Regulatory Playbook · Saudi Arabia

NCA ECC-2:2024 Compliance Checklist

Map your organization against all four domains and 108 controls of the current Essential Cybersecurity Controls, find your gaps, and prepare for NCA assessment. Free, and built on ECC-2:2024, not the outdated 2018 edition.

4Domains
108Main controls
92Sub-controls
2024Current edition

The Essential Cybersecurity Controls are the National Cybersecurity Authority's mandatory baseline for Saudi Arabia. Before anything else, one thing matters: use the current version. In October 2024 the NCA replaced ECC-1:2018 with ECC-2:2024, restructuring the framework into four domains, 28 subdomains, 108 controls, and 92 sub-controls.

A great deal of the guidance still circulating online describes the old five-domain, 114-control edition, which will not match what an assessor checks you against. This checklist is built on ECC-2:2024, so your self-assessment reflects the controls that actually apply.

What is inside The checklist walks all four ECC-2:2024 domains

For each control, you get a plain-language description, an assessment prompt, and a status field, so a walkthrough produces an honest gap picture rather than a vague sense of readiness.

01
DOMAIN 1
Cybersecurity Governance
Strategy, roles and Saudization, risk management, third-party and project security, compliance, and awareness and training.
02
DOMAIN 2
Cybersecurity Defense
Asset management, identity and access, data and system protection, network security, cryptography, backup, vulnerability and patch management, penetration testing, and event logging.
03
DOMAIN 3
Cybersecurity Resilience
Incorporating cybersecurity resilience into business continuity management so critical services survive a cyber incident.
04
DOMAIN 4
Third-Party & Cloud Cybersecurity
Managing the cybersecurity risks of third parties and cloud service providers, including hosting and outsourcing.

Who it is for

  • Built for the people who own ECC compliance
  • Government entities in Saudi Arabia: ministries, authorities, and establishments
  • Their affiliated companies and entities, inside and outside the Kingdom
  • Private-sector operators of critical national infrastructure
  • CISOs, GRC teams, and compliance leads preparing for an NCA ECC assessment
  • Any organization benchmarking against the Kingdom's baseline cybersecurity standard

Why use it

  • From a vague sense of readiness to a real position
  • Assess against the current controls — built on ECC-2:2024, not a retired edition
  • See your real position — a control-by-control view of where you comply and where you do not
  • Prepare evidence for assessment — organize what the NCA self-assessment expects
  • Catch the changes others miss — Saudization and data-localization shifts are flagged

ECC and OTCC: How They Fit Together

If you operate industrial control systems, the ECC is only half the picture. The ECC is the broad baseline across your information and technology assets; the Operational Technology Cybersecurity Controls (OTCC) extend that baseline specifically to OT and ICS, and ECC compliance underpins OTCC compliance. Many operators need both. Our NCA OTCC compliance checklist is the companion to this one, and our OT cybersecurity services help you meet both without duplicating effort.

NCA ECC, answered

The Essential Cybersecurity Controls are the National Cybersecurity Authority's mandatory baseline cybersecurity framework for Saudi Arabia, setting the minimum requirements that in-scope organizations must implement, operate, and continuously improve.
ECC-2:2024, effective October 2024, replaced ECC-1:2018. It restructured the framework from five domains and 114 controls to four domains, 28 subdomains, 108 controls, and 92 sub-controls, expanded the Saudization requirement to all cybersecurity roles, and moved data-localization requirements to the National Data Management Office under SDAIA.
ECC-2:2024 contains four domains, 28 subdomains, 108 main controls, and 92 sub-controls, for 232 nodes in total. The four domains are Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience, and Third-Party and Cloud Cybersecurity.
Compliance is mandatory for Saudi government entities and their affiliates inside and outside the Kingdom, and for private-sector operators of critical national infrastructure. The NCA supervises adherence through self-assessment reporting, evidence submission, and audit.
The ECC is the broad cybersecurity baseline across an organization. OTCC extends that baseline specifically to operational technology and industrial control systems, and ECC compliance underpins OTCC. See our NCA OTCC compliance checklist if you operate OT.