All services

NCA ECC Compliance

Navigate Saudi Arabia's Essential Cybersecurity Controls with confidence: 108 controls, 4 domains, one clear path to compliance.

What is NCA ECC-2:2024?

The Essential Cybersecurity Controls (ECC) is Saudi Arabia's mandatory cybersecurity framework issued by the National Cybersecurity Authority (NCA). Version 2:2024 restructures the original 2018 framework into 108 main controls and 92 subcontrols across 4 domains and 28 subdomains, spanning governance, defence, resilience, and third-party and cloud computing cybersecurity.

Compliance is not optional: NCA conducts periodic assessments of government entities, critical infrastructure operators, and designated private-sector organisations. Non-compliance carries regulatory penalties and can restrict an organisation's ability to operate.

4 ECC domains, 108 controls

Cybersecurity Governance

Domain 1

Strategy, policies, roles and responsibilities, risk management, compliance, audit, human resources, and awareness and training.

Cybersecurity Defence

Domain 2

Asset management, identity and access control, system and network security, application security, cryptography, and vulnerability and patch management.

Cybersecurity Resilience

Domain 3

Business continuity and disaster recovery aspects of cybersecurity, and incident and threat management.

Third-Party & Cloud Computing Cybersecurity

Domain 4

Supply chain and outsourcing controls, and cybersecurity requirements for cloud services and hosting.

Our 6-phase approach

1

Discovery & Scoping

2 weeks

Inventory assets, identify applicable ECC controls, and define assessment boundaries.

2

Gap Assessment

3–4 weeks

Evaluate current controls against all 108 ECC main controls with a risk-rated gap report.

3

Remediation Roadmap

1 week

Prioritised action plan with quick wins, resource estimates, and timeline.

4

Control Implementation

6–12 weeks

Deploy technical controls, draft policies, and configure monitoring tools.

5

Evidence & Documentation

2–3 weeks

Build evidence packages, control matrices, and prepare for NCA assessment.

6

Mock Assessment & Support

2 weeks

Simulate NCA assessment, remediate findings, and provide on-site support during official review.

Common compliance challenges

Mapping 108 controls to existing security posture without duplicating effort
Meeting tight NCA assessment deadlines with limited internal resources
Aligning ECC with overlapping frameworks (SAMA CSF, ISO 27001)
Demonstrating compliance for cloud-hosted workloads under NCA CCC
Maintaining continuous compliance between assessment cycles

Ready for your NCA assessment?

Start with a free compliance gap analysis to understand where you stand.

Related services

SAMA Cybersecurity Framework

Compliance for Saudi financial institutions.

Explore

ISO 27001 Certification

International ISMS certification.

Explore

NCA CCC Cloud Compliance

Cloud-specific cybersecurity controls.

Explore

NCA ECC Compliance FAQ

Find answers to common questions about our services