What the ECC is
The Essential Cybersecurity Controls (ECC) are the minimum cybersecurity requirements the National Cybersecurity Authority (NCA) sets for the national entities within their scope. The first edition was ECC-1:2018. The edition in force is ECC-2:2024, published in Arabic and English; the Arabic text is the binding one on questions of meaning.
The controls aim to reduce internal and external threats to an organisation's information and technology assets by protecting confidentiality, integrity and availability, and they take account of four pillars: strategy, people, process and technology.
ECC-2:2024 in numbers
- 4 main domains.
- 28 subdomains.
- 108 main controls.
- 92 subcontrols.
How compliance is measured
Entities in scope must take the measures needed for ongoing, continuous compliance. The NCA evaluates compliance through several means, including self-assessment by the entity, periodic reports from its compliance tool and field audit visits, using the mechanism it considers appropriate. To organise this, the NCA issues the ECC-2:2024 Assessment and Compliance Tool.
The ECC is also the foundation for the NCA's other control sets. The Critical Systems Cybersecurity Controls (CSCC), for example, are an extension of the ECC for critical systems, and the NCA treats ECC compliance as a prerequisite for CSCC compliance.
Who it applies to
The scope of ECC-2:2024 covers:
- Government agencies in the Kingdom, including ministries, authorities and establishments.
- The companies and entities affiliated with those agencies, inside or outside the Kingdom.
- Private-sector organisations that own, operate or host critical national infrastructure (CNI).
The NCA strongly encourages every other organisation in the Kingdom to use the controls to implement best practice, without mandating them.
Applicability control by control
Being in scope does not mean every control applies. Each entity must comply with all the controls applicable to it, and applicability depends on its business and the technologies it uses. The NCA's own example is subdomain 4-2, cloud computing and hosting cybersecurity, whose controls bind entities that use or plan to use cloud computing and hosting services.
Private companies outside the mandate
A private company that is not a government affiliate and does not own, operate or host CNI is not directly obliged to comply. The ECC can still reach you through your customers, because subdomain 4-1 requires in-scope entities to write cybersecurity requirements into their contracts with third parties, including non-disclosure, incident communication procedures and an obligation to apply the entity's cybersecurity requirements and policies. Whether your contracts or activities bring you into scope is a legal question, so confirm it with your legal adviser.
Structure: four main domains
ECC-2:2024 organises its main controls into four main domains. Each subdomain states an objective and the controls that achieve it, and most subdomains include a control requiring periodic review of implementation.
Domain 1: cybersecurity governance (10 subdomains)
Strategy, management, policies and procedures, roles and responsibilities, risk management, cybersecurity in IT project management, compliance with standards, laws and regulations, periodic review and audit, human resources, and awareness and training. Its controls include a cybersecurity department independent of the IT and communications department (1-2-1) and a cybersecurity supervisory committee (1-2-3).
Domain 2: cybersecurity defence (15 subdomains)
The operational core of the controls. Its subdomains include asset management, identity and access, email, network and mobile device security, cryptography, backup and recovery, vulnerability management, penetration testing, event logs and monitoring, incident and threat management, physical security and web application security. Subdomain 2-12, for instance, requires continuous monitoring of event logs and a retention period of at least 12 months.
Domain 3: cybersecurity resilience (1 subdomain)
The cybersecurity resilience aspects of business continuity management.
Domain 4: third-party and cloud computing cybersecurity (2 subdomains)
Third-party cybersecurity, which now names IT outsourcing, cybersecurity outsourcing and managed services explicitly, and cloud computing and hosting cybersecurity. Control 4-1-3 requires managed cybersecurity monitoring and operations centres that use remote access to be located entirely in the Kingdom.
What changed in ECC-2:2024
Appendix C of ECC-2:2024 lists the updates made to ECC-1:2018. The most significant:
- Domain 5 removed: industrial control systems cybersecurity is no longer part of the ECC. Its controls moved to the Operational Technology Cybersecurity Controls (OTCC), leaving four main domains.
- Saudi staffing extended: control 1-2-2 now requires all cybersecurity positions to be filled by full-time, qualified Saudi professionals. The 2018 text covered the head of the function and its supervisory and critical positions.
- Scope clarified: the companies and entities affiliated with government agencies are covered whether they are inside or outside the Kingdom.
- Authentication: multi-factor authentication for remote access and privileged accounts, with the number of factors and the techniques chosen on the basis of an impact assessment of authentication failure and bypass.
- Email: domain validation now names SPF, DKIM and DMARC explicitly.
- Network: a new subcontrol requires protection against distributed denial-of-service (DDoS) attacks.
- Cryptography: requirements must include at least those in the NCA's National Cryptographic Standards.
- Data localisation and privacy: these items were removed from the ECC, and entities are referred on them to the National Data Management Office (NDMO) at the Saudi Data and AI Authority (SDAIA).
Control and subdomain numbering also changed, so map your evidence and any earlier gap assessment to the 2024 numbering.
How to comply in practice
There is no shortcut, but organisations that make steady progress tend to follow a similar order:
- Establish your position: whether the ECC is mandatory for you, required by contract or adopted voluntarily, and which controls apply given your use of cloud, outsourcing and web applications.
- Work from the NCA's tool: assess yourselves with the ECC-2:2024 Assessment and Compliance Tool rather than a home-made checklist, so your results follow the regulator's own structure.
- Start with the asset inventory: systems, applications, privileged accounts, cloud services and the suppliers who reach your environment. Many controls in the defence domain cannot be assessed without it.
- Rate each applicable control with evidence: a document, a configuration or a log sample, not a verbal answer.
- Rank gaps by risk first and effort second.
