The NCA’s Essential Cybersecurity Controls (ECC-2:2024) are the national cybersecurity baseline for Saudi Arabia. They apply to government agencies and their affiliated entities, and to private-sector entities that own, operate or host critical national infrastructure, and the NCA encourages everyone else to use them. The controls sit in four domains and 28 subdomains, and the NCA checks compliance through self-assessment, its compliance tool and field audits.
The scope statement in ECC-2:2024 is short. The controls apply to government agencies in the Kingdom (including ministries, authorities and establishments) and their affiliated companies and entities, inside and outside the Kingdom, and to all private-sector entities that own, operate or host critical national infrastructure (CNI). The National Cybersecurity Authority (NCA) “strongly encourages” every other entity in the Kingdom to use the controls to improve its cybersecurity.
ECC-2:2024 groups its controls into four main domains and 28 subdomains. Most day-to-day IT work sits in domain 2.
| Domain | Subdomains |
|---|---|
| 1. Cybersecurity Governance | Strategy, management, policies and procedures, roles and responsibilities, risk management, cybersecurity in IT project management, compliance with standards, laws and regulations, periodical review and audit, human resources, and awareness and training (1-1 to 1-10). |
| 2. Cybersecurity Defense | Asset management, identity and access management, systems and processing facilities protection, email protection, network security, mobile devices, data and information protection, cryptography, backup and recovery, vulnerability management, penetration testing, event logs and monitoring, incident and threat management, physical security and web application security (2-1 to 2-15). |
| 3. Cybersecurity Resilience | Cybersecurity resilience aspects of business continuity management (3-1). |
| 4. Third-Party and Cloud Computing Cybersecurity | Third-party cybersecurity (4-1) and cloud computing and hosting cybersecurity (4-2). |
Each subdomain follows the same pattern: requirements are identified, documented and approved; they are implemented; and they are reviewed periodically. That pattern is why evidence, not just configuration, is what an assessor looks for.
ECC-2:2024 lists its changes in Appendix C. Three matter most to IT teams:
| Topic | ECC-1:2018 | ECC-2:2024 |
|---|---|---|
| Industrial control systems | A fifth main domain covered industrial control systems (ICS) cybersecurity. | The domain was deleted. Its controls moved to the Operational Technology Cybersecurity Controls (OTCC). |
| Where data is hosted | Sub-control 4-2-3-3 said the entity’s information hosting and storage must be inside the Kingdom. | Deleted. The document says data localisation controls moved to the National Data Management Office (NDMO) at SDAIA, and entities must refer to the NDMO about localisation before taking any action. |
| Cloud data protection | Classify data before hosting it on cloud or hosting services, and return it in a usable format when the service ends. | The cloud or hosting provider must protect the entity’s data in line with its classification level, and return it in a usable format when the service ends (4-2-3-1). |
Checklists and templates written against ECC-1:2018 may still cite the in-Kingdom hosting sub-control, so check which version a document is based on before you rely on it.
Subdomain 4-1 covers risks from third parties, including IT outsourcing, cybersecurity outsourcing and managed services. Among its controls:
If a provider monitors your systems remotely, ask exactly where its monitoring and operations centre is. Our third-party risk guide has the full list of questions.
ECC-2:2024 says the NCA evaluates compliance through several means: self-assessment by the entity, periodic reports from the compliance tool, and field audit visits, in the way the NCA considers appropriate. It also says the NCA will issue an assessment and compliance tool for ECC-2:2024.
Control 1-8 adds internal expectations: the cybersecurity department reviews implementation periodically, and the controls are also reviewed and audited by people outside that department, independently and with conflicts of interest in mind. The results are documented and presented to the cybersecurity supervisory committee and the Authorized Official.
The table shows typical evidence for the areas IT teams own. This is our practical suggestion, not the NCA’s list.
| Area | Typical evidence |
|---|---|
| Identity and access (2-2) | MFA coverage report for remote access and privileged accounts (2.2.3.2), privileged access register, dated access-review records. |
| Backup and recovery (2-9) | Backup scope covering critical assets, and records of restore tests. |
| Logs and monitoring (2-12) | Log sources and retention settings, alert review records. |
| Incident and threat management (2-13) | Incident response plan with escalation and classification, and the route for reporting incidents to the NCA (2.13.3.3). |
| Third parties (4-1) | Provider register, signed contract clauses, pre-contract risk assessments and periodic reviews. |
Last reviewed 20 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
