Government and critical infrastructure · NCA ECC

IT and cyber security aligned to the NCA’s controls.

Managed IT, Microsoft 365 governance and cyber security for government-affiliated entities and organisations that own, operate or host critical national infrastructure, and must show compliance with the NCA’s Essential Cybersecurity Controls.
Built for ECC-2:2024

Controls you can point to, and evidence you can produce

The NCA’s Essential Cybersecurity Controls (ECC-2:2024) are binding on government agencies and their affiliated entities, and on private-sector entities that own, operate or host critical national infrastructure. The NCA checks compliance through self-assessment, its compliance tool and field audits.
Cre8 IT runs the technical controls you own, and keeps the evidence organised so an assessment request takes minutes to answer rather than weeks.

What ECC-scope organisations ask us for

What the regulator expects

How we support ECC-2:2024

ECC-2:2024 has four domains. These are the areas an assessor is likely to test and what we do for each.

Governance (domain 1)

Policies, roles, risk management and periodic review. We document the technical controls behind them and supply the inputs to your risk register.

Defense (domain 2)

Identity and access management with MFA for remote access and privileged accounts, email and network protection, patching, backup, logging and monitoring.

Resilience (domain 3)

Backup, recovery and continuity arrangements that are tested, with the records to prove it.

Third parties (4-1)

Contract terms, pre-contract risk assessment and periodic review. Where a managed cybersecurity service is delivered remotely, ECC requires the monitoring and operations centre to be fully in the Kingdom (4-1-3-2). We tell you where each service is delivered from.

Cloud and hosting (4-2)

Cloud requirements identified, approved and implemented, with data classification driving what goes where.

Assessment and audit

A standing evidence pack for self-assessment, compliance-tool reporting and audit, with independent review scheduled under control 1-8.
Summary for orientation, checked against the regulators’ published text on 20 September 2026. Confirm the current wording with the regulator. This is not legal advice.

Where we help on data

Data classification

Classify first, then decide where data lives

ECC-2:2024 removed the in-Kingdom hosting sub-control that ECC-1:2018 contained, and says data localisation questions go to the National Data Management Office (NDMO) at SDAIA. So a data classification scheme comes first: it decides what may go to a cloud service, and which requirements apply.
We help you build and apply the scheme in your systems, with labels, retention and access rules. Decisions on localisation and legal basis belong with your data governance lead and the relevant authority.
How we work with you

From first assessment to steady state

1. Assess

A cyber health audit and gap assessment against ECC-2:2024, with a prioritised plan.

2. Secure

A secure baseline: multi-factor authentication, Conditional Access, managed devices, endpoint protection, backup and recovery.

3. Evidence

Registers, reports and records collected into an evidence pack your compliance lead can use.

4. Operate

Helpdesk and regular reviews, with reports written for your management and governing body.
Why Cre8 IT

Certified, experienced and open to scrutiny

Our own information security management system is certified to ISO 27001:2022, and we can share our certificate and scope as part of your procurement or due diligence.
We will tell you plainly what we can and cannot evidence, including which credentials we hold and where a service is delivered from.

Our credentials

ISO 27001:2022

Information security management

ISO 9001

Quality management

Microsoft Partner

Certified partner
Guides

Guides for ECC-scope organisations

Sourced to the regulator’s own text, dated and written by a named specialist.
NCA ECC

NCA Essential Cybersecurity Controls (ECC-2:2024): what Saudi organisations need to evidence

A plain-English guide to the NCA’s ECC-2:2024: who it applies to, its four domains, what changed from ECC-1:2018 and the IT evidence to keep.
6 min read · Reviewed 20 September 2026
Cloud and Microsoft 365

Microsoft 365 and cloud governance for Saudi organisations

What the NCA’s cloud controls say, where data localisation now sits, what Microsoft has announced for Saudi Arabia and the Microsoft 365 settings to keep.
3 min read · Reviewed 20 September 2026
Audit readiness

Audit readiness for NCA and SAMA reviews: the IT evidence checklist

How the NCA assesses ECC compliance, what control 1-8 requires, the evidence pack to build and how ISO 27001:2022 fits alongside.
3 min read · Reviewed 20 September 2026
FAQ

NCA and critical infrastructure questions

Who must comply with ECC-2:2024?

Government agencies in the Kingdom and their affiliated companies and entities, and all private-sector entities that own, operate or host critical national infrastructure. The NCA encourages everyone else to use the controls.

Does using Cre8 IT make us ECC compliant?

No provider can. You remain the in-scope entity. We run and evidence the technical controls and help you prepare for assessment.

Must our managed security provider’s monitoring centre be in Saudi Arabia?

Control 4-1-3-2 says cybersecurity managed service centres for monitoring and operations that use remote access must be fully located in the Kingdom. Ask every provider, including us, exactly where its centre is.

Which credentials does Cre8 IT hold?

ISO 27001:2022 for information security, ISO 9001 for quality management, and Microsoft Partner status. We do not claim any registration or approval that we do not hold, and we are happy to discuss what your procurement team requires.

Talk to a specialist about ECC-2:2024

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.