Back to Insights
Compliance

Which NCA Framework Applies to You: The Complete Map

ECC, NCNICC, CSCC, CCC, DCC, OTCC, TCC and OSMACC: what each actually applies to, and a decision path to find your baseline in under five minutes.

By Al Rashdan
7 min read
#NCA frameworks#NCA ECC scope#NCNICC-1:2025#CCC-1:2020#DCC-1:2022#CSCC#OTCC#Saudi cybersecurity compliance

The NCA publishes at least eight sets of cybersecurity controls. Most Saudi organisations need one or two of them. Working out which is harder than it should be, because the scope trigger for each is buried in its own document and the abbreviations all look alike.

This is the map. The useful part is not the list, it is ruling things out quickly.

01

Start here: the two that decide most cases

ECC-2:2024, the Essential Cybersecurity Controls. 4 domains, 28 subdomains, 108 main controls and 92 sub-controls. Applies to government entities, public-sector bodies, and operators of critical national infrastructure. Private companies are pulled in indirectly, through government tenders, through contracts with regulated entities, or where their systems touch public services.

The NCA states the scope in its own words: "These controls are applicable to government organizations in the Kingdom of Saudi Arabia (including ministries, authorities, establishments, and others) and their companies and entities, as well as private sector organizations owning, operating, or hosting Critical National Infrastructures (CNIs)."

Where the wrong numbers come from. You will see ECC described as 114 controls across five domains. That was ECC-1:2018. ECC-2:2024 restructured to four domains and 108 main controls, moving industrial control systems out to the separate OTCC framework. The NCA's implementation guide (GECC-1:2023) still describes the ECC-1 structure, because it predates the 2024 revision, which is why the older figures remain in circulation. If a document quotes 114 controls or five domains, it is describing the superseded version.

NCNICC-1:2025, the Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities. Published January 2026. Applies to private sector organisations that are not CNI, which is most companies in the Kingdom. 3 components. Large entities (more than 250 staff or over SAR 200 million revenue) implement 65 controls across 22 sub-components. SMEs (6 to 249 staff, or SAR 3 million to 200 million) have 26 mandatory controls across 13 sub-components, concentrated in Cybersecurity Defence.

If you are a private company and nobody has told you that you operate critical national infrastructure, NCNICC is almost certainly your baseline and ECC is almost certainly not. This is the single most common error we see, and it is expensive in both directions: scoping 108 controls when 26 were required wastes budget, and assuming you are out of scope entirely leaves you exposed.

02

The situational ones

These layer on top of your baseline when a specific condition is met. None of them replaces ECC or NCNICC.

CSCC-1:2019, Critical Systems Cybersecurity Controls. An extension of ECC for systems classified as critical under the NCA's methodology. The trigger is the classification of the system, not the size of your organisation. If a system of yours has been designated critical, CSCC applies to that system in addition to your baseline.

CCC-1:2020, Cloud Cybersecurity Controls. This one is widely misdescribed as a CNI framework. It applies to both sides of a cloud arrangement:

  • Cloud Service Providers. Any provider, local or international, delivering cloud services within scope. The NCA explicitly excludes providers serving only individuals or only non-CNI private-sector organisations.
  • Cloud Service Tenants. Saudi government organisations, plus private organisations operating CNI, that use or plan to use cloud services.

So a private SaaS company selling only to ordinary Saudi businesses is outside CCC by the explicit exclusion. The same company selling to a government department is not.

DCC-1:2022, Data Cybersecurity Controls. Scoped by entity type, not by whether you happen to classify data. It applies to government organisations, private operators of CNI, and, in a category that catches people out, consultancy firms working on high-sensitivity strategic projects. DCC contains a four-tier data classification model, but that model is content inside the framework, not the test for whether it applies to you. If you are an advisory firm working on sensitive government or CNI programmes, check this one properly rather than assuming it is for someone else.

OTCC-1:2022, Operational Technology Cybersecurity Controls. Industrial control systems in critical facilities operated by government organisations, and private organisations owning, operating or hosting CNI. This is where the ICS and OT controls moved when ECC restructured to four domains.

TCC, Telework Cybersecurity Controls. Remote and hybrid working: VPN, endpoint security, and secure file transfer. Relevant to organisations already inside NCA scope that support remote work.

OSMACC, Organisations' Social Media Accounts Cybersecurity Controls. Official organisational social media accounts: multi-factor authentication, monitoring, and staff awareness against social engineering and account takeover.

