assessment around the VPN and the remote-desktop gateway, and leaves Teams, SharePoint and the file-transfer tool out, has assessed a fraction of its telework estate.

ComponentCount
Main domains3
Subdomains16
Main controls21
Subcontrols42

The three domains are Cybersecurity Governance (policies and procedures, risk management, awareness and training), Cybersecurity Defense (asset management through incident and threat management), and Cloud Computing and Hosting Cybersecurity. Appendix A of the document shows that telework controls were added to sixteen ECC subdomains and to none of the remaining thirteen.

Who is in scope

The TCC applies to government organisations in the Kingdom — ministries, authorities, establishments and others, along with their companies and entities — and to private sector organisations owning, operating or hosting Critical National Infrastructure. The NCA strongly encourages every other organisation in the Kingdom to adopt the controls voluntarily.

Applicability within the document depends on what the organisation actually uses. The NCA's own example: subdomain 3-1 (Cloud Computing and Hosting Cybersecurity) applies to organisations currently using or planning to use cloud and hosting services.

As with every NCA extension, continuous ECC compliance is a prerequisite, and the TCC's executive summary adds a second dependency: where critical systems are used in telework, the Critical Systems Cybersecurity Controls must be taken into account as well.

The controls that matter in practice

Identity and access

  • 2-2-1-1 — telework access rights must be managed on need, factoring in system sensitivity, the level of access rights, and the type of device the employee uses.
  • 2-2-1-2restrict concurrent logins: the same user must not hold remote access from multiple computers at the same time.
  • 2-2-1-3 — secure standards for managing identities and passwords in telework systems.
  • 2-2-2 — telework identities and access rights reviewed at least annually.

Concurrent-login restriction is the control most often missing. It is straightforward to implement in most access gateways and is a direct control against shared or stolen credentials — a session in Riyadh and a session elsewhere on the same account is precisely the signal it is designed to prevent.

Endpoint, mobile and BYOD

Subdomain 2-5 addresses mobile devices — laptops, smartphones and tablets — and explicitly contemplates Bring Your Own Device, with the objective of ensuring secure handling of the organisation's information, including sensitive information, under a BYOD policy:

  • 2-5-1-1central management of mobile devices and BYODs using a Mobile Device Management (MDM) system.
  • 2-5-1-2 — updates and security patches applied to mobile devices at least monthly.

The TCC therefore does not ban BYOD; it conditions it. Personal devices are permitted provided they are centrally managed and patched on a monthly cycle, which in practice means enrolment is a precondition of access.

System and network hardening

RequirementFrequencyControl
Telework risk assessmentAt least annually1-2-1-1
Access rights reviewAt least annually2-2-2
Patching telework systemsAt least every 3 months2-3-1-1
Patching mobile devicesAt least monthly2-5-1-2
Configuration and hardening reviewAt least annually2-3-1-2
Firewall rules and configuration reviewAt least annually2-4-1-2
Event log retentionMinimum 12 months2-11-2

Beyond the cadence, three hardening subcontrols are worth naming: 2-3-1-3 requires reviewing and changing default configurations and ensuring removal of hard-coded, backdoor and default passwords; 2-3-1-4 requires secure session management covering authenticity, lockout and timeout; and 2-3-1-5 restricts activation of telework system features and services to what is needed, with cyber risks analysed where a feature must be enabled.

On the network side, 2-4-1-1 restricts the services, protocols and ports usable for remote access — specifically to internal systems, opened only on need — and 2-4-1-3 and 2-4-1-4 require protection against DDoS and against Advanced Persistent Threats at the network layer.

Monitoring: around the clock, with an offshore lens

Subdomain 2-11 is where the TCC's design intent becomes clearest:

  • 2-11-1-1 — cybersecurity event logs activated on all technical components of telework systems.
  • 2-11-1-2User Behaviour Analytics (UBA) — monitoring and analysing user behaviour to detect harmful or unusual activity.
  • 2-11-1-3 — telework system events monitored around the clock.
  • 2-11-1-4 — 24/7 monitoring procedures updated and implemented to include remote access operations, especially remote access from outside the Kingdom of Saudi Arabia, after checking their authenticity.
  • 2-11-2 — event log retention of at least 12 months, in line with legislative and regulatory requirements.

For ordinary telework the NCA does not prohibit access from outside the Kingdom — it requires you to know about it, authenticate it, and watch it around the clock. For critical systems, the CSCC removes the option entirely. The two documents draw the line in different places, and which one applies depends on the system, not the worker.

The 24/7 requirement is the resourcing question hiding in a short document. Continuous monitoring of telework systems with UBA implies a SOC capability — in-house or managed — and 12 months of retained logs implies the storage and licensing to match. Organisations without an existing 24/7 capability should size this before the rest of the programme, because it is the item with real cost attached.

