Plenty of Saudi organisations already run a NIST CSF 2.0 programme, usually because a parent company or an international customer asked for one. The question that follows is whether that work counts towards NCA compliance, or whether it has to be done again.
Most of it counts. A specific and predictable part of it does not, and that part is where organisations fail reviews.
01
The two frameworks are built differently
NIST CSF 2.0 is a voluntary framework organised into six functions: Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in the 2.0 release in 2024, which matters here because it brought CSF closer in shape to the NCA's structure. It describes outcomes rather than prescribing implementation, and it is deliberately non-auditable.
The NCA frameworks are mandatory and prescriptive. ECC-2:2024 covers 4 domains, 28 subdomains and 108 main controls for government, public sector and critical national infrastructure. NCNICC-1:2025, published January 2026, covers 3 components for private sector entities that are not CNI: 65 controls for large entities, 26 mandatory for SMEs.
The practical difference: CSF tells you what outcome to achieve, the NCA tells you what to have in place and expects evidence of it.
02
Where the frameworks line up
| NIST CSF 2.0 function | Maps to NCA | Reusable evidence |
|---|---|---|
| Govern | Cybersecurity Governance | Policy set, roles and responsibilities, risk register, board reporting |
| Identify | Cybersecurity Governance and Defence | Asset inventory, risk assessments, third-party register |
| Protect | Cybersecurity Defence | Access control, MFA, hardening baselines, awareness training, encryption |
| Detect | Cybersecurity Defence | Logging, monitoring, alerting, detection coverage |
| Respond | Cybersecurity Defence, Resilience in ECC | Incident response plan, exercise records, escalation paths |
| Recover | Cybersecurity Resilience in ECC | Backup, restore testing, continuity plans |
NIST CSF 2.0 function
Govern
Maps to NCA
Cybersecurity Governance
Reusable evidence
Policy set, roles and responsibilities, risk register, board reporting
NIST CSF 2.0 function
Identify
Maps to NCA
Cybersecurity Governance and Defence
Reusable evidence
Asset inventory, risk assessments, third-party register
NIST CSF 2.0 function
Protect
Maps to NCA
Cybersecurity Defence
Reusable evidence
Access control, MFA, hardening baselines, awareness training, encryption
NIST CSF 2.0 function
Detect
Maps to NCA
Cybersecurity Defence
Reusable evidence
Logging, monitoring, alerting, detection coverage
NIST CSF 2.0 function
Respond
Maps to NCA
Cybersecurity Defence, Resilience in ECC
Reusable evidence
Incident response plan, exercise records, escalation paths
NIST CSF 2.0 function
Recover
Maps to NCA
Cybersecurity Resilience in ECC
Reusable evidence
Backup, restore testing, continuity plans
If you have a mature CSF programme, the artefacts that satisfy Govern, Identify and Protect will carry most of the way. Your asset inventory, risk register, access control evidence and awareness records do not need rebuilding. They need remapping to the NCA control references so a reviewer can follow them.
One structural note: ECC-2:2024 has an explicit Cybersecurity Resilience domain, where CSF splits the same ground across Respond and Recover. NCNICC-1:2025 has no separate resilience component and folds backup, recovery and incident response into Cybersecurity Defence. Same substance, different filing.
03
Where CSF leaves you exposed
These are the gaps. None of them are covered by a CSF programme, an ISO 27001 certificate, or a SOC 2 report, because they are specific to the Kingdom.
Haseen email alignment. The NCA operates a national email security platform, and alignment with it is an explicit requirement. There is no NIST or ISO equivalent to map from. Organisations that built to an international standard first almost always discover this late.
National Cryptographic Standards. CSF asks that data be protected with appropriate cryptography. The NCA specifies what is acceptable in Saudi Arabia. Compliant-by-CSF encryption can be non-compliant here.
NCA-licensed monitoring. Where security monitoring is outsourced, the arrangement may need to involve an NCA-licensed provider. CSF has nothing to say about the licensing status of your MDR vendor. This one catches organisations who signed with an international provider before checking.
Data residency and cross-border transfer. Driven by the PDPL rather than by the cybersecurity frameworks, but it lands in the same programme. SDAIA enforces it separately, and neither CSF nor the NCA controls discharge it.
Prescribed evidence. CSF is outcome-based, so a organisation can be genuinely secure and still fail a review by having no evidence in the form asked for. The NCA expects artefacts against control references.
04
How to run both without doing everything twice
Pick the mandatory framework as the system of record. Whichever NCA framework applies to you, ECC-2:2024 or NCNICC-1:2025, becomes the control library. CSF becomes a lens over it, not a parallel programme. Two control libraries means two sets of evidence and twice the maintenance.
Map once, and keep the map. Build a single matrix from your CSF subcategories to the applicable NCA controls. Every piece of evidence carries both references. The map is a maintained artefact, not a one-off migration exercise.
Close the Kingdom-specific gaps first. Haseen, cryptographic standards, monitoring provider licensing, and data residency. They are a short list, they are not covered by anything you already hold, and they are the ones a reviewer will find.
Keep CSF for maturity, use the NCA set for compliance. CSF tiers are a genuinely useful way to describe trajectory to a board. They are not what a Saudi reviewer is assessing.
05
Which NCA framework applies to you
Worth settling before any mapping work, because it determines the size of the target: ECC-2:2024 for government, public sector and CNI; NCNICC-1:2025 for private sector entities that are not CNI, with 65 controls for large entities and 26 mandatory for SMEs of 6 to 249 staff.
Getting this wrong is expensive in both directions. Scoping 108 controls when 26 were required wastes budget. Scoping 26 when you are contractually held to ECC leaves you exposed at the point a customer audits you.
06
Where to start
If you already run CSF, the fastest useful step is a gap assessment against the applicable NCA control set, using your existing evidence. It usually shows a high proportion already satisfied and a short, specific list of Kingdom-specific gaps.
Allo Technologies runs cross-framework assessments for Saudi organisations, mapping existing NIST CSF, ISO 27001 and SOC 2 work onto the applicable NCA controls so the same evidence serves both.
07
References
National Institute of Standards and Technology. Cybersecurity Framework 2.0. National Cybersecurity Authority. Essential Cybersecurity Controls (ECC-2:2024). National Cybersecurity Authority. Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities (NCNICC-1:2025). Saudi Data and Artificial Intelligence Authority. Personal Data Protection Law (PDPL).
Need Expert Guidance?
Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.
Schedule a ConsultationAllo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.
Share this article
Related Reading
More insights from the Allo Technologies practice
NCA ECC or NCNICC: Which Framework Applies to You
Most Saudi private companies are being told to comply with the wrong NCA framework. ECC-2:2024 is for government and CNI; NCNICC-1:2025 is for everyone else.
Read moreNCNICC-1:2025: The 26 Controls Saudi SMBs Must Meet
If your Saudi company has 6 to 249 staff, NCNICC-1:2025 makes 26 controls mandatory. What each one asks for, the evidence that satisfies it, and the order to do them in.
Read moreSAMA vs. NCA: Navigating Saudi Cyber Compliance
Saudi businesses often struggle differentiating SAMA CSF and NCA ECC compliance.
Read moreTalk to an Expert
Get personalized guidance from our senior security and compliance practitioners