NCA Essential Cybersecurity Controls (ECC-2:2024): The Complete Guide
ECC-2:2024 is the second edition of the Essential Cybersecurity Controls issued by Saudi Arabia's National Cybersecurity Authority (NCA). It is mandatory for government entities and their affiliates, and for private companies that own, operate or host critical national infrastructure. It has 4 domains, 28 subdomains, 108 main controls and 92 subcontrols. It replaced ECC-1:2018, which had 5 domains and 114 controls. Other organizations are strongly encouraged to adopt it, while most private companies now follow NCA's separate NCNICC-1:2025 controls.
| Official name | Essential Cybersecurity Controls (الضوابط الأساسية للأمن السيبراني) |
|---|---|
| Code / edition | ECC-2:2024 (replaces ECC-1:2018) |
| Issued by | National Cybersecurity Authority (NCA) |
| Structure | 4 domains · 28 subdomains · 108 main controls · 92 subcontrols |
| Mandatory for | Government entities and their affiliates (inside and outside KSA); private entities that own, operate or host critical national infrastructure |
| Others | Strongly encouraged to adopt |
| Assessment | Self-assessment, periodic reports through NCA compliance tools and/or field audits |
| Maximum penalty | Up to SAR 25 million under NCA's statutory violations framework (not applicable to public entities) |
What is ECC-2:2024?
The Essential Cybersecurity Controls (ECC) are the minimum cybersecurity requirements set by the National Cybersecurity Authority (NCA) for national entities in Saudi Arabia. The first edition, ECC-1:2018, became the country's best-known baseline. The second edition, ECC-2:2024, was issued in 2024 with a leaner structure: 4 domains, 28 subdomains, 108 main controls and 92 subcontrols.
The NCA requires "ongoing and continuous compliance". There is no one-off certification. Instead, entities must be able to show at any time that the controls are in place and documented.
Who must comply with ECC-2:2024?
- Government entities: ministries, authorities, establishments and other public bodies.
- Their affiliated companies and entities, inside and outside the Kingdom.
- Private-sector entities that own, operate or host critical national infrastructure (CNI).
All other organizations are "strongly encouraged" to adopt the ECC. Since December 2025, private companies that are not CNI have their own dedicated framework, NCNICC-1:2025. Suppliers to government and CNI clients are often asked to show ECC-aligned controls in tenders and vendor reviews, even when they are not directly in scope.
The 4 domains and 28 subdomains
| Domain | Subdomains |
|---|---|
| 1. Cybersecurity Governance (10) | Strategy; management; policies and procedures; roles and responsibilities; risk management; cybersecurity in IT project management; compliance with legislation and regulations; periodic review and audit; human resources; awareness and training |
| 2. Cybersecurity Defense (15) | Asset management; identity and access management; information system and processing facilities protection; email protection; network security; mobile device security; data and information protection; cryptography; backup and recovery; vulnerability management; penetration testing; event logs and monitoring; incident and threat management; physical security; web application security |
| 3. Cybersecurity Resilience (1) | Cybersecurity in business continuity management |
| 4. Third-Party and Cloud Computing Cybersecurity (2) | Third-party cybersecurity; cloud computing and hosting cybersecurity |
Subdomain names are summarized here. Map your gap assessment to the exact control numbers in the official NCA document.
What changed from ECC-1:2018
| ECC-1:2018 | ECC-2:2024 | |
|---|---|---|
| Domains | 5 | 4 |
| Subdomains | 29 | 28 |
| Main controls | 114 | 108 (+ 92 subcontrols) |
- Industrial control systems domain removed. Its controls moved to NCA's Operational Technology Cybersecurity Controls (OTCC).
- Data hosting inside the Kingdom is no longer an ECC control. Responsibility moved to the National Data Management Office (NDMO). Monitoring and operations centres that use remote access must still be fully located in Saudi Arabia.
