NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian, Arabic and Chinese.See what’s new →
Saudi NCA ECC vs SAMA CSF: Scope and Differences
Learn

Saudi NCA ECC vs SAMA CSF: Scope and Differences

·Alexander Sverdlov

The two frameworks come from different regulators and bind different organisations. The National Cybersecurity Authority's Essential Cybersecurity Controls, ECC-2:2024, apply to government agencies, their affiliated companies inside and outside the Kingdom, and private sector entities that own, operate or host Critical National Infrastructure. The Saudi Central Bank's Cyber Security Framework applies to every Member Organization SAMA regulates. A bank, insurer or financing company is always under the SAMA CSF, and is under the ECC as well only if it falls within one of those three ECC groups. Neither document refers to the other, so neither switches the other off. Where you answer to both, the rules mostly point the same way, but they differ on Saudi staffing, log retention, penetration testing, incident reporting and where services may sit, and on each of those you have to meet the stricter one.

This comparison is built from the two primary texts: ECC-2:2024 as published by the NCA, and the SAMA Cyber Security Framework, version 1.0 of May 2017, which the SAMA Rulebook lists as in force. What each one asks for domain by domain is in Saudi NCA ECC requirements explained and SAMA CSF requirements explained.

NCA ECC-2:2024SAMA CSF
IssuerNational Cybersecurity AuthoritySaudi Central Bank (SAMA)
Who it bindsGovernment agencies, their affiliated companies and entities inside and outside the Kingdom, and private sector owners, operators or hosts of Critical National InfrastructureAll Member Organizations regulated by SAMA: banks, insurance and reinsurance companies, financing companies, credit bureaus and the Financial Market Infrastructure
Everyone elseStrongly encouraged to leverage the ControlsNot applicable
Structure4 main domains, 28 subdomains, 108 main controls and 92 subcontrols4 domains and 32 subdomains, each with a principle, an objective and control considerations
StyleControls written as obligations; each entity complies with all controls applicable to itPrinciple based; control considerations tailored to risk, with waivers through Appendix D
How it is assessedSelf assessment, periodic reports of the NCA compliance tool and field audit visitsA periodic self assessment questionnaire that SAMA reviews and audits, scored by maturity level
CertificateNoneNone
NCA ECC and SAMA CSF at a glance: ECC-2:2024 has 4 domains, 28 subdomains and 108 main controls, the SAMA CSF has 4 domains and 32 subdomains, SAMA sets maturity level 3 per subdomain as the minimum, and neither ends in a certificate

Who must comply with the ECC, and who with the SAMA CSF?

The ECC's Scope of Work says the Controls "are applicable to government agencies in the Kingdom of Saudi Arabia (including ministries, authorities, establishments and others) and their affiliated companies and entities (inside and outside the kingdom), as well as all private sector entities owning, operating, or hosting Critical National Infrastructures". For everyone else, "the NCA strongly encourages" use of the Controls. That is an encouragement, not a mandate.

The SAMA CSF says it "is applicable to all Member Organizations regulated by SAMA", and lists all banks, insurance and reinsurance companies, financing companies and credit bureaus operating in Saudi Arabia, and the Financial Market Infrastructure. All domains apply to banks; other institutions are excused subdomains 3.2.3, 3.3.12 and 3.3.13, two of them with conditions.

So the question for a financial institution is not which framework applies, but whether the ECC applies on top. Check two things, and get the answer in writing from your regulators if it is not obvious: whether you own, operate or host Critical National Infrastructure, and whether you are an affiliate of a government agency, for example through state ownership. If neither holds, the ECC reaches you only by encouragement or through a customer's contract.

Who each one binds: the ECC binds government agencies, their affiliates and owners, operators or hosts of Critical National Infrastructure; the SAMA CSF binds banks, insurers, financing companies, credit bureaus and the Financial Market Infrastructure

How are the two frameworks structured and assessed?

The ECC states its own size in its introduction: "4 Cybersecurity Main Domains", "28 Cybersecurity Subdomains", "108 Cybersecurity Main Controls" and "92 Cybersecurity Subcontrols". The domains are Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience, and Third-Party and Cloud Computing Cybersecurity. Entities "shall take all necessary measures to ensure ongoing and continuous compliance", and the NCA evaluates compliance "through multiple means, such as self-assessment by the entities, periodic reports of the compliance tool, and/or field auditing visits". The document says its Arabic version is binding.

