Back to Insights
Compliance

SAMA CSF vs NCA ECC: A Side-by-Side Compliance Guide

Compare SAMA Cybersecurity Framework with NCA ECC 2:2024 control by control. Dual-compliance strategy for Saudi banks, insurers, and fintechs.

By Al Rashdan
12 min read
#SAMA CSF#NCA ECC#dual compliance#Saudi banking cybersecurity

Banks, insurers, and licensed fintechs in Saudi Arabia answer to two regulators on cybersecurity: SAMA (Cybersecurity Framework v1.0) and the NCA (ECC 2:2024). The frameworks overlap heavily but are not identical. A single integrated control set, mapped once, can satisfy both.

01

Origins and intent

  • SAMA CSF, issued 2017, mandatory for all SAMA-regulated entities. Maturity-based (levels 1–5).
  • NCA ECC 2:2024, issued 2018, refreshed 2024. Compliance-based (implemented or not).

02

Structural comparison

Dimension

Domains

SAMA CSF

4 (Leadership, Risk, Operations, Third-Party)

NCA ECC 2:2024

4 (Governance, Defence, Resilience, Third-Party/Cloud)

Dimension

Subdomains

SAMA CSF

30+

NCA ECC 2:2024

29

Dimension

Assessment model

SAMA CSF

Maturity 1–5

NCA ECC 2:2024

Implemented / Not Implemented

Dimension

Self-assessment cadence

SAMA CSF

Annual to SAMA

NCA ECC 2:2024

Annual internal, periodic NCA review

Dimension

Audit model

SAMA CSF

Independent assurance

NCA ECC 2:2024

Internal + external + NCA review

03

Where they align

Roughly 80% of controls overlap in spirit. Both require: board accountability, risk methodology, asset inventory, IAM with MFA, vulnerability and patch management, SOC monitoring, incident response, DR, and third-party assurance.

04

Where they diverge

01

Maturity expectation**, SAMA expects level 3 minimum (defined and measured). NCA expects implementation, not maturity.

02

Cybersecurity insurance**

explicit under SAMA; not required under ECC.
03

Customer protection**

SAMA includes anti-fraud and customer-facing controls outside ECC scope.
04

Cloud**

NCA ECC has stricter data residency expectations for government and CNI scope.

05

The dual-compliance playbook

1

Adopt one control library

typically NCA ECC plus SAMA-specific deltas.

2

Map every control to both frameworks in a single GRC tool.

3

Set the higher bar as the target

usually SAMA maturity level 3.

4

Run one annual self-assessment producing two regulator-ready reports.

5

Plan one external assurance per year covering both scopes.

06

Common audit gaps

01

Risk methodology exists but ratings are inconsistent across business units.

02

SIEM coverage stops at perimeter; cloud and SaaS not fully ingested.

03

Third-party risk programme covers IT vendors but misses fintech partners.

04

Incident response tested only at the SOC tier

board and crisis comms untested.

Need Expert Guidance?

Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.

Schedule a Consultation

Allo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.

Frequently asked questions

Find answers to common questions about our services

Share this article

Related Reading

More insights from the Allo Technologies practice

Compliance

SAMA vs. NCA: Navigating Saudi Cyber Compliance

Saudi businesses often struggle differentiating SAMA CSF and NCA ECC compliance.

Read more
Compliance

NIST CSF 2.0 Mapped to NCA Requirements

Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.

Read more
Compliance

Which NCA Framework Applies to You: The Complete Map

The NCA publishes at least eight sets of controls. Most organisations need one or two. A decision path for ruling out the rest quickly.

Read more

Talk to an Expert

Get personalized guidance from our senior security and compliance practitioners

By submitting, you consent to Allo Technologies using these details to arrange your consultation and follow up about it. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

0%