Cybersecurity governance
Strategy, management, policies and procedures, roles and responsibilities, risk management, cybersecurity in project management, compliance, review and audit, human resources, and awareness and training.

Regulation · Saudi Arabia
The National Cybersecurity Authority’s Essential Cybersecurity Controls set the minimum for government entities and critical national infrastructure in Saudi Arabia. The 2024 edition has 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols.
Government agencies in the Kingdom, including ministries, authorities and establishments, and their affiliated companies and entities inside and outside the Kingdom; and private-sector entities that own, operate or host critical national infrastructure. The NCA strongly encourages every other organisation to adopt the controls. The Arabic text is the binding version.
Strategy, management, policies and procedures, roles and responsibilities, risk management, cybersecurity in project management, compliance, review and audit, human resources, and awareness and training.
Asset management, identity and access, systems and email protection, network and mobile security, data protection, cryptography, backup and recovery, vulnerability management, penetration testing, logging and monitoring, incident and threat management, physical security and web application security.
Cybersecurity aspects of business continuity management.
Third-party cybersecurity, and cloud computing and hosting cybersecurity.
Entities must maintain continuous compliance. The NCA assesses it through self-assessment, periodic reports submitted through its compliance tools, and field audit visits, and has said it will issue an ECC-2:2024 assessment and compliance tool to structure the process.
An ECC-2:2024 gap assessment: we map your current controls to all 108 main controls and their subcontrols, test the evidence, flag what changed since ECC-1:2018 so nothing is rolled forward by mistake, and give you a prioritised plan your own team or chosen integrator can deliver. How an engagement is delivered in Saudi Arabia is agreed at scoping.
See our regulatory readiness assessment for scope and approach.
We never assess work we have advised on, and we never sell the fix for anything we assess. Where a framework requires a licensed or accredited assessor, we say so and tell you who can sign it.
Government agencies in Saudi Arabia and their affiliated companies and entities inside and outside the Kingdom, and private-sector entities that own, operate or host critical national infrastructure. The NCA strongly encourages all other entities to adopt it.
Through self-assessment, periodic reporting via the NCA’s compliance tools, and field audit visits.
Industrial control systems moved to the separate OT controls (OTCC), multi-factor authentication was extended to privileged accounts, DDoS protection and DKIM and DMARC email checks were added, and data privacy and localisation moved to the National Data Management Office.
Checked 30 September 2026. Nothing on this page is legal advice; the NCA’s Arabic text is the binding version.
Tell us the entity, whether it is government, affiliated or critical national infrastructure, and your last NCA assessment result.