NCA

The NCA controls family, on one page

Which NCA control set applies to whom, and how each one builds on the Essential Cybersecurity Controls.

Last verified against official sources: 26 September 2026

Each control set extends the ECC; none replaces it
Control setVersionApplies toRelationship to the ECC
Essential Cybersecurity Controls (ECC)ECC-2:2024Mandatory for government entities and their affiliates, and for private-sector organizations that own, operate or host critical national infrastructure; strongly encouraged for all othersThe baseline
Critical Systems Cybersecurity Controls (CSCC)CSCC-1:2019Organizations that own or operate critical systemsAdditional controls on top of the ECC
Cloud Cybersecurity Controls (CCC)CCC-2:2024Government entities and private-sector critical national infrastructure organizations that use cloud services, and the cloud providers that serve themExtends the ECC for cloud; replaced CCC-1:2020
Telework Cybersecurity Controls (TCC)TCC-1:2021Organizations in ECC scope that enable remote workExtends the ECC for telework
Operational Technology Cybersecurity Controls (OTCC)OTCC-1:2022Industrial control systems in critical facilities owned or operated by government organizations or by private-sector critical national infrastructure organizationsECC compliance is a prerequisite
Data Cybersecurity Controls (DCC)DCC-1:2022Data cybersecurity across its lifecycleComplements, and is separate from, the Personal Data Protection Law

Critical Systems Cybersecurity Controls

For organizations that own or operate critical systems, meaning systems whose failure or unauthorized access would have a negative impact at national level. The CSCC applies in addition to the ECC. Among its stricter requirements:

  • Classify all critical-system data, and encrypt it in transit and at rest.
  • Keep security event logs for critical systems for at least 18 months.
  • Rely on Saudi companies for outsourcing and managed services related to critical systems.
  • Host critical systems in the cloud only inside the organization, with a government provider, or with a Saudi cloud provider that complies with the Cloud Cybersecurity Controls, taking into account the classification of the hosted data.

Cloud Cybersecurity Controls

CCC-2:2024, which replaced CCC-1:2020, sets controls for both cloud service providers and the organizations that subscribe to their services. On the subscriber side, it covers government entities and their companies, and private-sector organizations that own, operate or host critical national infrastructure, when they use cloud services. On the provider side, it covers providers that serve those subscribers. A provider that serves only individuals, or private organizations outside critical national infrastructure, is outside its scope.

Obligations differ between providers and subscribers, and the level of controls required is driven by the classification of the data involved. For where data may be hosted, see the cloud and data residency guide.

Telework Cybersecurity Controls

TCC-1:2021 applies on top of the ECC for organizations that allow remote and hybrid work, and addresses remote access, endpoints, identity and data handling when people work outside the office.

Operational Technology Cybersecurity Controls

OTCC-1:2022 applies to industrial control systems in facilities deemed critical and owned or operated by government organizations, or by private-sector organizations that own, operate or host critical national infrastructure, inside or outside the Kingdom. It does not cover every operator of operational technology. It treats ECC compliance as a mandatory prerequisite, and the NCA evaluates OT compliance against it. It also took over the industrial control systems domain that sat in ECC-1:2018.

Data Cybersecurity Controls

The Data Cybersecurity Controls address the security of data across its lifecycle, including classification, encryption, backup and monitoring. They complement the Personal Data Protection Law but are a separate regime: the PDPL is administered by SDAIA and governs personal data, while the DCC is an NCA control set. The current version is DCC-1:2022.

Working with several control sets at once

Organizations in scope for more than one set should not run them as separate programs. Start from the ECC, then layer the additional controls from each extension onto the same control set, so one piece of evidence can satisfy several requirements.

AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the NCA, SDAIA, SAMA, CST, DGA or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. Always confirm current requirements against the official source.

Sources

  1. NCA, Essential Cybersecurity Controls (ECC-2:2024) (opens in a new tab)
  2. NCA, Critical Systems Cybersecurity Controls (opens in a new tab)
  3. NCA, Cloud Cybersecurity Controls (CCC-2:2024) (opens in a new tab)
  4. NCA, Telework Cybersecurity Controls (opens in a new tab)
  5. NCA, Operational Technology Cybersecurity Controls (opens in a new tab)
  6. NCA, Data Cybersecurity Controls (opens in a new tab)
  7. NCA, implementation guides (opens in a new tab)

Ten minutes to know exactly where you stand

Tell us what you do and who regulates you. We will show you which Saudi rules apply, where the gaps usually are, and the shortest route to ready. No slides, no pitch.