What the ECC is
The Essential Cybersecurity Controls (ECC) are the minimum cybersecurity requirements issued by the National Cybersecurity Authority (NCA) for the organisations under its remit. The first version (ECC-1:2018) was published in 2018; the version in force today is ECC-2:2024. It has four main domains, 28 subdomains, 108 main controls and 92 subcontrols, and each control carries its own detailed requirements and compliance indicators.
The Authority reviews the controls periodically. Do not build your plan on an old version or on a third-party summary. Always work from the version currently published on the NCA website and from the assessment and compliance tool the Authority issues for it (the ECC-2:2024 Assessment and Compliance Tool).
Who it applies to
The NCA mandates the ECC for government agencies in the Kingdom, including ministries, authorities and establishments, and their affiliated companies and entities inside and outside the Kingdom, and for private-sector organisations that own, operate or host critical national infrastructure. The NCA strongly encourages all other organisations to use the controls to raise their security maturity.
In practice, many private-sector companies treat the ECC as close to mandatory for two reasons: their government customers require it in contracts under third-party clauses, and sector regulators build their own frameworks on the same logic. Applying the ECC today shortens the path to any sector framework later.
The four main domains of ECC-2:2024
- Cybersecurity governance (10 subdomains): strategy, cybersecurity management, policies and procedures, roles and responsibilities, risk management, cybersecurity in IT project management, compliance with cybersecurity standards, laws and regulations, periodical review and audit, cybersecurity in human resources, and the awareness and training programme.
- Cybersecurity defence (15 subdomains): asset management, identity and access management, protection of information systems and processing facilities, email protection, network security management, mobile devices security, data and information protection, cryptography, backup and recovery management, vulnerability management, penetration testing, event logs and monitoring management, incident and threat management, physical security, and web application security.
- Cybersecurity resilience (1 subdomain): the cybersecurity resilience aspects of business continuity management.
- Third-party and cloud computing cybersecurity (2 subdomains): third parties, and cloud computing and hosting, whose controls bind anyone using or planning to use cloud services.
What changed from 2018? Main domain 5, industrial control systems cybersecurity, was removed and its controls moved to the Operational Technology Cybersecurity Controls (OTCC), so organisations running ICS work from those. And every cybersecurity position, not only the head of the function, must now be filled by full-time, qualified Saudi professionals. Control and subdomain numbering differs between versions, so document your evidence against ECC-2:2024 numbering.
A practical 90-day approach
Ninety days is not enough for full compliance. It is enough to know where you stand, close the most dangerous gaps and put governance in place so you do not slide back. Sequence is what matters.
Days 1 to 30: inventory and gap assessment
- Inventory your assets: systems, applications, databases, privileged accounts, cloud services, and the suppliers who have access to your environment. You cannot protect what you do not know you have.
- Assign an owner to every asset and every control. A control without an owner does not get closed.
- Rate each control against your current state on three levels: implemented, partially implemented and not implemented, with evidence for each rating.
- Rank the gaps by impact and effort, not by the order they appear in the document.
Days 31 to 60: quick wins and governance
- Multi-factor authentication on remote access and on privileged accounts.
- Close known critical vulnerabilities on internet-facing systems and schedule recurring scans.
- Enable event logging on sensitive systems and collect it centrally.
- Have senior management formally approve the core policies: cybersecurity policy, access management, acceptable use and incident management.
- Establish a cybersecurity committee or function with clear authority and regular reporting to senior management.
Days 61 to 90: monitoring and consolidation
- Test the incident response plan with at least one tabletop exercise and record the lessons.
- Make monitoring permanent: who watches the logs, what happens on an alert, and how closure is documented.
- Link every control to living evidence, such as a report, a configuration screenshot or meeting minutes, instead of files assembled before an audit.
- Write a remediation plan for the remaining gaps with dates, owners and budget.
How a licensed SOC supports continuous compliance
Several controls in the defence domain, such as event logs and monitoring and incident and threat management, are not closed by a written policy. They are closed by daily operation. That is where a managed Security Operations Centre (SOC) comes in: collecting and monitoring logs, detecting and analysing threats, recommending containment, and producing periodic reports that double as compliance evidence.
DataSec holds the Managed Security Operations Center (MSOC) Services Licence — Tier 2 from the National Cybersecurity Authority. A Tier 2 licence authorises the provision of managed SOC services to any organisation other than government entities and organisations that own, operate or host critical national infrastructure. This support is therefore available to eligible private-sector organisations applying the ECC voluntarily or at their customers' request. For government entities and critical infrastructure operators, we work on compliance assessment, advisory and solutions, without SOC services.
The licensing framework places obligations on the licensee that serve your compliance directly: keeping facilities and data inside the Kingdom, applying the Authority's alerts and detection rules, retaining security-event records for a defined period, and staffing the service with analysts who hold NCA qualification certificates. Refer to the current version of the framework for the detail of each obligation.
Common mistakes
- Treating the ECC as a documentation project: policies without implementation are found out at the first audit.
- Buying tools before the inventory: a monitoring tool that does not know what it is watching produces no evidence.
- Ignoring third parties: a supplier with access to your network is inside your compliance scope.
- Depending on one person: when they leave, the knowledge and the evidence leave with them.
- Stopping at one assessment: compliance is a state you keep measuring, not a certificate you hang on the wall.
Illustrative example: a logistics company began with an asset inventory and found active supplier accounts unused for months. Closing them took a day and closed two gaps in the identity and access subdomain before any tool was purchased.
This article is general awareness content, not legal advice. Refer to the current version of the regulations and frameworks mentioned.
All articles