- Saudization widened. In 2018 it covered only the head of cybersecurity and supervisory or critical roles. Now all cybersecurity positions must be filled by qualified, full-time Saudi professionals.
- Multi-factor authentication is now driven by the entity's risk assessment and explicitly covers privileged and remote access.
- Email security now expects SPF, DKIM and DMARC.
- DDoS protection was added as a control.
- Scope now explicitly includes affiliated entities inside and outside the Kingdom.
Requirements that surprise organizations
- The cybersecurity function must be independent from the IT department. This is mandatory. Reporting directly to the head of the entity is recommended.
- Every cybersecurity role must be held by a qualified, full-time Saudi national.
- Penetration testing must be periodic and cover all internet-facing services: infrastructure, websites, web and mobile apps, email and remote access.
- The strategy and policies must be backed by the head of the entity (or a delegate) and reviewed at planned intervals. The ECC does not set a fixed yearly cycle, so define your own and follow it.
How compliance is assessed and enforced
The NCA checks ECC compliance through entity self-assessment, periodic reports via its compliance tools and/or field audit visits. National entities submit self-assessments through NCA's Haseen platform, and the NCA reviews them and gives feedback.
The NCA's statutory violations framework lists non-compliance with its controls among its violations. Penalties include warnings, suspension or cancellation of a licence or service, and fines of up to SAR 25 million. Public entities and their staff acting in an official capacity are excluded from those penalties.
ECC and NCA's other frameworks
ECC is the base layer. Depending on your environment, other NCA frameworks sit on top of it: Operational Technology (OTCC), Cloud (CCC), Data (DCC), Telework (TCC) and Critical Systems (CSCC). Private companies outside CNI follow NCNICC-1:2025, which reuses the same building blocks in 65 controls. Financial institutions also answer to the SAMA Cyber Security Framework, and everyone processing personal data must meet the PDPL.
ECC-2:2024 compliance checklist
- Scope confirmed: government, affiliate or CNI operator (or a supplier asked for ECC alignment)
- Cybersecurity strategy approved by the head of the entity
- Cybersecurity department independent from IT, with Saudi professionals in all cybersecurity roles
- Policies and procedures for every applicable subdomain, approved and reviewed on a defined cycle
- Risk assessment and risk register
- Asset inventory and identity and access management, with risk-based MFA for privileged and remote access
- Email protection with SPF, DKIM and DMARC
- Network security including DDoS protection
- Backup and recovery tested
- Vulnerability management and periodic penetration testing of all internet-facing services
- Event logging, monitoring and incident and threat management
- Cybersecurity in business continuity management
- Third-party and cloud security requirements in contracts
- Awareness and training programme with records
- Self-assessment evidence ready for NCA review
Frequently Asked Questions
How many controls are in ECC-2:2024?
ECC-2:2024 has 108 main controls and 92 subcontrols, organized into 4 domains and 28 subdomains.
Who must comply with the NCA ECC?
Government entities and their affiliated entities inside and outside Saudi Arabia, and private-sector entities that own, operate or host critical national infrastructure. Other organizations are strongly encouraged to adopt it.
What is the difference between ECC-1:2018 and ECC-2:2024?
ECC-2:2024 reduced the framework from 5 domains and 114 controls to 4 domains and 108 main controls, moved industrial control systems to the OTCC, moved data hosting requirements to the NDMO, and extended Saudization to all cybersecurity positions.
Does ECC apply to private companies?
Only to private companies that own, operate or host critical national infrastructure. Other private companies follow NCA's NCNICC-1:2025 controls, although many clients still ask suppliers for ECC-aligned controls.
Is there an ECC certificate?
No. The NCA requires continuous compliance and checks it through self-assessments, periodic reports and field audits rather than issuing a certificate.
Must the cybersecurity team report to the CEO?
The cybersecurity function must be independent from IT, which is mandatory. Reporting directly to the head of the entity is recommended rather than mandatory.
Related guides
Sources
This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.