Back to Insights
Compliance

NCA ECC or NCNICC: Which Framework Applies to You

ECC-2:2024 covers government and CNI. Private companies that are not CNI fall under NCNICC-1:2025: 65 controls for large entities, 26 for SMEs. Which is yours.

By Al Rashdan
6 min read
#NCNICC-1:2025#NCA ECC 2:2024#Saudi cybersecurity compliance#NCNICC SME controls#NCA framework scope

Many Saudi private companies preparing for NCA ECC 2:2024 have a different obligation. It sits under NCNICC-1:2025, a framework the NCA published in January 2026.

If you run a private company in the Kingdom that is not critical national infrastructure, the controls that apply to you are NCNICC-1:2025, not ECC-2:2024. Getting this wrong wastes budget on the wrong control set and leaves the actual requirement unmet.

01

The two frameworks, and who each one is for

The National Cybersecurity Authority publishes several control sets. Two matter for this question.

ECC-2:2024, the Essential Cybersecurity Controls. Published in 2024 as a refresh of ECC-1:2018, it restructures the framework into 4 domains, 28 subdomains, 108 main controls and 92 sub-controls. It applies to government entities, public-sector bodies, and operators of critical national infrastructure. Private companies come into scope indirectly: when they tender for government work, when they act as a supplier to a regulated entity, or when their systems touch public services.

The NCA states the scope in its own words: "These controls are applicable to government organizations in the Kingdom of Saudi Arabia (including ministries, authorities, establishments, and others) and their companies and entities, as well as private sector organizations owning, operating, or hosting Critical National Infrastructures (CNIs)."

Where the wrong numbers come from. You will see ECC described as 114 controls across five domains. That was ECC-1:2018. ECC-2:2024 restructured to four domains and 108 main controls, moving industrial control systems out to the separate OTCC framework. The NCA's implementation guide (GECC-1:2023) still describes the ECC-1 structure, because it predates the 2024 revision, which is why the older figures remain in circulation. If a document quotes 114 controls or five domains, it is describing the superseded version.

NCNICC-1:2025, the Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities. Published by the NCA in January 2026, this is the framework built for everyone else: private sector organisations in Saudi Arabia that are not CNI. If your company has never been told it is critical national infrastructure, this is almost certainly your obligation.

The distinction matters commercially. ECC-2:2024 is a 108-control programme designed for government-grade environments. NCNICC-1:2025 is calibrated to the size and risk of ordinary businesses, and for most companies it is a materially smaller and more achievable scope.

02

How NCNICC classifies your organisation

NCNICC-1:2025 sorts entities into two classes, and the class determines how many controls are mandatory.

Large entity

Threshold

Small and medium entity

More than 250 full-time staff, or annual revenue above SAR 200 million

6 to 249 full-time staff, or annual revenue of SAR 3 million to 200 million

Large entity

Sub-components

Small and medium entity

22

13

Large entity

Essential controls

Small and medium entity

65, all mandatory

26 mandatory, the remainder recommended

Class A is assessed against all three components. Class B is assessed against one, Cybersecurity Defence, covering 13 of its 15 sub-components. Governance and Third-Party and Cloud are recommended for Class B rather than mandatory. The three components are:

  • Cybersecurity Governance, covering policy, roles and responsibilities, risk management, awareness and audit.
  • Cybersecurity Defence, the operational and technical baseline: asset management, access control, network and endpoint hardening, vulnerability management, logging and monitoring, backup and recovery, incident response, and physical security.
  • Third-Party and Cloud Computing Cybersecurity, covering vendor contracts, cloud service configuration and data handling.

For a Class B entity the 26 mandatory controls sit entirely in Cybersecurity Defence. There is no mandatory policy set, risk methodology, internal audit or awareness programme at that tier. That is a deliberate design choice by the NCA: a 40-person company is not expected to build a governance function, but it is expected to have multi-factor authentication, patching and backups that work.

03

What NCNICC actually requires you to do

The framework names specific technical expectations rather than leaving them to interpretation. The ones that catch most organisations out:
01

Multi-factor authentication on remote access.** Not just for administrators. If staff reach systems from outside the office, that path needs a second factor.

02

Email security aligned to Haseen**, the NCA's national platform. This is a Saudi-specific requirement with no equivalent in ISO 27001 or NIST, and it is routinely missed by organisations that adopted an international framework first.

03

Alignment with the National Cryptographic Standards.** Using strong encryption is not sufficient on its own; the standards specify what is acceptable in the Kingdom.

04

Cybersecurity event logging and monitoring.** Logs have to be generated, retained, and actually watched. Where monitoring is outsourced, the arrangement may need to involve an NCA-licensed provider.

