nca ecc 2 2024 compliance guide
All insights
ITBUILDERS INTELLIGENCECompliance

NCA ECC Requirements Explained: A Practical Guide to ECC-2:2024 for Saudi Organizations

The NCA replaced ECC-1:2018 with ECC-2:2024 in October 2024. What changed, who must comply, and how to build a compliance program that survives assessment.

By ITBuilders Editorial Team6 min read

For any organisation running critical systems in the Kingdom, the National Cybersecurity Authority's Essential Cybersecurity Controls aren't optional guidance. They're the regulatory baseline your security posture gets measured against.

In October 2024, the NCA replaced the original ECC-1:2018 with an updated edition — ECC-2:2024 — that reshaped how compliance is scoped, structured, staffed, and assessed. For boards and security leaders, knowing what changed is the difference between a smooth assessment and a last-minute scramble.

This guide walks through what the controls are, who they apply to, how the framework is built, what changed, and how to put together a compliance program that holds up under scrutiny.

What the ECC is

The ECC is a mandatory set of minimum cybersecurity controls the NCA developed from an analysis of national legislation and leading international standards. [1]

It does two jobs at once, and that dual nature is worth understanding. It's an implementation baseline that tells in-scope entities what they must put in place. And it's the assessment tool the NCA uses to check whether they've done it. [2] The document you use to build is the same document the regulator uses to grade — which means there's no ambiguity about what's expected, and no excuse for surprise at assessment.

Because it's a baseline rather than an aspirational target, every in-scope entity has to meet it — regardless of sector, size, or complexity. There's no "we're too small for this" exemption.

Who must comply

ECC-2:2024 broadly mirrors its predecessor's scope, with one useful clarification.

It applies to government entities in the Kingdom — ministries, authorities, government-established entities, and their subsidiaries and affiliates. ECC-2 specifically confirms that government entities established outside Saudi Arabia are in scope too, closing an ambiguity in the earlier edition. It also applies to private-sector organisations that own, operate, or host Critical National Infrastructure. [2]

Private-sector organisations that aren't CNI operators aren't always directly bound — but compliance is frequently required indirectly, through contracts with government entities or through sector regulations that reference the ECC as a baseline. [2]

In plain terms: any company that wants to win or keep public-sector business should treat ECC alignment as a commercial prerequisite, not a maybe. The requirement arrives through the procurement process whether or not the regulator names you directly.

How ECC-2:2024 is structured

The framework runs on a hierarchy — main domains contain subdomains, which contain main controls, which contain subcontrols with specific implementation requirements. ECC-2:2024 consists of 4 main domains, 28 subdomains, 108 main controls, and 92 subcontrols. [1]

The four domains:

1. Cybersecurity Governance — strategy, management, policies and procedures, roles and responsibilities, risk management, security in IT projects, compliance, periodic review and audit, human-resources security, and awareness and training. This is the domain organisations underestimate most, because it's documentation and process rather than technology.

2. Cybersecurity Defence — the largest domain, covering asset management, identity and access management, network security, cryptography, and vulnerability management. This is where most of the technical weight sits.

3. Cybersecurity Resilience — embedding cybersecurity into business continuity and disaster recovery, so the organisation can absorb and recover from incidents rather than merely prevent them.

4. Third-Party and Cloud Computing Cybersecurity — managing the risk that vendors, contractors, and cloud providers introduce. As Saudi organisations move to cloud and outsource more, this domain grows in practical weight.

The Defence domain is where technical effort concentrates, with published analysis describing it as holding 15 subdomains and roughly 60 controls. [3]

What changed from ECC-1:2018

Three shifts matter most.

The structure was streamlined. ECC-1 had 5 domains, 29 subdomains, and 114 controls; ECC-2 consolidated to 4 domains, 28 subdomains, and 108 controls, merging overlapping requirements and pointing organisations to specific NCA standards. Fewer controls doesn't mean less work — it means less duplication.

Cybersecurity roles were Saudised. Under ECC-1, only senior positions required Saudi nationals. ECC-2 now requires cybersecurity positions to be filled by qualified, full-time Saudi professionals. This has real operational consequences given the talent market, and it's the change most likely to require planning rather than just implementation. [2]

Data localisation was realigned. Responsibility for data-hosting and localisation shifted toward the National Data Management Office under SDAIA, rather than being prescribed directly inside the ECC. If you built your data strategy around ECC-1's language, check where the requirement now lives. [2]

A practical compliance roadmap

Reaching ECC alignment is a program, not a project — and treating it like a project is why organisations fail assessments. A credible sequence looks like this.

Scoping. Confirm which systems and entities fall in scope, including subsidiaries and any hosted CNI. Get this wrong and everything downstream is wrong — you'll either over-invest across systems that don't need it or, worse, miss systems that do.

Gap assessment. Map your current controls against all 108 controls and find where you fall short — with evidence, not assumptions. "We think we do that" is not a finding; either the control operates and you can show it, or it doesn't.

Prioritised remediation. Close the highest-risk gaps first, typically in governance and defence, before working down to lower-risk items. Resources are finite; sequence by risk, not by which controls are easiest.

Evidence and documentation. Here's the thing most organisations miss, and it's the single most common cause of a poor assessment: they don't fail for missing controls. They fail because they can't demonstrate the controls operated consistently over time. A firewall that's correctly configured today with no change records, no review cadence, and no logs proves nothing. Build the evidence trail as you go, not the week before the assessment.

Continuous monitoring. The NCA expects ongoing compliance, not a one-time pass — supported by the forthcoming ECC-2:2024 Assessment and Compliance Tool. Compliance is a state you maintain, not a certificate you earn.

Frequently asked questions

Does ECC apply to private companies? Directly, if you own or operate Critical National Infrastructure. Indirectly and very often in practice, through government contracts and sector regulations that reference it. If you serve the public sector, assume it applies.

How long does ECC alignment take? It depends on your starting point. Organisations with mature security typically need months for gap closure and evidence building. Those starting further back should plan across budget cycles rather than quarters.

What's the most common reason organisations fail? Insufficient evidence rather than absent controls. The control exists but nobody can prove it has been operating consistently.

Do we need external help? Not necessarily, but the governance documentation and evidence trail are where internal teams most often run short of capacity — they're time-consuming and compete with operational work.

How ITBuilders helps

We support organisations across the full ECC lifecycle. We run a gap assessment against the current ECC-2:2024 controls, produce a prioritised remediation roadmap, and deliver the technical implementation that actually closes the gaps — network and endpoint defence, identity and access management, vulnerability management, and continuous monitoring through a managed SOC.

Our consulting team handles the governance documentation and evidence trail the NCA assesses, while our engineers harden the environment itself. You end up aligned with the controls the regulator measures — and holding the evidence to prove it.

Book an ECC-2:2024 gap assessment. Call 920-020-750 or email [email protected].

Sources & references

  1. National Cybersecurity Authority (Saudi Arabia), Essential Cybersecurity Controls (ECC-2:2024)
  2. Security Scientist, "12 Questions and Answers About the NCA ECC Standard."
  3. Qualys, "Bridging the Gap: NCA ECC 2024 Compliance."
TALK TO A SPECIALIST

Turn this insight into a practical next step.

Discuss your environment with our team and get a clear recommendation grounded in your operational reality.

Start a conversation
CONTINUE READING

Related intelligence