العربية

Regulation · Saudi Arabia

NCA ECC-2:2024: the baseline every other Saudi control set builds on

The National Cybersecurity Authority’s Essential Cybersecurity Controls set the minimum for government entities and critical national infrastructure in Saudi Arabia. The 2024 edition has 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols.

Who it applies to

Government agencies in the Kingdom, including ministries, authorities and establishments, and their affiliated companies and entities inside and outside the Kingdom; and private-sector entities that own, operate or host critical national infrastructure. The NCA strongly encourages every other organisation to adopt the controls. The Arabic text is the binding version.

The four domains

Domain 1

Cybersecurity governance

10 subdomains

Strategy, management, policies and procedures, roles and responsibilities, risk management, cybersecurity in project management, compliance, review and audit, human resources, and awareness and training.

FocusAccountability and management
Domain 2

Cybersecurity defence

15 subdomains

Asset management, identity and access, systems and email protection, network and mobile security, data protection, cryptography, backup and recovery, vulnerability management, penetration testing, logging and monitoring, incident and threat management, physical security and web application security.

FocusTechnical protection
Domain 3

Cybersecurity resilience

1 subdomain

Cybersecurity aspects of business continuity management.

FocusRecovery
Domain 4

Third-party and cloud computing cybersecurity

2 subdomains

Third-party cybersecurity, and cloud computing and hosting cybersecurity.

FocusSupply chain and cloud

What changed from ECC-1:2018

  • Industrial control systems moved out into the separate Operational Technology Cybersecurity Controls (OTCC).
  • Multi-factor authentication extended beyond remote access to privileged accounts.
  • Protection against distributed denial-of-service attacks added.
  • Email validation expanded to include DKIM and DMARC.
  • Data privacy and localisation requirements transferred to the National Data Management Office.
  • Cybersecurity positions to be filled by qualified Saudi cybersecurity professionals.

How compliance is assessed

Entities must maintain continuous compliance. The NCA assesses it through self-assessment, periodic reports submitted through its compliance tools, and field audit visits, and has said it will issue an ECC-2:2024 assessment and compliance tool to structure the process.

How we help

An ECC-2:2024 gap assessment: we map your current controls to all 108 main controls and their subcontrols, test the evidence, flag what changed since ECC-1:2018 so nothing is rolled forward by mistake, and give you a prioritised plan your own team or chosen integrator can deliver. How an engagement is delivered in Saudi Arabia is agreed at scoping.

See our regulatory readiness assessment for scope and approach.

Independence

We never assess work we have advised on, and we never sell the fix for anything we assess. Where a framework requires a licensed or accredited assessor, we say so and tell you who can sign it.

Questions we are asked

Who must comply with ECC-2:2024?

Government agencies in Saudi Arabia and their affiliated companies and entities inside and outside the Kingdom, and private-sector entities that own, operate or host critical national infrastructure. The NCA strongly encourages all other entities to adopt it.

How is compliance assessed?

Through self-assessment, periodic reporting via the NCA’s compliance tools, and field audit visits.

What changed from ECC-1:2018?

Industrial control systems moved to the separate OT controls (OTCC), multi-factor authentication was extended to privileged accounts, DDoS protection and DKIM and DMARC email checks were added, and data privacy and localisation moved to the National Data Management Office.

Primary sources

Checked 30 September 2026. Nothing on this page is legal advice; the NCA’s Arabic text is the binding version.

Start with a scoping call

Tell us the entity, whether it is government, affiliated or critical national infrastructure, and your last NCA assessment result.