Insights · Audit readiness

Audit readiness for NCA and SAMA reviews: the IT evidence checklist

How the NCA assesses ECC compliance, what control 1-8 requires, the evidence pack to build and how ISO 27001:2022 fits alongside.
The short answer

The NCA checks ECC compliance through self-assessment, reports from its compliance tool and field audits, and control 1-8 expects periodic internal review plus independent audit whose results reach the supervisory committee and the Authorized Official. SAMA members assess against the framework’s maturity model. Audit readiness means an evidence pack that is dated, owned and quick to find.

Key points
  • The NCA evaluates ECC compliance by self-assessment, periodic reports from its compliance tool and/or field audit visits.
  • Control 1-8 requires periodic review by the cybersecurity department and independent audit by others, with results documented and presented to the supervisory committee and the Authorized Official.
  • SAMA member organisations should operate at maturity level 3 or higher, which needs documented, owned and monitored controls.
  • An evidence pack should be dated, owned and findable in minutes.
  • ISO 27001:2022 can give the management system behind the evidence, and it does not replace NCA or SAMA assessment.

How you will be assessed

  • NCA ECC. Self-assessment, periodic reports from the compliance tool and/or field audit visits, in the way the NCA considers appropriate.
  • Your own audit (ECC 1-8). The cybersecurity department reviews periodically. The controls are also reviewed and audited by parties outside it, independently and with conflicts of interest in mind, in line with generally accepted auditing standards. Results include scope, observations, recommendations, corrective actions and remediation plans, and go to the cybersecurity supervisory committee and the Authorized Official.
  • SAMA members. Assessment against the Cyber Security Framework, where SAMA says member organisations should operate at maturity level 3 or higher.

The evidence pack

An evidence pack is a standing, dated collection of proof, not something you assemble during the audit. Cadences below are our suggestions.

EvidenceWhat it showsRefresh
Asset registerWhat you own and how critical it isContinuous, reviewed quarterly
MFA and admin-role reportWho has strong authentication and privileged accessMonthly
Access-review recordRights reviewed and removedQuarterly, after joiners and leavers
Patch and vulnerability reportFix rates and exceptionsMonthly
Backup and restore test logBackups exist and actually restoreTest at least quarterly
Incident response plan and exercise notesRoles, escalation, classification and the NCA reporting routeReview annually
Provider register and reviewsThird-party oversightPer provider tier

Where ISO 27001:2022 fits

ISO/IEC 27001 certifies an information security management system within a defined scope, audited by an accredited certification body. It gives you a structure for policies, risk treatment, internal audit and management review, which is useful raw material for NCA and SAMA evidence.

It does not replace either regulator’s assessment. The NCA lists its own means of evaluating ECC compliance, and SAMA members are assessed against SAMA’s framework. The transition period from the 2013 edition ended on 31 October 2025, so any ISO 27001 certificate you rely on today should be to the 2022 edition.

Run a mock audit

Twice a year, ask someone who did not build the controls to pick five items from the pack and ask for the proof. The gaps that appear are almost always missing dates, missing owners or evidence that lives in one person’s mailbox. Fix those before an assessor finds them.

Sources and further reading

Last reviewed 20 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

How does the NCA check ECC compliance?

Through self-assessment, periodic reports from the compliance tool and/or field audit visits, in the way the NCA considers appropriate.

Does an ISO 27001 certificate satisfy the NCA or SAMA?

No. It helps with structure and evidence, but the NCA and SAMA assess against their own controls and framework.

Who receives the results of ECC audits and reviews?

Control 1-8-3 says results are documented and presented to the cybersecurity supervisory committee and the Authorized Official.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
NCA ECC

NCA Essential Cybersecurity Controls (ECC-2:2024): what Saudi organisations need to evidence

A plain-English guide to the NCA’s ECC-2:2024: who it applies to, its four domains, what changed from ECC-1:2018 and the IT evidence to keep.
6 min read · Reviewed 20 September 2026
SAMA

SAMA Cyber Security Framework: what Saudi financial institutions need to evidence

Who the SAMA Cyber Security Framework applies to, its four domains, the maturity level SAMA expects and the IT evidence a member organisation keeps.
3 min read · Reviewed 20 September 2026
Third-party risk

Choosing and overseeing an IT provider in Saudi Arabia: third-party risk

What NCA ECC and the SAMA framework expect of your IT provider contracts, the in-Kingdom rule for remote monitoring centres and the questions to ask.
3 min read · Reviewed 20 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.