Back to Insights
NCA ECC

NCA ECC 2:2024 Compliance Checklist: All 108 Controls Explained

Complete NCA ECC 2:2024 compliance checklist for Saudi organizations. All four domains, 28 subdomains, and 108 controls with practical implementation guidance.

By Al Rashdan
18 min read
#NCA ECC 2:2024#ECC compliance Saudi#Essential Cybersecurity Controls#NCA checklist

The National Cybersecurity Authority published ECC 2:2024 as a refresh of the original 2018 controls. Every Saudi government entity, critical national infrastructure operator, and most regulated private organizations must comply. This checklist walks every domain and explains what auditors actually look for.

01

Structure at a glance

  • 4 main domains: Cybersecurity Governance, Cybersecurity Defence, Cybersecurity Resilience, Third-Party and Cloud Computing Cybersecurity.
  • 28 subdomains
  • 108 main controls with sub-controls underneath

02

Domain 1: Cybersecurity Governance

Foundational. Auditors start here because weak governance invalidates everything below.
01

1-1 Strategy**

board-approved cybersecurity strategy aligned with business objectives, reviewed annually.
02

1-2 Management**

appointed CISO reporting to the head of the organization (not the CIO).
03

1-3 Policies and Procedures**

full policy set covering all 28 subdomains, version-controlled and acknowledged by staff.
04

1-4 Roles and Responsibilities**

RACI matrix for cybersecurity functions.
05

1-5 Risk Management**

documented methodology, risk register, treatment plans with owners and dates.
06

1-6 Cybersecurity in Project Management**

security requirements baked into every project from initiation.
07

1-7 Compliance**

annual compliance review against ECC and other regulations.
08

1-8 Periodic Review and Audit**

internal audit at least annually, external audit per regulator schedule.
09

1-9 Cybersecurity in HR**

background checks, NDAs, training, joiner/mover/leaver workflows.
10

1-10 Cybersecurity Awareness and Training**

role-based, measured, refreshed.

03

Domain 2: Cybersecurity Defence

The largest domain. Most ECC findings concentrate here.
01

2-1 Asset Management**

complete inventory of information and technology assets, classified.
02

2-2 Identity and Access Management**

least privilege, MFA for all privileged and remote access, periodic reviews.
03

2-3 Information System and Processing Facilities Protection**

hardening baselines, EDR, patch management.
04

2-4 Email Protection**

anti-phishing, DMARC, attachment sandboxing.
05

2-5 Network Security Management**

segmentation, NGFW, IDS/IPS, secure remote access.
06

2-6 Mobile Devices Security**

MDM, encryption, remote wipe.
07

2-7 Data and Information Protection**

classification, DLP, encryption at rest and in transit.
08

2-8 Cryptography**

approved algorithms, key management lifecycle.
09

2-9 Backup and Recovery**

tested backups, offline copies, recovery time objectives.
10

2-10 Vulnerability Management**

scheduled scans, risk-based remediation SLAs.
11

2-11 Penetration Testing**

at least annually, plus after major changes.
12

2-12 Cybersecurity Event Logs and Monitoring Management**

centralized SIEM, 12-month minimum retention.
13

2-13 Cybersecurity Incident and Threat Management**

IR plan, playbooks, tested at least annually.
14

2-14 Physical Security**

datacentre and office controls.
15

2-15 Web Application Security**

OWASP ASVS-aligned, WAF, regular testing.

04

Domain 3: Cybersecurity Resilience

  • 3-1 Cybersecurity Resilience Aspects of Business Continuity Management (BCM): BIA, recovery strategies, tested DR.

05

Domain 4: Third-Party and Cloud Computing Cybersecurity

  • 4-1 Third-Party Cybersecurity: vendor risk assessments, contractual clauses, ongoing monitoring.
  • 4-2 Cloud Computing and Hosting Cybersecurity: data residency, CSP assurance, shared responsibility documented.

06

Evidence auditors actually request

From dozens of Saudi assessments, the most-requested evidence:
01

Board minutes approving the strategy and policy

02

Risk register with treatment status

03

Asset inventory tied to classification

04

SIEM use-case catalogue and incident metrics

05

Last penetration test report and remediation tracker

06

BCM/DR test results from the last 12 months

07

Third-party risk register with refresh dates

07

Where SMBs typically fail

Mid-market organizations consistently struggle with: continuous monitoring (no SIEM), formal risk management (spreadsheets without methodology), and third-party assurance (no programme at all). Address these three first and you remove most of the audit risk.

Request a free NCA ECC gap assessment →

Need Expert Guidance?

Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.

Schedule a Consultation

Allo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.

Frequently asked questions

Find answers to common questions about our services

Share this article

Related Reading

More insights from the Allo Technologies practice

AI Governance

AI Governance ROI: Business Case for Executives

AI governance investments yield measurable returns through risk reduction, market access, and competitive advantage. Build your business case here.

Read more
Compliance

SAMA vs. NCA: Navigating Saudi Cyber Compliance

Saudi businesses often struggle differentiating SAMA CSF and NCA ECC compliance.

Read more
Compliance

NIST CSF 2.0 Mapped to NCA Requirements

Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.

Read more

Talk to an Expert

Get personalized guidance from our senior security and compliance practitioners

By submitting, you consent to Allo Technologies using these details to arrange your consultation and follow up about it. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

0%