NCA ECC-2
NCA Essential Cybersecurity Controls ECC-2:2024
ECC-2:2024
About this framework
The Essential Cybersecurity Controls (ECC-2:2024) are Saudi Arabia's national cybersecurity baseline, issued by the National Cybersecurity Authority. They set the minimum controls every in-scope organisation must implement across governance, defence, resilience, third-party and cloud, and industrial control systems. ECC-2 is the 2024 update to the original 2018 controls, with a tier-based model so each entity implements a proportionate set based on its criticality and risk.
Why it matters
ECC-2 is the de-facto national standard in the Kingdom — and increasingly the entry condition for working with Saudi government and critical infrastructure. But the reason to do it well is not the regulator's attention. The five domains describe what a genuinely defensible organisation looks like: it knows its assets, controls its access, can withstand disruption, and manages the risk its suppliers carry. ECC-2 is part of Saudi Vision 2030's digital agenda — getting it right is as much about being ready to operate in the Kingdom's digital economy as it is about passing an assessment. 786 Cyber makes that readiness provable, control by control, with the evidence kept current.
Who needs this
Mandatory for Saudi government bodies — ministries, authorities and their affiliates, including entities established outside the Kingdom — and for private operators of Critical National Infrastructure. Many Saudi enterprises also adopt ECC voluntarily because it is the national baseline. If you sell to KSA government or CNI, expect ECC alignment to be required of you too.
The five domains
- Cybersecurity Governance Strategy, policy, roles, risk management, compliance, and awareness.
- Cybersecurity Defence Asset and identity management, network and system protection, cryptography, backups, vulnerability management and monitoring. The largest domain.
- Cybersecurity Resilience Cyber resilience built into business continuity.
- Third-Party & Cloud Computing Cybersecurity Supplier, outsourcing and cloud-hosting controls.
- Industrial Control Systems (ICS) Cybersecurity Protection for OT and industrial environments.
How 786 Cyber helps
- Guided assessment Maps your current state across all five domains and ranks gaps by impact.
- Generated policies For governance, risk, third-party and more — pre-populated for your organisation.
- Cross-framework mapping ECC-2 controls map to SAMA CSF and ISO 27001, so one implementation counts across each. Implement once, progress everywhere.
- Continuous evidence Every implementation logged, ready for NCA self-assessment.
- AI-assisted validation Enriches the gap analysis; judgement stays with your team.
Cross-framework coverage
Controls in NCA ECC-2 also cover:
See how NCA ECC-2 connects to the rest → the Security Universe
Control domains
1-1 · Cybersecurity Strategy 3
1-2 · Cybersecurity Management 3
1-3 · Cybersecurity Policies and Procedures 4
1-4 · Cybersecurity Roles and Responsibilities 2
1-5 · Cybersecurity Risk Management 4
1-6 · Cybersecurity in Information and Technology Project Management 4
1-7 · Compliance with Cybersecurity Standards, Laws and Regulations 2
1-8 · Periodical Cybersecurity Review and Audit 3
1-9 · Cybersecurity in Human Resources 6
1-10 · Cybersecurity Awareness and Training Program 5
2-1 · Asset Management 6
2-2 · Identity and Access Management 4
2 sub-controls
- 2-2-3-1 User authentication based on username and password User authentication based on username and password. Single-factor authentication based on username and password. Clarification Modification Sub-control
- 2-2-3-2 Multi-factor authentication for remote access Multi-factor authentication for remote access. Multi-factor authentication, and defining the suitable authentication factors and their numbers as well as the suitable authentication techniques based on the result of impact assessment of authentication failure and bypass for remote access and for privileged accounts. Clarification Essential Cybersecurity Controls ﻣﻘﻴﺪ- ﺪﻣ 44 Version Date ECC – 2 : 2024 2024 Update type Section Previous text Updated text Rationale Modification Sub-control
2-3 · Information Systems and Information Processing Facilities Protection 4
2-4 · Email Protection 4
2 sub-controls
- 2-4-3-2 Multi-factor authentication for remote and webmail access to email service Multi-factor authentication for remote and webmail access to email service. Multi-factor authentication, and defining the suitable authentication factors and their numbers as well as the suitable authentication techniques based on the result of impact assessment of authentication failure and bypass for remote and webmail access. Clarification Modification Sub-control
- 2-4-3-5 Validation of the entity’s email service domains (e.g., using Sender Policy Framework (SPF)). Validation of the entity’s email service domains by using Sender Policy Framework (SPF Validation of the entity’s email service domains (e.g., using Sender Policy Framework (SPF)). Validation of the entity’s email service domains by using Sender Policy Framework (SPF), Domain Keys Identified Mail (DKIM), and Domain Message Authentication Reporting and Conformance (DMARC). Clarification Addition Sub-control
2-5 · Network Security Management 4
1 sub-control
- 2-5-3-9 N/A Protecting against Distributed Denial of Service (DDoS) attacks to limit risks arising from these attacks N/A Protecting against Distributed Denial of Service (DDoS) attacks to limit risks arising from these attacks. Cybersecurity enhancement Modification Control
2-6 · Mobile Devices Security 4
2-7 · Data and Information Protection 3
3 sub-controls
- 2-7-3-1 Data and information ownership. Data and information ownership.