How the NCA assesses compliance

The NCA evaluates TCC compliance through self-assessments by the organisation and/or External Compliance Assessment. Compliance is mandated under item 3 of article 10 of the NCA's mandate and Royal Decree No. 57231 dated 10/11/1439H, and — the document is explicit — can only be achieved by also achieving continuous ECC compliance where applicable.

A TCC readiness sequence

  1. Inventory telework systems against the NCA's definition — VPN and remote access, but also virtual meetings, collaboration platforms and file sharing. This is where scope is won or lost.
  2. Identify which telework-accessible systems are critical. Those attract CSCC obligations, including the prohibition on remote access from outside the Kingdom.
  3. Fix concurrent logins and MDM enrolment. Both are configuration-level changes with immediate risk reduction, and both are commonly missing.
  4. Size the 24/7 monitoring and 12-month retention requirement before committing to a compliance date.
  5. Put the frequencies into a schedule — quarterly telework patching, monthly mobile patching, annual access, hardening and firewall reviews, annual telework risk assessment.
  6. Fold telework risks into the main register and score them on the NFCRM matrix rather than keeping a separate telework risk list.

How GRC Vantage supports TCC compliance

GRC Vantage's compliance module carries the TCC library mapped to its ECC parents, so a telework assessment reuses ECC evidence rather than re-collecting it, and flags where a telework-accessible system is also classified critical — surfacing the CSCC obligations that attach to it before the access design is finalised.

The recurring items — quarterly and monthly patch cycles, annual access, hardening and firewall reviews, the annual telework risk assessment — run as scheduled, evidence-bearing tasks with owners, so the cadence is demonstrable to a self-assessment or an external compliance assessment. Telework risks flow into the same register as the rest of the programme, scored on the NFCRM matrix, and the platform is deployed inside the Kingdom with teams in Riyadh and Dammam.

For the full framework family, see the NCA frameworks pillar guide. To scope a TCC assessment, talk to our team.

Want to see this in the platform?

Book a demo with the GRC Vantage team in Riyadh or Dammam.

See Compliance Management

Frequently asked questions

What is the NCA TCC?

The Telework Cybersecurity Controls (TCC – 1: 2021) are the NCA's minimum cybersecurity requirements for organisations that allow remote work. They comprise 3 main domains, 16 subdomains, 21 main controls and 42 subcontrols, and extend the Essential Cybersecurity Controls, which are a prerequisite.

What counts as a telework system?

Any technical system, means or tool used to let employees do their jobs away from the official workplace — the NCA names virtual meeting systems, collaboration systems, file sharing, VPN and remote access systems, and includes other systems used in the work environment.

Does the TCC allow BYOD?

Yes, subject to controls. Subdomain 2-5 explicitly contemplates BYOD, requiring central management of mobile devices and BYODs through a Mobile Device Management system (2-5-1-1) and monthly application of updates and security patches (2-5-1-2).

Can employees work remotely from outside Saudi Arabia?

The TCC does not prohibit it, but subcontrol 2-11-1-4 requires around-the-clock monitoring procedures that specifically cover remote access from outside the Kingdom, after checking authenticity. Where a critical system is involved, CSCC subcontrol 2-2-1-1 prohibits remote access from outside the Kingdom altogether.

How long must telework logs be retained?

At least 12 months, in accordance with relevant legislative and regulatory requirements (2-11-2), with event logs activated on all technical components of telework systems and monitored around the clock.


Sources & References
Primary regulatory documents, international standards and guidance cited in this article
  • 1
    Primary Regulation — NCA
    National Cybersecurity Authority (NCA), Kingdom of Saudi Arabia, 2021
    Source for the control counts (3 domains, 16 subdomains, 21 controls, 42 subcontrols), the telework systems definition, scope of work, the concurrent-login restriction 2-2-1-2, MDM and BYOD subcontrols 2-5-1-1 and 2-5-1-2, monitoring subcontrols 2-11-1-1 to 2-11-1-4, the 12-month log retention in 2-11-2, and the review and patching frequencies.
  • 2
    Primary Regulation — NCA
    National Cybersecurity Authority (NCA), 2022
    Published 02/06/2022, last updated 15/05/2025. Hosts the main document and the TCC-1:2021 Assessment and Compliance Tool.
  • 3
    Primary Regulation — NCA
    National Cybersecurity Authority (NCA), 2019
    Referenced in the TCC executive summary for cases where critical systems are used in telework. Subcontrol 2-2-1-1 prohibits remote access to critical systems from outside the Kingdom.
GRC Vantage Team
GRC Vantage Team
Saudi GRC Practitioners

The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.