05

Vulnerability management and penetration testing.** Scanning on a defined cycle, with testing that produces evidence, and remediation that is tracked to closure.

06

Backup and recovery procedures** that have been tested, not merely configured.

07

Endpoint and network hardening**, and physical security for the environments that hold your systems.

04

The deadline question, answered honestly

Compliance dates for the NCA frameworks are worth taking from the control documents themselves, since secondary sources vary.

The controls bind entities the NCA notifies. The document applies them to non-CNI private entities in the Kingdom that are circulated to by the Authority, and states that Class A and Class B controls are binding on entities notified by the Authority, which may also impose additional controls where it decides they are needed. Entities outside scope are told to benefit from the controls as appropriate. So this is not automatically binding on every private company from publication day.

No compliance deadline is published, and the document sets out no penalty schedule of its own. It says compliance is assessed by the Authority through whatever mechanism it deems appropriate, under Article 10(3) of the NCA's statute. Separately, the NCA holds general enforcement powers under Royal Decree M/117 of 22 December 2024 including fines of up to SAR 25 million. Two things follow:

  1. Once notified, there is no stated grace period to point at.
  2. The absence of a deadline removes the date you would otherwise have organised around, which in practice means the first time many organisations discover their obligation is when someone asks for evidence.

The practical answer is to establish now whether you have been notified, and to know where you stand against the applicable set either way.

05

Which framework applies to you: a short decision path

You are a government entity, public-sector body, or designated critical national infrastructure. ECC-2:2024 applies. All 108 controls across 4 domains.

You are a private company, not CNI, with more than 250 staff or over SAR 200 million in revenue. NCNICC-1:2025 applies as a large entity. All 65 controls.

You are a private company, not CNI, with 6 to 249 staff or SAR 3 million to 200 million in revenue. NCNICC-1:2025 applies as an SME. 26 mandatory controls, concentrated in Cybersecurity Defence.

You are a private company that supplies government or a regulated entity. NCNICC-1:2025 is your baseline, but your contracts may separately impose ECC-aligned obligations. Read the contract, because the customer's requirement can exceed the regulator's.

You handle personal data, which is nearly everyone. The PDPL applies in parallel and is enforced separately by SDAIA. Neither NCA framework discharges it.

06

Common scoping pitfalls

Adopting ECC when NCNICC applies. The most expensive mistake in this list. You end up scoping 108 controls when 26 were mandatory, and you still miss the Saudi-specific items if you worked from an international template.

Assuming ISO 27001 covers it. ISO 27001:2022 is a strong foundation and much of the evidence is reusable, but it says nothing about Haseen or the National Cryptographic Standards. Certification does not equal NCA compliance.

Treating it as a documentation exercise. For SMEs the mandatory set is deliberately weighted towards technical controls. A folder of policies with no MFA, no tested backups and no monitoring will not survive a review.

Waiting for a deadline that is not coming. See above.

07

Where to start

Establish which framework and which class applies to you, then assess against that control set rather than a generic checklist. A structured gap assessment produces the prioritised remediation plan, and the evidence register that a review will ask for.

If your situation involves more than one NCA control set, the complete framework map covers CSCC, CCC, DCC, OTCC and the rest, including which apply to cloud providers and advisory firms.

Allo Technologies works with Saudi organisations on exactly this: determining scope, running the assessment, closing the gaps, and preparing the evidence. If you want to see roughly where you stand before speaking to anyone, our free assessment tools score you against the relevant control set and email you the breakdown.

08

References

National Cybersecurity Authority. Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities (NCNICC-1:2025), published January 2026. National Cybersecurity Authority. Essential Cybersecurity Controls (ECC-2:2024). Published at nca.gov.sa. National Cybersecurity Authority. Guide to Essential Cybersecurity Controls Implementation (GECC-1:2023). Note this guide documents the superseded ECC-1:2018 structure. Saudi Data and Artificial Intelligence Authority. Personal Data Protection Law (PDPL).

Need Expert Guidance?

Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.

Schedule a Consultation

Allo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.

Frequently asked questions

Find answers to common questions about our services

Share this article

Related Reading

More insights from the Allo Technologies practice

Compliance

NIST CSF 2.0 Mapped to NCA Requirements

Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.

Read more
Compliance

Which NCA Framework Applies to You: The Complete Map

The NCA publishes at least eight sets of controls. Most organisations need one or two. A decision path for ruling out the rest quickly.

Read more
Compliance

SAMA vs. NCA: Navigating Saudi Cyber Compliance

Saudi businesses often struggle differentiating SAMA CSF and NCA ECC compliance.

Read more

Talk to an Expert

Get personalized guidance from our senior security and compliance practitioners

By submitting, you consent to Allo Technologies using these details to arrange your consultation and follow up about it. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

0%