The SAMA CSF has four domains, Cyber Security Leadership and Governance, Cyber Security Risk Management and Compliance, Cyber Security Operations and Technology, and Third Party Cyber Security, across 32 subdomains. It is principle based, and instead of a pass or fail per control it scores a maturity level from 0 to 5 per subdomain. Member Organizations "should at least operate at maturity level 3 or higher", and in 2019 banks were told to roadmap to level 4 on four operations subdomains. Where a control consideration cannot be implemented, the route is compensating controls, an internal risk acceptance and a formal waiver request to SAMA.

The difference in style matters for evidence. An ECC answer is per control: is 2-12-3 met or not. A SAMA answer is per subdomain: at what maturity level do you operate it, and can you show the key performance indicators that prove level 3.

Venvera Saudi NCA ECC dashboard showing the compliance score, control implementation status, implementation by domain and roadmap progress

Where do the ECC and the SAMA CSF set different rules?

On most topics the two point the same way: an independent cyber security function, a committee, risk management, independent audit, incident management and third party controls. The differences are in the detail, and they decide what a dual programme has to meet.

TopicNCA ECC-2:2024SAMA CSF
Saudi nationalsControl 1-2-2: all cybersecurity positions filled with full-time and qualified Saudi professionals3.1.1: the CISO must be Saudi, sufficiently qualified, with SAMA's no objection
Independence1-2-1: a cybersecurity department independent from IT; reporting to the head of the entity is recommended3.1.1: separate reporting lines, budgets and staff evaluations from IT; reports to the CEO, managing director or a control function head
Committee1-2-3: a supervisory committee that includes the head of cybersecurity3.1.1: board mandated, headed by an independent control function manager, meeting at least quarterly
Event logs2-12-3: continuous monitoring; retention of at least 12 months3.3.14: a 24x7 security operations centre and SIEM; no retention period stated
Penetration testing2-11-3: all internet facing services, tested periodically3.2.4: customer and internet facing services, annually
Incidents2-13-3: report incidents to the NCA and share notifications, threat intelligence and incident reports with it3.3.15: inform SAMA IT Risk Supervision immediately of medium or high incidents; no objection before media contact; formal report after recovery
Location4-1-3: managed security operations centres using remote access fully in the Kingdom; data localisation moved to the NDMO3.4.3: SAMA approval before public or hybrid cloud; in principle only cloud services located in Saudi Arabia
Business continuityDomain 3, subdomain 3-1: cybersecurity resilience in business continuityRefers to the separate SAMA Business Continuity Minimum Requirements

Two of these change hiring and sourcing decisions. Under the ECC every cybersecurity role must be held by a qualified Saudi professional, not only the head of the function. And a managed security operations centre that monitors you remotely must be located fully in the Kingdom, while SAMA separately requires its approval before any material outsourcing and before public cloud.

Where the two disagree: the ECC requires Saudi professionals in all cybersecurity positions while SAMA names the CISO, the ECC sets 12 months of log retention while SAMA sets no figure, SAMA requires annual penetration tests while the ECC says periodically, and the ECC requires remote managed SOCs in the Kingdom while SAMA governs cloud location
Venvera SAMA Cyber Security Framework assessment showing overall and target maturity, the four domains and subdomain maturity scoring

What the other results get wrong

Page one for this query is mostly vendor and consultancy pages, and two errors are worth correcting. One says the ECC binds government offices, key infrastructure sites and "many private firms" too. The Scope of Work binds private sector entities only if they own, operate or host Critical National Infrastructure, and encourages everyone else. A private company may still have to implement the ECC because a government or CNI customer writes it into a contract, but that duty comes from the contract. The same page says control 2-12 requires a SIEM tool. The text of 2-12-3 asks for "identification of Security Information and Event Management (SIEM) techniques required for cybersecurity event logs collection", continuous monitoring and 12 months of retention; the SAMA CSF is the one that names a SIEM, under 3.3.14. The difference matters when an auditor asks what the control actually requires.

A third, older error still circulates: describing the ECC with a fifth domain for industrial control systems. That was ECC-1:2018. Appendix C of the 2024 edition records that main domain 5 was deleted and its controls moved to the NCA's separate Operational Technology Cybersecurity Controls.

How do you comply with both?

