Insights · NCA ECC

NCA Essential Cybersecurity Controls (ECC-2:2024): what Saudi organisations need to evidence

A plain-English guide to the NCA’s ECC-2:2024: who it applies to, its four domains, what changed from ECC-1:2018 and the IT evidence to keep.
The short answer

The NCA’s Essential Cybersecurity Controls (ECC-2:2024) are the national cybersecurity baseline for Saudi Arabia. They apply to government agencies and their affiliated entities, and to private-sector entities that own, operate or host critical national infrastructure, and the NCA encourages everyone else to use them. The controls sit in four domains and 28 subdomains, and the NCA checks compliance through self-assessment, its compliance tool and field audits.

Key points
  • ECC-2:2024 applies to government agencies and their affiliated companies and entities, and to private-sector entities that own, operate or host critical national infrastructure (CNI). The NCA encourages all others to use it.
  • There are four main domains: Governance, Defense, Resilience, and Third-Party and Cloud Computing Cybersecurity, split into 28 subdomains.
  • ECC-2:2024 replaced ECC-1:2018. The industrial control systems domain moved to the OTCC, and the in-Kingdom hosting sub-control was deleted, with data localisation referred to the NDMO.
  • For IT or cybersecurity managed services, monitoring and operations centres that use remote access must be fully located in the Kingdom (control 4-1-3-2).
  • Evidence matters as much as the controls: the NCA assesses by self-assessment, compliance-tool reports and field audits.

Who ECC-2:2024 applies to

The scope statement in ECC-2:2024 is short. The controls apply to government agencies in the Kingdom (including ministries, authorities and establishments) and their affiliated companies and entities, inside and outside the Kingdom, and to all private-sector entities that own, operate or host critical national infrastructure (CNI). The National Cybersecurity Authority (NCA) “strongly encourages” every other entity in the Kingdom to use the controls to improve its cybersecurity.

  • Not every organisation is in the mandatory scope. A private company that does not own, operate or host CNI, and is not affiliated with a government body, is not covered by the scope statement. It may still choose to follow ECC, or be asked to by a customer.
  • Applicability varies by control. The document’s own example is the cloud computing and hosting subdomain (4-2): it is binding on entities that currently use, or plan to use, cloud and hosting services. Each entity must comply with all the controls that apply to it.
  • Compliance is a continuing duty. The document cites Article 10(3) of the NCA’s Statute and High Order No. 57231 and says in-scope entities must take all necessary measures to ensure ongoing and continuous compliance.

The four domains at a glance

ECC-2:2024 groups its controls into four main domains and 28 subdomains. Most day-to-day IT work sits in domain 2.

DomainSubdomains
1. Cybersecurity GovernanceStrategy, management, policies and procedures, roles and responsibilities, risk management, cybersecurity in IT project management, compliance with standards, laws and regulations, periodical review and audit, human resources, and awareness and training (1-1 to 1-10).
2. Cybersecurity DefenseAsset management, identity and access management, systems and processing facilities protection, email protection, network security, mobile devices, data and information protection, cryptography, backup and recovery, vulnerability management, penetration testing, event logs and monitoring, incident and threat management, physical security and web application security (2-1 to 2-15).
3. Cybersecurity ResilienceCybersecurity resilience aspects of business continuity management (3-1).
4. Third-Party and Cloud Computing CybersecurityThird-party cybersecurity (4-1) and cloud computing and hosting cybersecurity (4-2).

Each subdomain follows the same pattern: requirements are identified, documented and approved; they are implemented; and they are reviewed periodically. That pattern is why evidence, not just configuration, is what an assessor looks for.

What changed from ECC-1:2018

ECC-2:2024 lists its changes in Appendix C. Three matter most to IT teams:

TopicECC-1:2018ECC-2:2024
Industrial control systemsA fifth main domain covered industrial control systems (ICS) cybersecurity.The domain was deleted. Its controls moved to the Operational Technology Cybersecurity Controls (OTCC).
Where data is hostedSub-control 4-2-3-3 said the entity’s information hosting and storage must be inside the Kingdom.Deleted. The document says data localisation controls moved to the National Data Management Office (NDMO) at SDAIA, and entities must refer to the NDMO about localisation before taking any action.
Cloud data protectionClassify data before hosting it on cloud or hosting services, and return it in a usable format when the service ends.The cloud or hosting provider must protect the entity’s data in line with its classification level, and return it in a usable format when the service ends (4-2-3-1).

