NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
Saudi NCA ECC Compliance Cost: What Drives It
Learn

Saudi NCA ECC Compliance Cost: What Drives It

·Alexander Sverdlov

There is no published price for Saudi NCA ECC compliance, and the figures that circulate come from firms selling the assessment. What exists is the document. The Essential Cybersecurity Controls (ECC-2:2024) issued by the National Cybersecurity Authority consist of 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols, and the cost of meeting them is a function of three things: how many controls apply to you, how many you can already evidence from ISO 27001 or similar work, and whether you have made four organisational decisions that no licence can make for you.

That last point is what makes the ECC different from most frameworks. Its expensive lines are not software. A cybersecurity department independent of IT, filled with full-time qualified Saudi professionals, audited by someone other than itself and penetration tested on every external service: these are fixed by the text of the controls, not by your maturity, and they are where budgets go wrong.

Cost lineWhat sets its sizeOne-off or recurring
Gap assessment against the 108 controlsHow much ISO 27001 or NIST CSF evidence already exists, and whether it is mapped across frameworksOne-off, then repeated for each NCA assessment cycle
Governance build (domain 1)10 subdomains: strategy, policies, roles, risk, project security, compliance, audit, HR and awarenessOne-off, then maintained
Technology controls (domain 2)15 subdomains, more than half the framework: logging and SIEM, vulnerability management, backup, cryptography, network and emailLargest one-off spend, then recurring licences and staff
People (controls 1-2-1 and 1-2-2)An independent cybersecurity department staffed by full-time qualified Saudi professionalsRecurring salary
Independent review and audit (control 1-8-2)A party other than the cybersecurity department, working to auditing standardsRecurring
Penetration testing (control 2-11-3)Every externally provided service and its components, tested periodicallyRecurring
Third party and cloud (domain 4)Contract count, cloud footprint and where your managed security provider sitsOne-off per contract, then at renewal
Evidence and NCA reportingContinuous compliance evaluated through self-assessment, the compliance tool and field visitsRecurring
The order in which a Saudi NCA ECC-2:2024 budget is spent, from scope and applicability through gap assessment, governance and people, domain 2 technology, and audit, testing and reporting

What does Saudi NCA ECC compliance cost?

A function, not a price. Four inputs set it.

Applicability. The ECC states that each entity shall comply with all controls applicable to it, and gives its own worked example: the cloud computing and hosting controls in subdomain 4-2 are binding on entities currently using or planning to use cloud services. An entity with no cloud footprint pays nothing for 4-2. One with three providers pays for it three times over.

Starting point. The NCA developed the ECC after studying national and international standards, frameworks and controls, and much of domain 2 will be familiar to anyone who has evidenced ISO 27001 Annex A controls. Whether that work transfers depends on whether your controls are mapped across frameworks or maintained separately per framework. Separately maintained means paying for the same evidence twice.

Headcount decisions. Controls 1-2-1 and 1-2-2 create salary lines rather than licence lines. They dominate the recurring cost for any entity that has been running security inside IT with a mixed team of employees and contractors.

Assessment mechanism. The NCA evaluates compliance through self-assessment by the entity, periodic reports of the compliance tool and field auditing visits, in whichever combination it considers appropriate, and states that it will issue an ECC-2:2024 Assessment and Compliance Tool to organise the process. Evidence therefore has to be kept in a form that answers to the control numbering on demand, which is an operating cost rather than a project one.

Which ECC costs are set by the document rather than your maturity?

Five, and they set the critical path because each needs a hiring decision, an organisational change or an outside party.

An independent cybersecurity department (control 1-2-1)

A department for cybersecurity shall be established within the entity, independent from the Information Technology and Communications Department, as per High Order No. 37140 dated 14/08/1438H. Reporting directly to the head of the entity or a delegate is recommended. If security currently reports to the CIO, this is an organisational change with a budget owner, not a policy edit.

Full-time qualified Saudi professionals (control 1-2-2)

All cybersecurity positions shall be filled with full-time and qualified Saudi cybersecurity professionals. ECC-1:2018 applied that to the function head and related supervisory and critical positions. Appendix C of ECC-2:2024 records the change to every position, with cybersecurity enhancement as the rationale. Contractors and offshore analysts do not satisfy it, and the recruitment market sets the price.