Keep one evidence base and two indexes. Confirm the ECC scope first, because everything else follows from it. Map each ECC control to the SAMA subdomain it supports, and where a topic appears in both, write your internal standard to the stricter rule: Saudi staffing across the whole function, 12 months of log retention, annual penetration tests, immediate notice to SAMA and reporting to the NCA, and in Kingdom location for remote managed security services. Then score SAMA maturity per subdomain and answer the NCA in its compliance tool, each in the format its regulator asks for. If you also hold ISO 27001, SAMA CSF vs ISO 27001 shows how that certificate fits underneath both.

Running both programmes: confirm ECC scope in writing, map ECC controls to SAMA subdomains, apply the stricter rule where they differ, score SAMA maturity, and answer each regulator in its own format
An illustrative view of ECC and SAMA together: ECC controls mapped to a SAMA subdomain, SAMA subdomains at target maturity, log sources kept 12 months or more, and third party contracts missing ECC clauses

Check your own position

Fill in the middle column. The first row decides whether the rest apply.

QuestionYour answerWhy it matters
Do you own, operate or host Critical National Infrastructure, or are you a government affiliate?If not, the ECC is an encouragement or a contract term, not a mandate.
Are all cybersecurity roles held by full-time qualified Saudi professionals?ECC 1-2-2 covers every position; SAMA 3.1.1 covers the CISO.
Are event logs kept for at least 12 months?ECC 2-12-3 sets the figure; SAMA sets none.
Were internet facing services pen tested in the last year?SAMA 3.2.4 requires annual tests; the ECC says periodically.
Does your incident procedure notify both regulators?SAMA wants medium and high incidents immediately; the ECC requires reporting to the NCA.
Is your managed SOC, if remote, located in the Kingdom?ECC 4-1-3; and SAMA approval for material outsourcing under 3.4.2.
Which edition of the ECC are you assessed against?ECC-2:2024 has 108 main controls in 4 domains; a list with an industrial control systems domain is the 2018 edition.

If most rows are blank, the free compliance check gives you a starting position. Saudi NCA ECC in Venvera tracks controls with owner, status and evidence and scores gaps by domain, and SAMA CSF in Venvera scores the 32 subdomains on the maturity model, so both regulators can be answered from the same evidence. Budgets for each are in Saudi NCA ECC compliance cost and SAMA CSF compliance cost.

The bottom line on NCA ECC vs SAMA CSF: two regulators, one evidence base, and where they differ, meet the stricter rule

Frequently asked questions

Do Saudi banks have to comply with the NCA ECC?

Every bank is under the SAMA CSF. The ECC applies on top only if the bank owns, operates or hosts Critical National Infrastructure or is affiliated with a government agency; otherwise the NCA encourages it. Confirm your position with your regulators.

Does SAMA CSF compliance satisfy the ECC?

No. Neither framework refers to the other, they are assessed by different authorities in different formats, and they differ on several rules, including Saudi staffing, log retention and testing frequency.

How many controls are in each?

ECC-2:2024 has 108 main controls and 92 subcontrols across 4 domains and 28 subdomains. The SAMA CSF has 4 domains and 32 subdomains; its control considerations nest, so published totals differ.

Which one is stricter?

Neither across the board. The ECC is stricter on Saudi staffing and log retention; the SAMA CSF is stricter on testing frequency, incident timing, the committee and approvals for outsourcing and cloud.

Is there a certificate for either?

No. The NCA assesses ECC compliance through self assessment, its compliance tool and field audits; SAMA reviews and audits a self assessment and scores maturity.

Primary sources

ECC provisions are quoted from the Essential Cybersecurity Controls (ECC-2:2024), published by the National Cybersecurity Authority among its regulatory documents: the introduction, the Scope of Work and Applicability, Implementation and Compliance, controls 1-2-1 to 1-2-3, 2-11-3, 2-12-3, 2-13-3, 4-1-3 and subdomain 3-1, and the updates in Appendix C. SAMA provisions are quoted from the SAMA Cyber Security Framework, version 1.0 of May 2017, sections 1.3, 1.4, 2.2 to 2.4 and subdomains 3.1.1, 3.2.4, 3.3.14, 3.3.15, 3.4.2 and 3.4.3, and the level 4 requirement from Circular No. 298140000067. The ECC states that its Arabic version is binding. Confirm the current versions before relying on a reference.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander →

CONTINUE READING