NCA OTCC Compliance in Saudi Arabia

Helping OT and ICS operators across the Kingdom meet the National Cybersecurity Authority Operational Technology Cybersecurity Controls, from gap assessment to audit-ready evidence.

Book Your Free Consultation Explore Our Services

The National Cybersecurity Authority Operational Technology Cybersecurity Controls, known as NCA OTCC, are now a mandatory cybersecurity requirement for critical infrastructure operators in Saudi Arabia. If your organization owns, operates, or hosts industrial control systems that are part of the Kingdom's critical national infrastructure, OTCC compliance is not optional, and the cost of falling short is significant. Arista Cyber helps Saudi operators achieve and demonstrate NCA OTCC compliance across their OT and ICS environments, combining deep operational technology engineering with a clear, audit-ready path through the controls. As a specialist OT cybersecurity firm, we bridge the gap between what the regulation requires and what actually works on a live plant floor.

What Is NCA OTCC?

The Operational Technology Cybersecurity Controls, OTCC-1:2022, were issued by Saudi Arabia's National Cybersecurity Authority to set the minimum cybersecurity requirements for protecting industrial control systems in the Kingdom. They are an extension of the NCA's Essential Cybersecurity Controls (ECC), applying that baseline specifically to the operational technology environment. Where the ECC covers cybersecurity broadly, OTCC focuses on the ICS and OT systems that run critical processes. You can see the official controls on the NCA OTCC page.

OTCC exists because operational technology carries risks that general IT security does not fully address. A cyber incident in an OT environment can stop production, damage equipment, cause environmental harm, or endanger people. The NCA introduced OTCC to raise the cybersecurity level of these systems across the Kingdom and to give operators a clear, enforceable standard to meet.

Who Must Comply With NCA OTCC?

OTCC applies to public and private sector organizations that own, operate, or host critical national infrastructure in Saudi Arabia, and to the industrial control systems within those environments. In practice, that means operators across the Kingdom's most important sectors:

If your ICS environment is considered critical to national operations, OTCC compliance is a mandatory obligation, not a voluntary best practice. Importantly, the requirement can extend to organizations that host or operate this infrastructure even from outside the Kingdom, so international operators with Saudi critical infrastructure are also in scope.

Why OTCC Compliance Matters Now

OTCC is enforced, and the NCA has the authority to issue penalties for non-compliance. Beyond the regulatory exposure, OTCC compliance protects the operations that your business and, in many cases, the Kingdom's essential services depend on. The reasons to act are both regulatory and operational.

The Cost of Non-Compliance

Penalties for OTCC non-compliance can reach up to 25 million Saudi riyals, roughly 6.67 million US dollars. For critical infrastructure operators, that places OTCC firmly at board level. The exposure is not only financial: a serious OT incident that compliance would have prevented can halt production and damage an operator's standing with regulators and customers.

The Four Domains of NCA OTCC

The OTCC framework is organized into four main domains, covering strategy, people, process, and technology. In total, it comprises four domains, twenty-three subdomains, forty-seven main controls, and one hundred and twenty-two sub-controls. Understanding how your OT environment maps against these four domains is the starting point for compliance.

OTCC Domain What it covers
1. Cybersecurity Governance Policies and procedures, roles and responsibilities, OT cybersecurity risk management, change management, review and audit, and awareness and training.
2. Cybersecurity Defense Asset management, identity and access management, network security and segmentation, system and facility protection, and the core technical controls that protect OT systems day to day.
3. Cybersecurity Resilience The ability to withstand, respond to, and recover from cybersecurity incidents affecting OT, including continuity of critical operations.
4. Third-Party Cybersecurity Managing the cybersecurity risks introduced by vendors, suppliers, and service providers with access to OT systems.

How Arista Cyber Helps You Achieve OTCC Compliance

1. OTCC Gap Assessment

We begin with a free initial OT assessment, then a detailed gap assessment of your current OT environment against all four OTCC domains and their controls. This tells you exactly where you stand, which controls you already meet, and where the gaps are, prioritised by risk.