- 2-7-3-2 Data and information classification and labeling mechanisms. Data and information classification and labeling mechanisms.
- 2-7-3-3 Data and information privacy Data and information privacy. Data and Artificial Intelligence Authority mandates, entities must refer to the National Data Management Office regarding data privacy before taking any action in this regard. Modification Control
2-8 · Cryptography 4
3 sub-controls
- 2-8-3-1 Approved cryptographic solutions standards and its technical and regulatory limitations. Approved cryptographic solutions standards and its technical and regulatory limitations.
- 2-8-3-2 Secure management of cryptographic keys during their lifecycles. Secure management of cryptographic keys during their lifecycles.
- 2-8-3-3 Encryption of data in-transit and at-rest as per classification and related laws and regulations Encryption of data in-transit and at-rest as per classification and related laws and regulations. Cybersecurity requirements for cryptography shall include at least the requirements in the National Cryptographic Standards, published by NCA. The appropriate cryptographic standard level shall be implemented based on the nature and sensitivity of the data, systems, and networks to be protected as well as the entity’s risk assessment, and as per the relevant legislative and regulatory requirements, as follows: 2.8.3.1 Approved cryptographic systems and solutions standards and their technical and regulatory restrictions. Clarification Essential Cybersecurity Controls ﻣﻘﻴﺪ- ﺪﻣ 46 Version Date ECC – 2 : 2024 2024 Update type Section Previous text Updated text Rationale 2.8.3.2 Secure management of cryptographic keys during their lifecycles. 2.8.3.3 Encryption of data in-transit and at-rest, as per their classification and the relevant legislative and regulatory requirements. Modification Sub-control
2-9 · Backup and Recovery Management 4
2-10 · Vulnerability Management 4
2-11 · Penetration Testing 4
2-12 · Cybersecurity Event Logs and Monitoring Management 4
2-13 · Cybersecurity Incident and Threat Management 4
2-14 · Physical Security 4
2-15 · Web Application Security 4
1 sub-control
- 2-15-3-5 Multi-factor authentication for users’ access Multi-factor authentication for users’ access. User authentication, and the suitable authentication factors and their numbers as well as the authentication techniques shall be defined based on the result of impact assessment of authentication failure and bypass for users’ access. Clarification Modification Objective of Sub-domain 4-1 To ensure the protection of assets against the cybersecurity risks related to third-parties including outsourcing and managed services as per organizational policies and procedures, and related laws and regulations. To ensure the protection of the entity’s assets against third-party cybersecurity risks (including Information Technology (IT) outsourcing, cybersecurity outsourcing, and managed services), as per the entity’s regulatory policies and procedures and the relevant legislative and regulatory requirements. Clarification Modification Control
3-1 · Cybersecurity Resilience Aspects of Business Continuity Management (BCM) 4
4-1 · Third-Party Cybersecurity 4
4-2 · Cloud Computing and Hosting Cybersecurity 4
2 sub-controls
- 4-2-3-1 Classification of data prior to hosting on cloud or hosting services and returning data (in a usable format) upon service completion Classification of data prior to hosting on cloud or hosting services and returning data (in a usable format) upon service completion. Protection of entity’s data by cloud and hosting service providers in accordance with its classification level and returning data (in a usable format) upon service completion. Cybersecurity enhancement Deletion Sub-control
- 4-2-3-3 Entity’s information hosting and storage must be inside the Kingdom of Saudi Arabia Entity’s information hosting and storage must be inside the Kingdom of Saudi Arabia. Controls related to data localization have been transferred from the document to the National Data Management Office (NDMO) at the Saudi Data and Artificial Intelligence Authority for as per the mandates, and entities must refer to the National Data Management Office regarding data localization before taking any action in this regard. Deletion Main domain 5 Industrial Control Systems Cybersecurity Controls in domain 5 moved to the OTCC Essential Cybersecurity Controls ﻣﻘﻴﺪ- ﺪﻣ 48 Version Date ECC – 2 : 2024 2024 