NCA · ECC-2:2024
NCA Essential Cybersecurity Controls (ECC-2:2024)
The Kingdom's baseline cybersecurity requirements, explained for a mid-size organization: what the ECC contains, who must comply and how to start.
Last verified against official sources: 26 September 2026
Key facts
- Issued by
- National Cybersecurity Authority (NCA)
- Current version
- ECC-2:2024, which replaced ECC-1:2018
- Structure
- 4 main domains, 28 subdomains and 108 main controls
- Mandatory for
- Government entities in the Kingdom and their affiliated companies and entities, inside and outside the Kingdom
- Also mandatory for
- Private-sector organizations that own, operate or host critical national infrastructure
- Strongly encouraged for
- All other organizations
What the ECC is
The Essential Cybersecurity Controls are the minimum cybersecurity requirements set by the National Cybersecurity Authority. The NCA's other control sets, for critical systems, cloud, telework and operational technology, build on the ECC rather than replacing it. If you are in scope for any of them, the ECC comes first.
Read it as a baseline, not a ceiling. It tells you what must be in place; how far you go beyond it depends on your risk.
The four domains
ECC-2:2024 organizes its 108 main controls into four domains:
- Cybersecurity Governance. How cybersecurity is directed and overseen: strategy, roles and responsibilities, policies and risk management.
- Cybersecurity Defense. The technical and operational controls that protect systems and data day to day.
- Cybersecurity Resilience. Keeping essential services running through a cybersecurity incident, and recovering from one.
- Third-Party and Cloud Computing Cybersecurity. Cybersecurity requirements for suppliers, service providers and cloud computing.
The change from ECC-1:2018 worth knowing: the earlier edition had a fifth domain for industrial control systems. That content now sits in the separate Operational Technology Cybersecurity Controls (OTCC-1:2022).
Who must comply
The ECC is mandatory for government entities in the Kingdom, meaning ministries, authorities, establishments and others, and for their affiliated companies and entities, whether inside or outside the Kingdom.
It is also mandatory for private-sector organizations that own, operate or host critical national infrastructure. The NCA strongly encourages all other organizations to apply the controls.
Outside that scope, the ECC is still the reference most Saudi buyers recognize. A private company that can show alignment with the ECC is speaking the language its government and enterprise customers already use.
A requirement that surprises foreign firms
ECC-2:2024 states that all cybersecurity positions shall be filled by full-time, qualified Saudi professionals. For an entity in scope, that is a staffing and hiring decision, not only a technical one, and it is worth planning early.
Where to start
- Confirm if you are in mandatory scope, or are adopting the ECC because your customers expect it.
- Document which controls apply to you and why. A control you decide does not apply needs a reason you can defend.
- Assess each applicable control against evidence, not intent. A policy that exists but is not followed is still a gap.
- Fix in risk order: governance first, then the controls that protect your most important systems and data.
- Keep it current. Entities in scope are expected to maintain compliance continuously, and the NCA monitors and evaluates it.
How AccuSights helps
We assess your controls against ECC-2:2024, map them once so the same evidence also serves the Personal Data Protection Law and ISO/IEC 27001, and use our read-only compliance agent to report configuration drift between reviews. See our services.
Questions about the ECC
Is ECC-1:2018 still valid?
ECC-2:2024 is the current version and replaced ECC-1:2018. Work to the current version, and check the NCA site for any later update.
Does ISO 27001 certification satisfy the ECC?
No. ISO/IEC 27001 maps well to the ECC, and the same evidence can serve both, but certification does not replace compliance with the ECC for an entity in scope.
Where do industrial control systems fit now?
In the Operational Technology Cybersecurity Controls, OTCC-1:2022. The ICS domain that sat in ECC-1:2018 moved there, and the OTCC treats ECC compliance as a prerequisite.
AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the NCA, SDAIA, SAMA, CST, DGA or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. Always confirm current requirements against the official source.