The two frameworks come from different regulators and bind different organisations. The National Cybersecurity Authority's Essential Cybersecurity Controls, ECC-2:2024, apply to government agencies, their affiliated companies inside and outside the Kingdom, and private sector entities that own, operate or host Critical National Infrastructure. The Saudi Central Bank's Cyber Security Framework applies to every Member Organization SAMA regulates. A bank, insurer or financing company is always under the SAMA CSF, and is under the ECC as well only if it falls within one of those three ECC groups. Neither document refers to the other, so neither switches the other off. Where you answer to both, the rules mostly point the same way, but they differ on Saudi staffing, log retention, penetration testing, incident reporting and where services may sit, and on each of those you have to meet the stricter one.
This comparison is built from the two primary texts: ECC-2:2024 as published by the NCA, and the SAMA Cyber Security Framework, version 1.0 of May 2017, which the SAMA Rulebook lists as in force. What each one asks for domain by domain is in Saudi NCA ECC requirements explained and SAMA CSF requirements explained.
| NCA ECC-2:2024 | SAMA CSF | |
|---|---|---|
| Issuer | National Cybersecurity Authority | Saudi Central Bank (SAMA) |
| Who it binds | Government agencies, their affiliated companies and entities inside and outside the Kingdom, and private sector owners, operators or hosts of Critical National Infrastructure | All Member Organizations regulated by SAMA: banks, insurance and reinsurance companies, financing companies, credit bureaus and the Financial Market Infrastructure |
| Everyone else | Strongly encouraged to leverage the Controls | Not applicable |
| Structure | 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols | 4 domains and 32 subdomains, each with a principle, an objective and control considerations |
| Style | Controls written as obligations; each entity complies with all controls applicable to it | Principle based; control considerations tailored to risk, with waivers through Appendix D |
| How it is assessed | Self assessment, periodic reports of the NCA compliance tool and field audit visits | A periodic self assessment questionnaire that SAMA reviews and audits, scored by maturity level |
| Certificate | None | None |
Who must comply with the ECC, and who with the SAMA CSF?
The ECC's Scope of Work says the Controls "are applicable to government agencies in the Kingdom of Saudi Arabia (including ministries, authorities, establishments and others) and their affiliated companies and entities (inside and outside the kingdom), as well as all private sector entities owning, operating, or hosting Critical National Infrastructures". For everyone else, "the NCA strongly encourages" use of the Controls. That is an encouragement, not a mandate.
The SAMA CSF says it "is applicable to all Member Organizations regulated by SAMA", and lists all banks, insurance and reinsurance companies, financing companies and credit bureaus operating in Saudi Arabia, and the Financial Market Infrastructure. All domains apply to banks; other institutions are excused subdomains 3.2.3, 3.3.12 and 3.3.13, two of them with conditions.
So the question for a financial institution is not which framework applies, but whether the ECC applies on top. Check two things, and get the answer in writing from your regulators if it is not obvious: whether you own, operate or host Critical National Infrastructure, and whether you are an affiliate of a government agency, for example through state ownership. If neither holds, the ECC reaches you only by encouragement or through a customer's contract.
How are the two frameworks structured and assessed?
The ECC states its own size in its introduction: "4 Cybersecurity Main Domains", "28 Cybersecurity Subdomains", "108 Cybersecurity Main Controls" and "92 Cybersecurity Subcontrols". The domains are Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience, and Third-Party and Cloud Computing Cybersecurity. Entities "shall take all necessary measures to ensure ongoing and continuous compliance", and the NCA evaluates compliance "through multiple means, such as self-assessment by the entities, periodic reports of the compliance tool, and/or field auditing visits". The document says its Arabic version is binding.
The SAMA CSF has four domains, Cyber Security Leadership and Governance, Cyber Security Risk Management and Compliance, Cyber Security Operations and Technology, and Third Party Cyber Security, across 32 subdomains. It is principle based, and instead of a pass or fail per control it scores a maturity level from 0 to 5 per subdomain. Member Organizations "should at least operate at maturity level 3 or higher", and in 2019 banks were told to roadmap to level 4 on four operations subdomains. Where a control consideration cannot be implemented, the route is compensating controls, an internal risk acceptance and a formal waiver request to SAMA.
The difference in style matters for evidence. An ECC answer is per control: is 2-12-3 met or not. A SAMA answer is per subdomain: at what maturity level do you operate it, and can you show the key performance indicators that prove level 3.

Where do the ECC and the SAMA CSF set different rules?
On most topics the two point the same way: an independent cyber security function, a committee, risk management, independent audit, incident management and third party controls. The differences are in the detail, and they decide what a dual programme has to meet.
| Topic | NCA ECC-2:2024 | SAMA CSF |
|---|---|---|
| Saudi nationals | Control 1-2-2: all cybersecurity positions filled with full-time and qualified Saudi professionals | 3.1.1: the CISO must be Saudi, sufficiently qualified, with SAMA's no objection |
| Independence | 1-2-1: a cybersecurity department independent from IT; reporting to the head of the entity is recommended | 3.1.1: separate reporting lines, budgets and staff evaluations from IT; reports to the CEO, managing director or a control function head |
| Committee | 1-2-3: a supervisory committee that includes the head of cybersecurity | 3.1.1: board mandated, headed by an independent control function manager, meeting at least quarterly |
| Event logs | 2-12-3: continuous monitoring; retention of at least 12 months | 3.3.14: a 24x7 security operations centre and SIEM; no retention period stated |
| Penetration testing | 2-11-3: all internet facing services, tested periodically | 3.2.4: customer and internet facing services, annually |
| Incidents | 2-13-3: report incidents to the NCA and share notifications, threat intelligence and incident reports with it | 3.3.15: inform SAMA IT Risk Supervision immediately of medium or high incidents; no objection before media contact; formal report after recovery |
| Location | 4-1-3: managed security operations centres using remote access fully in the Kingdom; data localisation moved to the NDMO | 3.4.3: SAMA approval before public or hybrid cloud; in principle only cloud services located in Saudi Arabia |
| Business continuity | Domain 3, subdomain 3-1: cybersecurity resilience in business continuity | Refers to the separate SAMA Business Continuity Minimum Requirements |
Two of these change hiring and sourcing decisions. Under the ECC every cybersecurity role must be held by a qualified Saudi professional, not only the head of the function. And a managed security operations centre that monitors you remotely must be located fully in the Kingdom, while SAMA separately requires its approval before any material outsourcing and before public cloud.