A supervisory committee (control 1-2-3)

A cybersecurity supervisory committee with documented members, responsibilities and governance framework, including the head of the cybersecurity department. Cheap in money, expensive in senior time, and it is the body that receives audit results under control 1-8-3.

An independent audit (control 1-8-2)

Implementation of the controls shall be reviewed and audited by parties other than the cybersecurity department, independently and with regard to conflict of interest, in line with Generally Accepted Auditing Standards. Internal audit can do it if it is genuinely independent. Otherwise it is an external fee, and it recurs.

Penetration testing on every external service (control 2-11-3)

Scope must include all externally provided services and their technical components: infrastructure, websites, web applications, smartphone and tablet applications, email and remote access, tested periodically. The cost scales with your external attack surface rather than your headcount.

Four Saudi NCA ECC cost lines fixed by the document: control 1-2-1 independent department, 1-2-2 full-time Saudi professionals, 1-8-2 independent audit and 2-11-3 penetration testing

Where does the technology spend go?

Domain 2, Cybersecurity Defense, holds 15 of the 28 subdomains, and three lines carry most of the technology budget.

Event logs and monitoring under control 2-12-3 require logs for critical information assets and for critical and privileged accounts and remote access, identification of the SIEM techniques used to collect them, continuous monitoring, and a retention period of at least 12 months. That is a SIEM licence, the storage behind it and the people watching it.

Vulnerability management under control 2-10-3 requires periodic assessment and detection, classification by severity, remediation tied to that classification, patch management with updates verified in a non-production environment before they are applied, and subscription to trusted sources for new vulnerabilities. The non-production environment is the line teams forget to cost.

Awareness and training under subdomain 1-10 sits in the governance domain but is a recurring spend: an awareness programme delivered through multiple channels and covering phishing, mobile devices and storage media, browsing and social media, plus specialised training for cybersecurity staff, developers and people working on technology assets, and executive and supervisory positions.

How the 28 ECC-2:2024 subdomains are distributed: 10 in governance, 15 in defense, 1 in resilience and 2 in third party and cloud

How do third party and cloud controls change the number?

Domain 4 has two subdomains and a disproportionate share of the legal and procurement cost.

Control 4-1-2 sets minimum clauses for any third party contract that could affect your data or services: non-disclosure and secure removal of your data at the end of service, communication procedures for cybersecurity incidents, and an obligation on the third party to apply your cybersecurity requirements and the relevant regulation. Every contract that lacks them is a renegotiation. Control 4-1-3 adds, for IT and cybersecurity outsourcing or managed services, a risk assessment before signing and a requirement that managed cybersecurity service centres using remote access be fully located in the Kingdom. An offshore security operations centre does not meet it.

Control 4-2-3 applies the controls of main domains 1, 2 and 3 and subdomain 4-1 to your cloud environment in addition to its own requirements: data protected by the provider according to its classification level and returned in a usable format at the end of service, and separation of your environment from those of other tenants. Budget for evidencing your controls in the cloud, not only on premises.

One line to remove from the budget. Sub-control 4-2-3-3, which required hosting and storage inside the Kingdom, was deleted in ECC-2:2024. Appendix C records that data localisation controls have been transferred to the National Data Management Office at the Saudi Data and Artificial Intelligence Authority, and that entities must refer to it before acting. A residency requirement may still apply to you, but it does not come from the ECC and should not be priced as if it did.

What does the ECC cost after the first year?

More than most programmes, because the ECC has no certificate and no expiry date. The obligation is ongoing and continuous compliance, and the document is built for it. Almost every subdomain ends with a control requiring its implementation to be periodically reviewed, and control 1-5-3 requires a cybersecurity risk assessment at the early stage of technology projects, before major changes to infrastructure, when planning to obtain third party services, and before releasing new services and products. The recurring lines are the independent audit, penetration testing, awareness delivery, monitoring staff and the compliance tool reporting the NCA describes. Plan year two at close to year one for everything except the initial build.

