Energy, utilities and industrial · NCA ECC and OTCC

Secure IT for organisations that run critical facilities.

Managed IT, Microsoft 365 governance and cyber security for energy, utilities and industrial organisations, where the corporate IT estate connects to operational technology.
Built for critical facilities

The IT estate is the way in to operational technology

Organisations that own, operate or host critical national infrastructure are inside the scope of the NCA’s ECC-2:2024. Industrial control systems in critical facilities have their own NCA controls, the Operational Technology Cybersecurity Controls (OTCC-1:2022). ECC used to carry an industrial control systems domain, and ECC-2:2024 moved it to the OTCC.
We focus on the IT estate and where it meets operational technology: identity, remote access, endpoints, patching, backup and logging. Detailed OT design and control-system engineering are specialist disciplines, and if you need them we will say so plainly and scope accordingly.

What critical-facility operators ask us for

What the regulator expects

How we support ECC and the IT side of OT

These are the IT areas that matter most for critical facilities, and what we do for each.

The IT and OT boundary

We document the IT side, keep it patched and monitored, and help you agree what may connect to what.

Identity and remote access

ECC-2:2024 expects multi-factor authentication for remote access and privileged accounts (2.2.3.2). We implement and report on it, including supplier access.

Patching and vulnerabilities

Regular vulnerability scanning and patch reporting for the IT estate, with a tracked remediation plan.

Logging and incidents

Log sources and retention, an incident plan with classification, and the route for reporting incidents to the NCA (2.13.3.3).

Suppliers and remote support

Contract terms and pre-contract risk assessment under ECC subdomain 4-1, including where any remote monitoring centre is located.

Evidence

A standing evidence pack for self-assessment and audit, with independent review scheduled under control 1-8.
Summary for orientation, checked against the regulators’ published text on 20 September 2026. Confirm the current wording with the regulator. This is not legal advice.

Where we help on data

Data

Classify data, then protect it accordingly

ECC-2:2024 expects data protection to follow classification (2-7-2). The NCA’s Data Cybersecurity Controls (DCC-1:2022), an extension to ECC, set minimum requirements for protecting data through its lifecycle. Localisation questions go to the NDMO at SDAIA.
We help you apply classification in Microsoft 365 and your file systems, with labels, access and retention rules that your data owners agree.
How we work with you

From first assessment to steady state

1. Assess

A cyber health audit and gap assessment against ECC-2:2024, with a prioritised plan.

2. Secure

A secure baseline: multi-factor authentication, Conditional Access, managed devices, endpoint protection, backup and recovery.

3. Evidence

Registers, reports and records collected into an evidence pack your compliance lead can use.

4. Operate

Helpdesk and regular reviews, with reports written for your management and governing body.
Why Cre8 IT

Certified, experienced and open to scrutiny

Our own information security management system is certified to ISO 27001:2022, and we can share our certificate and scope as part of your procurement or due diligence.
We will tell you plainly what we can and cannot evidence, including the limits of our OT expertise and where each service is delivered from.

Our credentials

ISO 27001:2022

Information security management

ISO 9001

Quality management

Microsoft Partner

Certified partner
Guides

Guides for critical-facility operators

Sourced to the regulator’s own text, dated and written by a named specialist.
NCA ECC

NCA Essential Cybersecurity Controls (ECC-2:2024): what Saudi organisations need to evidence

A plain-English guide to the NCA’s ECC-2:2024: who it applies to, its four domains, what changed from ECC-1:2018 and the IT evidence to keep.
6 min read · Reviewed 20 September 2026
Third-party risk

Choosing and overseeing an IT provider in Saudi Arabia: third-party risk

What NCA ECC and the SAMA framework expect of your IT provider contracts, the in-Kingdom rule for remote monitoring centres and the questions to ask.
3 min read · Reviewed 20 September 2026
Audit readiness

Audit readiness for NCA and SAMA reviews: the IT evidence checklist

How the NCA assesses ECC compliance, what control 1-8 requires, the evidence pack to build and how ISO 27001:2022 fits alongside.
3 min read · Reviewed 20 September 2026
FAQ

Energy and industrial questions

Do the OTCC apply to us?

The OTCC-1:2022 apply to industrial control systems in critical facilities owned or operated by government organisations, and by private-sector organisations that own, operate or host critical national infrastructure, in the Kingdom or abroad. The NCA encourages others to use them.

What happened to the industrial control systems domain in ECC?

ECC-1:2018 had one. ECC-2:2024 deleted it and moved those controls to the OTCC.

Can Cre8 IT secure our operational technology?

We focus on the IT estate and where it meets OT. Control-system design and engineering are specialist work, and if your project needs it we will say so and scope accordingly.

Does using Cre8 IT make us ECC compliant?

No provider can. You remain the in-scope entity. We run and evidence the technical controls and help you prepare for assessment.

Talk to a specialist about securing your IT estate

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.