What the other results get wrong
Page one for this query is mostly vendor and consultancy pages, and two errors are worth correcting. One says the ECC binds government offices, key infrastructure sites and "many private firms" too. The Scope of Work binds private sector entities only if they own, operate or host Critical National Infrastructure, and encourages everyone else. A private company may still have to implement the ECC because a government or CNI customer writes it into a contract, but that duty comes from the contract. The same page says control 2-12 requires a SIEM tool. The text of 2-12-3 asks for "identification of Security Information and Event Management (SIEM) techniques required for cybersecurity event logs collection", continuous monitoring and 12 months of retention; the SAMA CSF is the one that names a SIEM, under 3.3.14. The difference matters when an auditor asks what the control actually requires.
A third, older error still circulates: describing the ECC with a fifth domain for industrial control systems. That was ECC-1:2018. Appendix C of the 2024 edition records that main domain 5 was deleted and its controls moved to the NCA's separate Operational Technology Cybersecurity Controls.
How do you comply with both?
Keep one evidence base and two indexes. Confirm the ECC scope first, because everything else follows from it. Map each ECC control to the SAMA subdomain it supports, and where a topic appears in both, write your internal standard to the stricter rule: Saudi staffing across the whole function, 12 months of log retention, annual penetration tests, immediate notice to SAMA and reporting to the NCA, and in Kingdom location for remote managed security services. Then score SAMA maturity per subdomain and answer the NCA in its compliance tool, each in the format its regulator asks for. If you also hold ISO 27001, SAMA CSF vs ISO 27001 shows how that certificate fits underneath both.
Check your own position
Fill in the middle column. The first row decides whether the rest apply.
| Question | Your answer | Why it matters |
|---|---|---|
| Do you own, operate or host Critical National Infrastructure, or are you a government affiliate? | If not, the ECC is an encouragement or a contract term, not a mandate. | |
| Are all cybersecurity roles held by full-time qualified Saudi professionals? | ECC 1-2-2 covers every position; SAMA 3.1.1 covers the CISO. | |
| Are event logs kept for at least 12 months? | ECC 2-12-3 sets the figure; SAMA sets none. | |
| Were internet facing services pen tested in the last year? | SAMA 3.2.4 requires annual tests; the ECC says periodically. | |
| Does your incident procedure notify both regulators? | SAMA wants medium and high incidents immediately; the ECC requires reporting to the NCA. | |
| Is your managed SOC, if remote, located in the Kingdom? | ECC 4-1-3; and SAMA approval for material outsourcing under 3.4.2. | |
| Which edition of the ECC are you assessed against? | ECC-2:2024 has 108 main controls in 4 domains; a list with an industrial control systems domain is the 2018 edition. |
If most rows are blank, the free compliance check gives you a starting position. Saudi NCA ECC in Venvera tracks controls with owner, status and evidence and scores gaps by domain, and SAMA CSF in Venvera scores the 32 subdomains on the maturity model, so both regulators can be answered from the same evidence. Budgets for each are in Saudi NCA ECC compliance cost and SAMA CSF compliance cost.
Frequently asked questions
Do Saudi banks have to comply with the NCA ECC?
Every bank is under the SAMA CSF. The ECC applies on top only if the bank owns, operates or hosts Critical National Infrastructure or is affiliated with a government agency; otherwise the NCA encourages it. Confirm your position with your regulators.
Does SAMA CSF compliance satisfy the ECC?
No. Neither framework refers to the other, they are assessed by different authorities in different formats, and they differ on several rules, including Saudi staffing, log retention and testing frequency.
How many controls are in each?
ECC-2:2024 has 108 main controls and 92 subcontrols across 4 domains and 28 subdomains. The SAMA CSF has 4 domains and 32 subdomains; its control considerations nest, so published totals differ.
Which one is stricter?
Neither across the board. The ECC is stricter on Saudi staffing and log retention; the SAMA CSF is stricter on testing frequency, incident timing, the committee and approvals for outsourcing and cloud.
Is there a certificate for either?
No. The NCA assesses ECC compliance through self assessment, its compliance tool and field audits; SAMA reviews and audits a self assessment and scores maturity.
Primary sources
ECC provisions are quoted from the Essential Cybersecurity Controls (ECC-2:2024), published by the National Cybersecurity Authority among its regulatory documents: the introduction, the Scope of Work and Applicability, Implementation and Compliance, controls 1-2-1 to 1-2-3, 2-11-3, 2-12-3, 2-13-3, 4-1-3 and subdomain 3-1, and the updates in Appendix C. SAMA provisions are quoted from the SAMA Cyber Security Framework, version 1.0 of May 2017, sections 1.3, 1.4, 2.2 to 2.4 and subdomains 3.1.1, 3.2.4, 3.3.14, 3.3.15, 3.4.2 and 3.4.3, and the level 4 requirement from Circular No. 298140000067. The ECC states that its Arabic version is binding. Confirm the current versions before relying on a reference.