Checklists and templates written against ECC-1:2018 may still cite the in-Kingdom hosting sub-control, so check which version a document is based on before you rely on it.

What ECC-2:2024 says about IT providers and managed services

Subdomain 4-1 covers risks from third parties, including IT outsourcing, cybersecurity outsourcing and managed services. Among its controls:

  • Cybersecurity requirements for contracts with third parties must be identified, documented and approved (4-1-1).
  • Contracts with third parties must include, as a minimum: non-disclosure and secure removal of your data when the service ends, communication procedures for a cybersecurity incident, and an obligation on the third party to apply your cybersecurity requirements and the relevant legislation (4-1-2).
  • For IT or cybersecurity outsourcing and managed services, you must run a cybersecurity risk assessment and ensure mitigating controls are available before signing, and cybersecurity managed service centres for monitoring and operations that use remote access must be fully located in the Kingdom of Saudi Arabia (4-1-3).
  • The requirements must be reviewed periodically (4-1-4).

If a provider monitors your systems remotely, ask exactly where its monitoring and operations centre is. Our third-party risk guide has the full list of questions.

How the NCA checks compliance, and what evidence to keep

ECC-2:2024 says the NCA evaluates compliance through several means: self-assessment by the entity, periodic reports from the compliance tool, and field audit visits, in the way the NCA considers appropriate. It also says the NCA will issue an assessment and compliance tool for ECC-2:2024.

Control 1-8 adds internal expectations: the cybersecurity department reviews implementation periodically, and the controls are also reviewed and audited by people outside that department, independently and with conflicts of interest in mind. The results are documented and presented to the cybersecurity supervisory committee and the Authorized Official.

The table shows typical evidence for the areas IT teams own. This is our practical suggestion, not the NCA’s list.

AreaTypical evidence
Identity and access (2-2)MFA coverage report for remote access and privileged accounts (2.2.3.2), privileged access register, dated access-review records.
Backup and recovery (2-9)Backup scope covering critical assets, and records of restore tests.
Logs and monitoring (2-12)Log sources and retention settings, alert review records.
Incident and threat management (2-13)Incident response plan with escalation and classification, and the route for reporting incidents to the NCA (2.13.3.3).
Third parties (4-1)Provider register, signed contract clauses, pre-contract risk assessments and periodic reviews.

Sources and further reading

Last reviewed 20 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

Does ECC apply to a private company?

Only if it owns, operates or hosts critical national infrastructure, or is an affiliated company or entity of a government agency. The NCA encourages all other entities to use the controls, and a customer or contract may require it.

Is ISO 27001 the same as ECC?

No. ISO 27001 is an international management-system standard. ECC is the NCA’s national set of controls, which the NCA assesses through its own means: self-assessment, the compliance tool and field audits. ISO 27001 can support your evidence but is not one of the assessment routes ECC lists.

Does ECC-2:2024 require data to be hosted in Saudi Arabia?

ECC-2:2024 deleted the ECC-1:2018 sub-control that said so. It says data localisation controls moved to the NDMO at SDAIA and that entities must refer to the NDMO before acting. Also check your sector regulator and your contracts.

Does using a managed IT provider change our ECC obligations?

You remain the in-scope entity. Subdomain 4-1 sets what your contracts must cover and, for remote managed cybersecurity services, where monitoring and operations centres must be located.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
Third-party risk

Choosing and overseeing an IT provider in Saudi Arabia: third-party risk

What NCA ECC and the SAMA framework expect of your IT provider contracts, the in-Kingdom rule for remote monitoring centres and the questions to ask.
3 min read · Reviewed 20 September 2026
Audit readiness

Audit readiness for NCA and SAMA reviews: the IT evidence checklist

How the NCA assesses ECC compliance, what control 1-8 requires, the evidence pack to build and how ISO 27001:2022 fits alongside.
3 min read · Reviewed 20 September 2026
Cloud and Microsoft 365

Microsoft 365 and cloud governance for Saudi organisations

What the NCA’s cloud controls say, where data localisation now sits, what Microsoft has announced for Saudi Arabia and the Microsoft 365 settings to keep.
3 min read · Reviewed 20 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.