Update type Section Previous text Updated text Rationale (Operational Technology Cybersecurity Controls) Modification Terms and Definitions Confidential Data/Information Sensitive Data/Information Translation update Modification Terms and Definitions Critical National Infrastructure (CNI) These are the assets (i.e., facilities, systems, networks, processes and key operators who operate and process them), whose loss or vulnerability to security breaches may result in: Significant negative impact on the availability, integration or delivery of basic services, including services that could result in serious loss of property and/or lives and/or injuries, alongside observance of significant economic and/or social impacts. Significant impact on national security and/or national defense and/or state economy or national capacities. Critical National Infrastructure (CNI) Essential elements of infrastructure (i.e. assets, facilities, systems, networks, processes, and key personnel who operate and process them) whose loss or compromise may result in: Significant negative impact on the availability, integration, or delivery of basic services, including services whose integrity could, if compromised, result in serious loss of property, lives, and/or injuries, taking into account significant national-level economic and/or social impacts. Significant impact on national security, national defense, and/or Clarification Essential Cybersecurity Controls ﻣﻘﻴﺪ- ﺪﻣ 49 Version Date ECC – 2 : 2024 2024 Update type Section Previous text Updated text Rationale State economy or national capacities. Modification Terms and Definitions Cyber Attack Intentional exploitation of computer systems, networks, and entities whose work depends on digital ICT, in order to cause damage. Cyber Attack An intentional attempt to impact cybersecurity negatively; whether succeeded or not. Clarification Modification Terms and Definitions Event Something that happens in a specific place (such as network, system, application) at a specific time. Event An event related to the cybersecurity state of a network, or a system, or a service, or data, or any other digital device. Clarification Modification Terms and Definitions Incident A compromise through violation of cybersecurity policies, acceptable use policies, practices or cybersecurity controls or requirements. Incident An event that occurred and negatively impacted cybersecurity, whether intentional or unintentional. Clarification Modification Terms and Definitions (Inter)National Requirements National requirements are those developed by a regulatory entity or body in Saudi Arabia for regulatory use (e.g., NCA’s Essential Cybersecurity Controls (ECC-1:2018) International Requirements International requirements are those developed by an international entity or organization for regulatory use worldwide (e.g. SWIFT, PCI, etc.). Clarification Essential Cybersecurity Controls ﻣﻘﻴﺪ- ﺪﻣ 50 Version Date ECC – 2 : 2024 2024 Update type Section Previous text Updated text Rationale International requirements are those developed by a global entity for worldwide regulatory or best practices use (e.g., SWIFT, PCI-DSS, etc.). Modification Terms and Definitions Multi-Factor Authentication (MFA) A security system that verifies user identity, which requires the use of several separate elements of identity verification mechanisms. Verification mechanisms include several elements: Knowledge (something only the user knows “like password”). Possession (something only owned by the user “such as a program, device generating random numbers or SMSs” for login records, which are called: One-Time-Password). Inherent characteristics (characteristics of the user only, such as fingerprint). Multi-Factor Authentication (MFA) A security system that verifies user identity, using several authentication factors through user authentication techniques. Authentication factors are: Knowledge (something only the user knows “such as using a password technique”). Possession (something only owned by the user “such as using techniques like a program or a device generating random numbers or SMSs” for login records, which are called One-Time-Password). Inherent characteristics (characteristics of the user only, such as using Clarification Essential Cybersecurity Controls ﻣﻘﻴﺪ- ﺪﻣ 51 Version Date ECC – 2 : 2024 2024 Update type Section Previous text Updated text Rationale fingerprint or face recognition techniques). Deletion Terms and Definitions