Back to Insights
Compliance

NIST CSF 2.0 Mapped to NCA Requirements

How NIST CSF 2.0 maps to NCA ECC-2:2024 and NCNICC-1:2025, which evidence you can reuse, and the Kingdom-specific gaps CSF and ISO 27001 never cover.

By Al Rashdan
5 min read
#NIST CSF 2.0#NCA ECC mapping#NCNICC-1:2025#cross-framework compliance#ISO 27001 Saudi

Plenty of Saudi organisations already run a NIST CSF 2.0 programme, usually because a parent company or an international customer asked for one. The question that follows is whether that work counts towards NCA compliance, or whether it has to be done again.

Most of it counts. A specific and predictable part of it does not, and that part is where organisations fail reviews.

01

The two frameworks are built differently

NIST CSF 2.0 is a voluntary framework organised into six functions: Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in the 2.0 release in 2024, which matters here because it brought CSF closer in shape to the NCA's structure. It describes outcomes rather than prescribing implementation, and it is deliberately non-auditable.

The NCA frameworks are mandatory and prescriptive. ECC-2:2024 covers 4 domains, 28 subdomains and 108 main controls for government, public sector and critical national infrastructure. NCNICC-1:2025, published January 2026, covers 3 components for private sector entities that are not CNI: 65 controls for large entities, 26 mandatory for SMEs.

The practical difference: CSF tells you what outcome to achieve, the NCA tells you what to have in place and expects evidence of it.

02

Where the frameworks line up

The mapping is cleaner than most people expect, because both are built on the same underlying security practice.

NIST CSF 2.0 function

Govern

Maps to NCA

Cybersecurity Governance

Reusable evidence

Policy set, roles and responsibilities, risk register, board reporting

NIST CSF 2.0 function

Identify

Maps to NCA

Cybersecurity Governance and Defence

Reusable evidence

Asset inventory, risk assessments, third-party register

NIST CSF 2.0 function

Protect

Maps to NCA

Cybersecurity Defence

Reusable evidence

Access control, MFA, hardening baselines, awareness training, encryption

NIST CSF 2.0 function

Detect

Maps to NCA

Cybersecurity Defence

Reusable evidence

Logging, monitoring, alerting, detection coverage

NIST CSF 2.0 function

Respond

Maps to NCA

Cybersecurity Defence, Resilience in ECC

Reusable evidence

Incident response plan, exercise records, escalation paths

NIST CSF 2.0 function

Recover

Maps to NCA

Cybersecurity Resilience in ECC

Reusable evidence

Backup, restore testing, continuity plans

If you have a mature CSF programme, the artefacts that satisfy Govern, Identify and Protect will carry most of the way. Your asset inventory, risk register, access control evidence and awareness records do not need rebuilding. They need remapping to the NCA control references so a reviewer can follow them.

One structural note: ECC-2:2024 has an explicit Cybersecurity Resilience domain, where CSF splits the same ground across Respond and Recover. NCNICC-1:2025 has no separate resilience component and folds backup, recovery and incident response into Cybersecurity Defence. Same substance, different filing.

03

Where CSF leaves you exposed

These are the gaps. None of them are covered by a CSF programme, an ISO 27001 certificate, or a SOC 2 report, because they are specific to the Kingdom.

Haseen email alignment. The NCA operates a national email security platform, and alignment with it is an explicit requirement. There is no NIST or ISO equivalent to map from. Organisations that built to an international standard first almost always discover this late.

National Cryptographic Standards. CSF asks that data be protected with appropriate cryptography. The NCA specifies what is acceptable in Saudi Arabia. Compliant-by-CSF encryption can be non-compliant here.

NCA-licensed monitoring. Where security monitoring is outsourced, the arrangement may need to involve an NCA-licensed provider. CSF has nothing to say about the licensing status of your MDR vendor. This one catches organisations who signed with an international provider before checking.

Data residency and cross-border transfer. Driven by the PDPL rather than by the cybersecurity frameworks, but it lands in the same programme. SDAIA enforces it separately, and neither CSF nor the NCA controls discharge it.

Prescribed evidence. CSF is outcome-based, so a organisation can be genuinely secure and still fail a review by having no evidence in the form asked for. The NCA expects artefacts against control references.

04

How to run both without doing everything twice

Pick the mandatory framework as the system of record. Whichever NCA framework applies to you, ECC-2:2024 or NCNICC-1:2025, becomes the control library. CSF becomes a lens over it, not a parallel programme. Two control libraries means two sets of evidence and twice the maintenance.

Map once, and keep the map. Build a single matrix from your CSF subcategories to the applicable NCA controls. Every piece of evidence carries both references. The map is a maintained artefact, not a one-off migration exercise.

Close the Kingdom-specific gaps first. Haseen, cryptographic standards, monitoring provider licensing, and data residency. They are a short list, they are not covered by anything you already hold, and they are the ones a reviewer will find.

Keep CSF for maturity, use the NCA set for compliance. CSF tiers are a genuinely useful way to describe trajectory to a board. They are not what a Saudi reviewer is assessing.

05

Which NCA framework applies to you

Worth settling before any mapping work, because it determines the size of the target: ECC-2:2024 for government, public sector and CNI; NCNICC-1:2025 for private sector entities that are not CNI, with 65 controls for large entities and 26 mandatory for SMEs of 6 to 249 staff.

Getting this wrong is expensive in both directions. Scoping 108 controls when 26 were required wastes budget. Scoping 26 when you are contractually held to ECC leaves you exposed at the point a customer audits you.

06

Where to start

If you already run CSF, the fastest useful step is a gap assessment against the applicable NCA control set, using your existing evidence. It usually shows a high proportion already satisfied and a short, specific list of Kingdom-specific gaps.

Allo Technologies runs cross-framework assessments for Saudi organisations, mapping existing NIST CSF, ISO 27001 and SOC 2 work onto the applicable NCA controls so the same evidence serves both.

07

References

National Institute of Standards and Technology. Cybersecurity Framework 2.0. National Cybersecurity Authority. Essential Cybersecurity Controls (ECC-2:2024). National Cybersecurity Authority. Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities (NCNICC-1:2025). Saudi Data and Artificial Intelligence Authority. Personal Data Protection Law (PDPL).

Need Expert Guidance?

Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.

Schedule a Consultation

Allo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.

Share this article

Related Reading

More insights from the Allo Technologies practice

Compliance

NCA ECC or NCNICC: Which Framework Applies to You

Most Saudi private companies are being told to comply with the wrong NCA framework. ECC-2:2024 is for government and CNI; NCNICC-1:2025 is for everyone else.

Read more
Compliance

NCNICC-1:2025: The 26 Controls Saudi SMBs Must Meet

If your Saudi company has 6 to 249 staff, NCNICC-1:2025 makes 26 controls mandatory. What each one asks for, the evidence that satisfies it, and the order to do them in.

Read more
Compliance

SAMA vs. NCA: Navigating Saudi Cyber Compliance

Saudi businesses often struggle differentiating SAMA CSF and NCA ECC compliance.

Read more

Talk to an Expert

Get personalized guidance from our senior security and compliance practitioners

By submitting, you consent to Allo Technologies using these details to arrange your consultation and follow up about it. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

0%