What the other results get wrong

The first error is scoping against 114 controls in 5 domains. Those are ECC-1:2018 figures. Appendix C of ECC-2:2024 records the deletion of main domain 5, Industrial Control Systems Cybersecurity, and the move of its controls to the separate Operational Technology Cybersecurity Controls. A quote built on 114 controls is pricing a domain that now lives in a different instrument. Read our guide to the Saudi NCA ECC requirements before accepting one.

The second is pricing data residency into the ECC. Sub-control 4-2-3-3 is gone, and the question now belongs to the National Data Management Office.

The third is quoting the assessment as the compliance cost. A gap assessment is the cheapest line in the table above. The hires under controls 1-2-1 and 1-2-2 and the recurring audit under 1-8-2 are the expensive ones, and no assessment quote includes them.

The fourth is treating the ECC as a certification with a renewal date. The NCA evaluates continuously through the mechanisms it chooses, so evidence has to be current on the day of a field visit, not on an anniversary.

Saudi NCA ECC readiness dashboard showing applicable controls evidenced, positions filled under control 1-2-2, days since the last independent audit and external services penetration tested
Venvera Saudi NCA ECC dashboard with control status by domain and subdomain

Sizing your own number

Fill this in. The point is not to produce a total, it is to find out which lines in the table at the top are yours.

QuestionYour answerWhy it matters
Are you within the ECC scope of work, or required by a customer contract?Government agencies, their affiliates inside and outside the Kingdom, and CNI operators are in scope. Everyone else is strongly encouraged.
Does your cybersecurity function sit outside IT today?Control 1-2-1. If not, this is the first organisational cost.
How many cybersecurity positions are held by full-time qualified Saudi professionals?Control 1-2-2 applies to all positions in ECC-2:2024.
Who reviews and audits the cybersecurity department?Control 1-8-2 requires a party other than the department, working independently.
Do you use, or plan to use, cloud or hosting services?Subdomain 4-2 is binding if yes, and it pulls domains 1 to 3 into the cloud environment.
How many third party contracts touch your data or services?Control 4-1-2 sets minimum clauses for each one.
Which ISO 27001 or NIST CSF controls can you already evidence?Reuse decides how much of domain 2 is re-evidencing rather than new work.

If most rows are blank, start with a baseline rather than a quote. A free compliance check gives you a starting position, our Saudi NCA ECC compliance software holds the controls and their evidence in the structure the NCA assesses against, and our comparison of the best NCA ECC compliance software shows what the platforms charge.

The bottom line on Saudi NCA ECC cost: the expensive lines are hires and audits rather than licences

Frequently asked questions

Does the NCA charge a fee for ECC compliance?

ECC-2:2024 contains no fee schedule and no penalty table. It describes how compliance is evaluated, through self-assessment, compliance tool reports and field audits, and leaves the cost of meeting the controls with the entity.

Do we need the ECC if we already hold ISO 27001?

If you are in scope, yes. ISO 27001 evidence shortens domain 2 considerably, but it does not create an independent department, a Saudi staffing profile or a Kingdom based managed security centre, and those are ECC specific.

Does the ECC still require our data to stay in Saudi Arabia?

Not the ECC. Sub-control 4-2-3-3 was deleted and data localisation now sits with the National Data Management Office. Check there before assuming either way.

Does the ECC cover our OT and industrial control systems?

No longer. Main domain 5 moved to the Operational Technology Cybersecurity Controls, which is a separate budget line if you run OT.

Do our subsidiaries abroad have to comply?

For government agencies, yes. The scope of work covers their affiliated companies and entities inside and outside the Kingdom, a clarification made in the 2024 update.

What if we are a private company outside the scope?

The NCA strongly encourages all other entities in the Kingdom to leverage the controls, which is encouragement rather than a mandate. In practice a government or CNI customer may require it contractually, and the cost then follows the contract. The same logic applies to the SAMA Cyber Security Framework for financial institutions.

Primary sources

Control texts, structure and scope are taken from the NCA's English edition of the Essential Cybersecurity Controls (ECC-2:2024), including Appendix C, as published on the NCA's Essential Cybersecurity Controls page. The Arabic version is the binding language for all matters of interpretation. Cost lines are a planning structure from implementation work, not figures from the document.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING