WaqiSecWaqiSec

NCA Essential Cybersecurity Controls (ECC-2:2024): The Complete Guide

WaqiSec Compliance Team · Last reviewed:

SHORT ANSWER

ECC-2:2024 is the second edition of the Essential Cybersecurity Controls issued by Saudi Arabia's National Cybersecurity Authority (NCA). It is mandatory for government entities and their affiliates, and for private companies that own, operate or host critical national infrastructure. It has 4 domains, 28 subdomains, 108 main controls and 92 subcontrols. It replaced ECC-1:2018, which had 5 domains and 114 controls. Other organizations are strongly encouraged to adopt it, while most private companies now follow NCA's separate NCNICC-1:2025 controls.

Official nameEssential Cybersecurity Controls (الضوابط الأساسية للأمن السيبراني)
Code / editionECC-2:2024 (replaces ECC-1:2018)
Issued byNational Cybersecurity Authority (NCA)
Structure4 domains · 28 subdomains · 108 main controls · 92 subcontrols
Mandatory forGovernment entities and their affiliates (inside and outside KSA); private entities that own, operate or host critical national infrastructure
OthersStrongly encouraged to adopt
AssessmentSelf-assessment, periodic reports through NCA compliance tools and/or field audits
Maximum penaltyUp to SAR 25 million under NCA's statutory violations framework (not applicable to public entities)

What is ECC-2:2024?

The Essential Cybersecurity Controls (ECC) are the minimum cybersecurity requirements set by the National Cybersecurity Authority (NCA) for national entities in Saudi Arabia. The first edition, ECC-1:2018, became the country's best-known baseline. The second edition, ECC-2:2024, was issued in 2024 with a leaner structure: 4 domains, 28 subdomains, 108 main controls and 92 subcontrols.

The NCA requires "ongoing and continuous compliance". There is no one-off certification. Instead, entities must be able to show at any time that the controls are in place and documented.

Who must comply with ECC-2:2024?

All other organizations are "strongly encouraged" to adopt the ECC. Since December 2025, private companies that are not CNI have their own dedicated framework, NCNICC-1:2025. Suppliers to government and CNI clients are often asked to show ECC-aligned controls in tenders and vendor reviews, even when they are not directly in scope.

The 4 domains and 28 subdomains

DomainSubdomains
1. Cybersecurity Governance (10)Strategy; management; policies and procedures; roles and responsibilities; risk management; cybersecurity in IT project management; compliance with legislation and regulations; periodic review and audit; human resources; awareness and training
2. Cybersecurity Defense (15)Asset management; identity and access management; information system and processing facilities protection; email protection; network security; mobile device security; data and information protection; cryptography; backup and recovery; vulnerability management; penetration testing; event logs and monitoring; incident and threat management; physical security; web application security
3. Cybersecurity Resilience (1)Cybersecurity in business continuity management
4. Third-Party and Cloud Computing Cybersecurity (2)Third-party cybersecurity; cloud computing and hosting cybersecurity

Subdomain names are summarized here. Map your gap assessment to the exact control numbers in the official NCA document.

What changed from ECC-1:2018

ECC-1:2018ECC-2:2024
Domains54
Subdomains2928
Main controls114108 (+ 92 subcontrols)

Requirements that surprise organizations

How compliance is assessed and enforced

The NCA checks ECC compliance through entity self-assessment, periodic reports via its compliance tools and/or field audit visits. National entities submit self-assessments through NCA's Haseen platform, and the NCA reviews them and gives feedback.

The NCA's statutory violations framework lists non-compliance with its controls among its violations. Penalties include warnings, suspension or cancellation of a licence or service, and fines of up to SAR 25 million. Public entities and their staff acting in an official capacity are excluded from those penalties.

ECC and NCA's other frameworks

ECC is the base layer. Depending on your environment, other NCA frameworks sit on top of it: Operational Technology (OTCC), Cloud (CCC), Data (DCC), Telework (TCC) and Critical Systems (CSCC). Private companies outside CNI follow NCNICC-1:2025, which reuses the same building blocks in 65 controls. Financial institutions also answer to the SAMA Cyber Security Framework, and everyone processing personal data must meet the PDPL.

ECC-2:2024 compliance checklist

Frequently Asked Questions

How many controls are in ECC-2:2024?

ECC-2:2024 has 108 main controls and 92 subcontrols, organized into 4 domains and 28 subdomains.

Who must comply with the NCA ECC?

Government entities and their affiliated entities inside and outside Saudi Arabia, and private-sector entities that own, operate or host critical national infrastructure. Other organizations are strongly encouraged to adopt it.

What is the difference between ECC-1:2018 and ECC-2:2024?

ECC-2:2024 reduced the framework from 5 domains and 114 controls to 4 domains and 108 main controls, moved industrial control systems to the OTCC, moved data hosting requirements to the NDMO, and extended Saudization to all cybersecurity positions.

Does ECC apply to private companies?

Only to private companies that own, operate or host critical national infrastructure. Other private companies follow NCA's NCNICC-1:2025 controls, although many clients still ask suppliers for ECC-aligned controls.

Is there an ECC certificate?

No. The NCA requires continuous compliance and checks it through self-assessments, periodic reports and field audits rather than issuing a certificate.

Must the cybersecurity team report to the CEO?

The cybersecurity function must be independent from IT, which is mandatory. Reporting directly to the head of the entity is recommended rather than mandatory.

Related guides

Sources

  1. NCA — Essential Cybersecurity Controls ECC-2:2024 (English PDF)
  2. NCA — ECC-2:2024 (Arabic PDF)
  3. NCA — ECC page
  4. NCA — Self-assessment service (Haseen)
  5. Umm Al-Qura — NCA statutory enablers
  6. Bird & Bird — NCA Regulations 2024
  7. SecurityWall — ECC-2:2024 domains and controls

This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.

💬