NCA
The NCA controls family, on one page
Which NCA control set applies to whom, and how each one builds on the Essential Cybersecurity Controls.
Last verified against official sources: 26 September 2026
| Control set | Version | Applies to | Relationship to the ECC |
|---|---|---|---|
| Essential Cybersecurity Controls (ECC) | ECC-2:2024 | Mandatory for government entities and their affiliates, and for private-sector organizations that own, operate or host critical national infrastructure; strongly encouraged for all others | The baseline |
| Critical Systems Cybersecurity Controls (CSCC) | CSCC-1:2019 | Organizations that own or operate critical systems | Additional controls on top of the ECC |
| Cloud Cybersecurity Controls (CCC) | CCC-2:2024 | Government entities and private-sector critical national infrastructure organizations that use cloud services, and the cloud providers that serve them | Extends the ECC for cloud; replaced CCC-1:2020 |
| Telework Cybersecurity Controls (TCC) | TCC-1:2021 | Organizations in ECC scope that enable remote work | Extends the ECC for telework |
| Operational Technology Cybersecurity Controls (OTCC) | OTCC-1:2022 | Industrial control systems in critical facilities owned or operated by government organizations or by private-sector critical national infrastructure organizations | ECC compliance is a prerequisite |
| Data Cybersecurity Controls (DCC) | DCC-1:2022 | Data cybersecurity across its lifecycle | Complements, and is separate from, the Personal Data Protection Law |
Critical Systems Cybersecurity Controls
For organizations that own or operate critical systems, meaning systems whose failure or unauthorized access would have a negative impact at national level. The CSCC applies in addition to the ECC. Among its stricter requirements:
- Classify all critical-system data, and encrypt it in transit and at rest.
- Keep security event logs for critical systems for at least 18 months.
- Rely on Saudi companies for outsourcing and managed services related to critical systems.
- Host critical systems in the cloud only inside the organization, with a government provider, or with a Saudi cloud provider that complies with the Cloud Cybersecurity Controls, taking into account the classification of the hosted data.
Cloud Cybersecurity Controls
CCC-2:2024, which replaced CCC-1:2020, sets controls for both cloud service providers and the organizations that subscribe to their services. On the subscriber side, it covers government entities and their companies, and private-sector organizations that own, operate or host critical national infrastructure, when they use cloud services. On the provider side, it covers providers that serve those subscribers. A provider that serves only individuals, or private organizations outside critical national infrastructure, is outside its scope.
Obligations differ between providers and subscribers, and the level of controls required is driven by the classification of the data involved. For where data may be hosted, see the cloud and data residency guide.
Telework Cybersecurity Controls
TCC-1:2021 applies on top of the ECC for organizations that allow remote and hybrid work, and addresses remote access, endpoints, identity and data handling when people work outside the office.
Operational Technology Cybersecurity Controls
OTCC-1:2022 applies to industrial control systems in facilities deemed critical and owned or operated by government organizations, or by private-sector organizations that own, operate or host critical national infrastructure, inside or outside the Kingdom. It does not cover every operator of operational technology. It treats ECC compliance as a mandatory prerequisite, and the NCA evaluates OT compliance against it. It also took over the industrial control systems domain that sat in ECC-1:2018.
Data Cybersecurity Controls
The Data Cybersecurity Controls address the security of data across its lifecycle, including classification, encryption, backup and monitoring. They complement the Personal Data Protection Law but are a separate regime: the PDPL is administered by SDAIA and governs personal data, while the DCC is an NCA control set. The current version is DCC-1:2022.
Working with several control sets at once
Organizations in scope for more than one set should not run them as separate programs. Start from the ECC, then layer the additional controls from each extension onto the same control set, so one piece of evidence can satisfy several requirements.
AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the NCA, SDAIA, SAMA, CST, DGA or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. Always confirm current requirements against the official source.
Sources
- NCA, Essential Cybersecurity Controls (ECC-2:2024) (opens in a new tab)
- NCA, Critical Systems Cybersecurity Controls (opens in a new tab)
- NCA, Cloud Cybersecurity Controls (CCC-2:2024) (opens in a new tab)
- NCA, Telework Cybersecurity Controls (opens in a new tab)
- NCA, Operational Technology Cybersecurity Controls (opens in a new tab)
- NCA, Data Cybersecurity Controls (opens in a new tab)
- NCA, implementation guides (opens in a new tab)