2. OT Asset Inventory and Visibility

You cannot secure or evidence what you have not identified. Using passive, non-disruptive techniques, we build a complete inventory of your OT and ICS assets, which underpins the asset management and defense controls OTCC requires.

3. Remediation and Control Implementation

We design and help implement the technical and procedural controls needed to close your gaps, including network segmentation, identity and access management, secure remote access, and monitoring, all engineered for a live OT environment rather than imposed from an IT playbook.

4. Audit-Ready Documentation

We produce the documentation and evidence you need to demonstrate compliance to the NCA, so that when an assessment comes, your controls are not only in place but provable.

OTCC, ECC, and How They Fit Together

A common question is how OTCC relates to the NCA's Essential Cybersecurity Controls. The ECC is the Kingdom's baseline cybersecurity standard, applying broadly across an organization's information and technology assets. OTCC is an extension of the ECC, built specifically for the operational technology environment. Compliance with the ECC baseline supports and underpins OTCC compliance, so the two work together rather than in isolation. Arista Cyber helps operators understand where their ECC posture ends and their OTCC-specific OT obligations begin, so effort is not duplicated and nothing critical is missed.

The Safety and Security Connection

OTCC compliance matters most where OT protects people and processes, and nowhere is that clearer than in Saudi Arabia, the country where the world first saw malware built to defeat a safety instrumented system. That attack proved that a cyber compromise of an OT safety system is not only a security failure but a safety failure. Arista Cyber is one of the few firms that treats OT cybersecurity and functional safety as connected disciplines. If your OTCC scope includes safety instrumented systems, our functional safety services in Saudi Arabia complement this work, so your safety systems are protected against both failure and attack.

Why Choose Arista Cyber for NCA OTCC Compliance

OT Engineering Depth

We are an operational technology cybersecurity specialist, not a general IT compliance firm. Our work is delivered by people who understand ICS, SCADA, and safety systems, and who know how to implement controls without disrupting live production.

Full Compliance Path

We take you from gap assessment through remediation to audit-ready evidence, rather than handing you a report and leaving the hard part to you.

Safety and Security Together

Uniquely, we bring functional safety expertise alongside OT cybersecurity, which matters wherever OTCC scope touches safety instrumented systems.

Free Initial Assessment

We start with a free OT assessment, so you can understand your OTCC position and the path forward before committing to a full engagement.

Need to achieve NCA OTCC compliance?

Start with a free OT assessment and a clear view of where you stand against all four OTCC domains.

Book Your Free OT Assessment

Frequently Asked Questions

NCA OTCC stands for the National Cybersecurity Authority Operational Technology Cybersecurity Controls, issued as OTCC-1:2022. It is Saudi Arabia's mandatory cybersecurity standard for protecting industrial control systems that are part of critical national infrastructure, and it is an extension of the NCA Essential Cybersecurity Controls.

Yes. For organizations that own, operate, or host critical national infrastructure and its industrial control systems in Saudi Arabia, OTCC compliance is a mandatory regulatory requirement, not a voluntary best practice.

Penalties for non-compliance can reach up to 25 million Saudi riyals, approximately 6.67 million US dollars, which places OTCC compliance at board level for critical infrastructure operators.

The four OTCC domains are Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience, and Third-Party Cybersecurity. Together they contain 23 subdomains, 47 main controls, and 122 sub-controls.

The ECC, Essential Cybersecurity Controls, is the NCA's broad baseline cybersecurity standard. OTCC is an extension of the ECC built specifically for operational technology and industrial control systems. ECC compliance supports and underpins OTCC compliance.

We provide a full path to compliance: a free initial assessment, an OTCC gap assessment against all four domains, OT asset inventory, remediation and control implementation, and audit-ready documentation. Explore our OT cybersecurity services to learn more.

More from Arista Cyber