The National Cybersecurity Authority published ECC 2:2024 as a refresh of the original 2018 controls. Every Saudi government entity, critical national infrastructure operator, and most regulated private organizations must comply. This checklist walks every domain and explains what auditors actually look for.
01
Structure at a glance
- 4 main domains: Cybersecurity Governance, Cybersecurity Defence, Cybersecurity Resilience, Third-Party and Cloud Computing Cybersecurity.
- 28 subdomains
- 108 main controls with sub-controls underneath
02
Domain 1: Cybersecurity Governance
1-1 Strategy**
1-2 Management**
1-3 Policies and Procedures**
1-4 Roles and Responsibilities**
1-5 Risk Management**
1-6 Cybersecurity in Project Management**
1-7 Compliance**
1-8 Periodic Review and Audit**
1-9 Cybersecurity in HR**
1-10 Cybersecurity Awareness and Training**
03
Domain 2: Cybersecurity Defence
2-1 Asset Management**
2-2 Identity and Access Management**
2-3 Information System and Processing Facilities Protection**
2-4 Email Protection**
2-5 Network Security Management**
2-6 Mobile Devices Security**
2-7 Data and Information Protection**
2-8 Cryptography**
2-9 Backup and Recovery**
2-10 Vulnerability Management**
2-11 Penetration Testing**
2-12 Cybersecurity Event Logs and Monitoring Management**
2-13 Cybersecurity Incident and Threat Management**
2-14 Physical Security**
2-15 Web Application Security**
04
Domain 3: Cybersecurity Resilience
- 3-1 Cybersecurity Resilience Aspects of Business Continuity Management (BCM): BIA, recovery strategies, tested DR.
05
Domain 4: Third-Party and Cloud Computing Cybersecurity
- 4-1 Third-Party Cybersecurity: vendor risk assessments, contractual clauses, ongoing monitoring.
- 4-2 Cloud Computing and Hosting Cybersecurity: data residency, CSP assurance, shared responsibility documented.
06
Evidence auditors actually request
Board minutes approving the strategy and policy
Risk register with treatment status
Asset inventory tied to classification
SIEM use-case catalogue and incident metrics
Last penetration test report and remediation tracker
BCM/DR test results from the last 12 months
Third-party risk register with refresh dates
07
Where SMBs typically fail
Mid-market organizations consistently struggle with: continuous monitoring (no SIEM), formal risk management (spreadsheets without methodology), and third-party assurance (no programme at all). Address these three first and you remove most of the audit risk.
Need Expert Guidance?
Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.
Schedule a ConsultationAllo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.
Frequently asked questions
Find answers to common questions about our services
Share this article
Related Reading
More insights from the Allo Technologies practice
AI Governance ROI: Business Case for Executives
AI governance investments yield measurable returns through risk reduction, market access, and competitive advantage. Build your business case here.
Read moreSAMA vs. NCA: Navigating Saudi Cyber Compliance
Saudi businesses often struggle differentiating SAMA CSF and NCA ECC compliance.
Read moreNIST CSF 2.0 Mapped to NCA Requirements
Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.
Read moreTalk to an Expert
Get personalized guidance from our senior security and compliance practitioners