- Put governance in place early: an independent cybersecurity department, an approved strategy and policies, the supervisory committee and regular reporting to the authorised official.
- Operate the controls that need daily work, such as log monitoring, vulnerability management and incident handling.
- Arrange independent review: control 1-8-2 requires implementation to be reviewed and audited by parties other than the cybersecurity department.
Effort depends on the size of your technology estate, the number of applicable controls and how much evidence already exists, so plan in phases rather than to a single date.
Common mistakes
- Assessing against ECC-1:2018: an old gap assessment no longer maps to the current version after domain 5 was removed and numbering changed.
- Treating a policy as compliance: a written policy without implementation and periodic review does not meet the control.
- Keeping the cybersecurity function inside IT: control 1-2-1 requires a department independent of the IT and communications department.
- Assuming the cloud controls do not apply: if you use or plan to use cloud or hosting services, including software as a service (SaaS), subdomain 4-2 binds you.
- Leaving suppliers out: contracts for IT outsourcing, cybersecurity outsourcing and managed services need the clauses subdomain 4-1 requires, and a cybersecurity risk assessment before signing.
- Overlooking the staffing control: control 1-2-2 covers all cybersecurity positions, not only the head of the function.
- Forgetting operational technology: if you run industrial control systems, their controls are now in the OTCC, so check whether it applies to you.
- Stopping after one assessment: the ECC requires continuous compliance, and most subdomains require periodic review of implementation.
What these mistakes share is that compliance is treated as a project that ends with a report, while the ECC treats it as a state that is measured and reviewed continuously.
How DataSec helps
DataSec supports ECC programmes from the first assessment to continuous operation:
- Compliance assessment: an evidence-based gap assessment against ECC-2:2024, in a format compatible with the NCA's assessment and compliance tool.
- GRC advisory: the strategy, policies, roles, supervisory committee charter and risk methodology the governance domain calls for.
- Penetration testing and vulnerability management: testing and remediation evidence for subdomains 2-10 and 2-11.
- Third-party risk and GRC platform: supplier assessments and contract requirements for subdomain 4-1.
- Managed SOC: event log monitoring and incident handling for subdomains 2-12 and 2-13, within the licence scope set out below.
Licence scope
DataSec holds the NCA Managed Security Operations Center (MSOC) Services Licence, Tier 2 and operates its SOC from Riyadh. Our licensed managed SOC serves private-sector organisations that do not own, operate or host CNI, including companies that apply the ECC voluntarily or at their customers' request. Government entities and organisations that own, operate or host CNI are served with compliance assessment, advisory, testing and solutions, without managed SOC, managed detection and response (MDR) or network operations centre (NOC) services.
To scope an assessment, send us a request.
How DataSec helps
Managed SOC services are provided within the scope of our Tier 2 licence, that is, to organisations other than government entities and those that own, operate or host critical national infrastructure.
Compliance assessment
Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.
GRC advisory
Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.
Penetration testing
Application, network and infrastructure testing with recognised methodologies and an actionable report.
Third-party risk & GRC platform
Vendor assessment and compliance management on a single platform.
Managed SOC
24/7 monitoring, analysis and response under an NCA licence.
Frequently asked questions
Does the ECC apply to private companies?
It is mandatory for private-sector organisations that own, operate or host critical national infrastructure, and for companies affiliated with government agencies. The NCA strongly encourages all other companies to apply it, and many meet ECC requirements through contracts with in-scope customers. Check your contracts and confirm your position with your legal adviser.
What changed in ECC-2:2024?
The industrial control systems domain was removed and moved to the OTCC, leaving 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols. All cybersecurity positions must now be filled by full-time, qualified Saudi professionals, and requirements were strengthened for multi-factor authentication, email domain validation and DDoS protection. Data localisation and privacy items were referred to the National Data Management Office.
What is the difference between ECC and CSCC?
The ECC is the baseline for every entity in scope. The Critical Systems Cybersecurity Controls (CSCC) extend it with additional controls for the systems an organisation identifies as critical, and the NCA treats ECC compliance as a prerequisite for CSCC compliance.
How does the NCA assess ECC compliance?
Through several means, including self-assessment by the entity, periodic reports from the compliance tool and field audit visits, using the mechanism the NCA considers appropriate. The NCA issues the ECC-2:2024 Assessment and Compliance Tool to organise the process.
Must all cybersecurity staff be Saudi?
Control 1-2-2 of ECC-2:2024 requires all cybersecurity positions to be filled by full-time, qualified Saudi cybersecurity professionals. The 2018 version applied this only to the head of the function and its supervisory and critical positions.
Do the cloud controls apply if we only use SaaS?
The controls in subdomain 4-2 bind in-scope entities that use or plan to use cloud computing and hosting services. Software as a service (SaaS) is one of the cloud service models the ECC names, so review those controls for every such service you use.
Can DataSec's managed SOC serve government entities?
No. DataSec's licence is Tier 2, which covers managed SOC services for any organisation other than government entities and organisations that own, operate or host critical national infrastructure. We serve those entities with compliance assessment, advisory, testing and solutions.
Does ECC compliance cover the PDPL?
No. The ECC is a cybersecurity framework from the NCA, while the Personal Data Protection Law is a separate law supervised by SDAIA with its own obligations. They overlap on security, because the PDPL Implementing Regulation requires controllers that are obliged to follow NCA controls to adopt them.
Official sources
- Essential Cybersecurity Controls (ECC-2:2024), National Cybersecurity Authority
- Critical Systems Cybersecurity Controls (CSCC), National Cybersecurity Authority
- Operational Technology Cybersecurity Controls (OTCC), National Cybersecurity Authority
This guide is general information, not legal advice, and regulators update their requirements; always refer to the version currently published by the regulator.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