03

Not a control set: MSOC licensing

Worth separating clearly, because conflating the two is the most common confusion in this whole area.

The Regulatory Framework for Licensing the Provision of MSOC Services (RFMSOC) governs who may sell managed security operations centre services in the Kingdom. It is a licensing regime, not a control set. It has its own requirements, including minimum staffing of certified SOC analysts.

Licences come in two tiers. Tier 1 providers may serve all organisations including government and CNI. Tier 2 providers may serve all organisations except government and CNI operators.

Being ECC compliant does not make you licensed. Holding a licence does not discharge your own control obligations. If you are buying monitoring, the relevant question is whether your provider holds the right tier for what you are, and it is a fair question to ask directly.

04

A decision path

Work down this list and stop at the first line that describes you.
1

Government entity, public

sector body, or designated CNI operator?** ECC-2:2024 is your baseline. Add CSCC for any system classified critical, OTCC if you run industrial control systems, DCC for data, CCC if you consume cloud.

2

Private company, not CNI, more than 250 staff or over SAR 200 million revenue? NCNICC

1:2025 as a large entity: 65 controls.

3

Private company, not CNI, 6 to 249 staff or SAR 3 million to 200 million? NCNICC

1:2025 as an SME: 26 mandatory controls.

4

Selling cloud services? Check CCC. You are outside it if your customers are only individuals or non

CNI private companies, and inside it the moment you serve government or CNI.

5

Advisory firm on high

sensitivity strategic projects?** Check DCC properly. This is the least-known scope trigger in the family.

6

Selling managed SOC services? RFMSOC licensing, on top of whichever baseline applies to you as an organisation.

05

Two things that trip people up

Frameworks layer, they do not substitute. CSCC, CCC, DCC and OTCC sit on top of a baseline. Being in scope for one of them does not remove the baseline obligation, and satisfying the baseline does not cover the situational set.

International certification does not map cleanly. ISO 27001:2022 and NIST CSF 2.0 are genuinely useful and most of the evidence is reusable, but neither says anything about Haseen email alignment or the National Cryptographic Standards, both of which are named in the Saudi frameworks. A certified organisation can still fail on the Kingdom-specific items.

06

Where to start

Settle scope before assessing anything. The cost of assessing against the wrong control set is the whole assessment.

If you want a quick read on where you stand, our free assessment tools score you against the relevant control set and email you the breakdown. If your situation involves more than one of the frameworks above, that is exactly the conversation to have with a practitioner rather than a checklist.

07

References

National Cybersecurity Authority. Essential Cybersecurity Controls (ECC-2:2024). Published at nca.gov.sa. National Cybersecurity Authority. Guide to Essential Cybersecurity Controls Implementation (GECC-1:2023). Note this guide documents the superseded ECC-1:2018 structure. National Cybersecurity Authority. Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities (NCNICC-1:2025). National Cybersecurity Authority. Critical Systems Cybersecurity Controls (CSCC-1:2019). National Cybersecurity Authority. Cloud Cybersecurity Controls (CCC-1:2020). National Cybersecurity Authority. Data Cybersecurity Controls (DCC-1:2022). National Cybersecurity Authority. Operational Technology Cybersecurity Controls (OTCC-1:2022). National Cybersecurity Authority. Telework Cybersecurity Controls (TCC). National Cybersecurity Authority. Organisations' Social Media Accounts Cybersecurity Controls (OSMACC). National Cybersecurity Authority. Regulatory Framework for Licensing the Provision of MSOC Services. Saudi Data and Artificial Intelligence Authority. Personal Data Protection Law (PDPL).

Need Expert Guidance?

Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.

Schedule a Consultation

Allo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.

Share this article

Related Reading

More insights from the Allo Technologies practice

Compliance

NCNICC-1:2025: The 26 Controls Saudi SMBs Must Meet

If your Saudi company has 6 to 249 staff, NCNICC-1:2025 makes 26 controls mandatory. What each one asks for, the evidence that satisfies it, and the order to do them in.

Read more
Compliance

NIST CSF 2.0 Mapped to NCA Requirements

Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.

Read more
Compliance

SAMA vs. NCA: Navigating Saudi Cyber Compliance

Saudi businesses often struggle differentiating SAMA CSF and NCA ECC compliance.

Read more

Talk to an Expert

Get personalized guidance from our senior security and compliance practitioners

By submitting, you consent to Allo Technologies using these details to arrange your consultation and follow up about it. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

0%