Privacy Freedom from unauthorized interference or disclosure of personal information about an individual. For the National Data Management Office (NDMO) at the Saudi Data and Artificial Intelligence Authority mandates, entities must refer to the National Data Management Office regarding data privacy before taking any action in this regard. Modification Terms and Definitions Threat Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. Also, the potential for a threat-source to successfully exploit a Threat Anything with the potential to impact cybersecurity negatively. Clarification Essential Cybersecurity Controls ﻣﻘﻴﺪ- ﺪﻣ 52 Version Date ECC – 2 : 2024 2024 Update type Section Previous text Updated text Rationale particular information system vulnerability. Modification Terms and Definitions Vulnerability Any type of weakness in a computer system, software, application, a set of procedures, or in anything that leaves cybersecurity exposed to a threat. Vulnerability A weakness in any information technology asset (such as software and systems) or a process, control, or anything, that could be exploited to negatively impact cybersecurity. Clarification Addition List of the Abbreviations DDoS: Distributed Denial of Service Attack DKIM: Domain Keys Identified Mail DMARC: Domain Message Authentication Reporting and Conformance SPF: Sender Policy Framework Addition of abbreviations Deletion List of the Abbreviations ICS: Industrial Control System SIS: Safety Instrumented System Controls in domain 5 moved to the OTCC (Operational Technology Cybersecurity Controls) Essential Cybersecurity Controls ﻣﻘﻴﺪ- ﺪﻣ
Frequently asked questions
What is NCA ECC-2:2024?
The Essential Cybersecurity Controls are Saudi Arabia's national cybersecurity baseline, issued by the National Cybersecurity Authority. ECC-2:2024 is the current edition, organised across five main domains: Cybersecurity Governance, Cybersecurity Defence, Cybersecurity Resilience, Third-Party and Cloud Computing Cybersecurity, and Industrial Control Systems Cybersecurity.
How many controls are in NCA ECC-2, and how are they organised?
The five main domains break down into 28 subdomains. 786 Cyber's catalogue tracks 109 assessable controls across them, each mapped to the canonical control model so work you evidence for ECC-2 also counts toward the other frameworks that share those controls. The National Cybersecurity Authority's own publication remains the source of record for the control set.
Who must comply with NCA ECC-2?
It is mandatory for Saudi government bodies — ministries, authorities and their affiliates, including entities established outside the Kingdom — and for private operators of Critical National Infrastructure. Many Saudi enterprises also adopt it voluntarily because it is the national baseline, and suppliers selling into government or CNI are increasingly asked to demonstrate alignment.
Is NCA ECC-2 mandatory, or is it guidance?
Mandatory for in-scope entities. It is a national directive rather than a voluntary standard, and the National Cybersecurity Authority oversees compliance on an ongoing basis rather than as a one-off exercise.
What changed between ECC-1:2018 and ECC-2:2024?
ECC-2:2024 is the National Cybersecurity Authority's update to the original 2018 controls. The five-domain structure carries over, but the control set itself was revised. Practically: if you were assessed against ECC-1, plan a re-baseline against the 2024 control set rather than assuming your existing evidence maps across one-to-one.
Does NCA ECC-2 apply to Saudi entities operating outside the Kingdom?
Yes — the scope covers government bodies and their affiliates including entities established outside Saudi Arabia. If you are part of an in-scope Saudi organisation, geography does not put you outside the requirement.
How does NCA ECC-2 relate to SAMA CSF?
They overlap heavily for Saudi financial institutions, which are typically in scope for both. 786 Cyber maps the shared controls through one canonical model, so a control you implement and evidence once is credited to both frameworks rather than assessed twice. See the SAMA CSF page for that framework in detail.
Where can I get the official ECC-2:2024 document?
From the National Cybersecurity Authority directly, at nca.gov.sa. 786 Cyber tracks the control set so you can assess against it, but the authority's own publication is the authoritative text.
Related frameworks
Ready to assess against NCA ECC-2?
Start free trial →