The Essential Cybersecurity Controls issued by Saudi Arabia's National Cybersecurity Authority consist of 4 cybersecurity main domains, 28 cybersecurity subdomains, 108 cybersecurity main controls and 92 cybersecurity subcontrols. Those are the NCA's own figures, stated in the introduction to ECC-2:2024, and they are the first thing to get right, because most published guidance still quotes 114 controls across 5 domains and 29 subdomains. That was ECC-1:2018. It has been superseded.
The difference is not cosmetic. Main domain 5, Industrial Control Systems Cybersecurity, was deleted outright and its controls moved to a separate document, the Operational Technology Cybersecurity Controls. If you are scoping an ECC programme against a control count that still includes ICS, you are scoping against the wrong instrument.
| Fact | Detail |
|---|---|
| Governing document | Essential Cybersecurity Controls (ECC-2:2024), issued by the National Cybersecurity Authority, classified TLP White and published on nca.gov.sa. |
| Structure | 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols. |
| Who it applies to | Government agencies in the Kingdom including ministries, authorities and establishments, and their affiliated companies and entities inside and outside the Kingdom, plus all private sector entities owning, operating or hosting Critical National Infrastructure. |
| Everyone else | The NCA strongly encourages all other entities in the Kingdom to leverage the Controls, which is an encouragement rather than a mandate. |
| Legal basis | Article 10(3) of the NCA's Statute and High Order No. 57231, dated 10/11/1439H. |
| The obligation | Entities within scope shall take all necessary measures to ensure ongoing and continuous compliance. |
| How it is assessed | The NCA evaluates compliance through multiple means, such as self-assessment by the entity, periodic reports of the compliance tool, and field auditing visits. |
| Applicability caveat | Each entity shall comply with all controls applicable to it. Some controls are conditional, for example the cloud computing and hosting controls in subdomain 4-2. |
| Binding language | The Arabic version is the binding language for all matters relating to meaning or interpretation. |
What are the Saudi NCA ECC requirements?
Three things, and the structure of the document tells you how they are assessed.
First, coverage of every applicable control. Each entity shall comply with all controls applicable to it. Applicability varies, and the NCA gives cloud computing as its own worked example: the controls in subdomain 4-2 bind entities currently using or planning to use cloud computing and hosting services. So the question is never whether a domain applies, only whether the technology or activity it governs is present.
Second, continuous compliance rather than a point in time. The Implementation and Compliance section requires entities to take all necessary measures to ensure ongoing and continuous compliance. There is no certificate and no expiry date to work back from, which changes how evidence has to be kept.
Third, evidence you can produce on demand in the NCA's own format. Compliance is evaluated through self-assessment, through periodic reports of the compliance tool the NCA issues for ECC-2:2024, and through field auditing visits, in whichever combination the NCA considers appropriate. Each subdomain in the document states an objective followed by numbered controls, and that numbering is the structure your evidence has to answer to.
What is in each of the four domains?
The 28 subdomains are distributed very unevenly, which is the most useful fact to know before scoping.
1. Cybersecurity Governance: 10 subdomains
1-1 Cybersecurity Strategy, 1-2 Cybersecurity Management, 1-3 Cybersecurity Policies and Procedures, 1-4 Cybersecurity Roles and Responsibilities, 1-5 Cybersecurity Risk Management, 1-6 Cybersecurity in Information and Technology Project Management, 1-7 Compliance with Cybersecurity Standards, Laws and Regulations, 1-8 Periodical Cybersecurity Review and Audit, 1-9 Cybersecurity in Human Resources, and 1-10 Cybersecurity Awareness and Training Program. This domain constrains your organisation chart more than your tooling.
2. Cybersecurity Defense: 15 subdomains
2-1 Asset Management, 2-2 Identity and Access Management, 2-3 Information Systems and Information Processing Facilities Protection, 2-4 Email Protection, 2-5 Network Security Management, 2-6 Mobile Devices Security, 2-7 Data and Information Protection, 2-8 Cryptography, 2-9 Backup and Recovery Management, 2-10 Vulnerability Management, 2-11 Penetration Testing, 2-12 Cybersecurity Event Logs and Monitoring Management, 2-13 Cybersecurity Incident and Threat Management, 2-14 Physical Security, and 2-15 Web Application Security. More than half the framework sits here.
3. Cybersecurity Resilience: 1 subdomain
3-1 Cybersecurity Resilience Aspects of Business Continuity Management. One subdomain, but it is the one that ties your cyber programme to your continuity plan rather than leaving them as separate documents.
4. Third-Party and Cloud Computing Cybersecurity: 2 subdomains
4-1 Third-Party Cybersecurity and 4-2 Cloud Computing and Hosting Cybersecurity. Small in count and disproportionately heavy in practice, because 4-2-3 requires the controls in main domains 1, 2 and 3 and in subdomain 4-1 to be applied to the cloud environment as well, in addition to its own requirements.
What changed in ECC-2:2024?
Appendix C of the document lists the updates against ECC-1:2018. Five of them change scoping decisions rather than wording.
Main domain 5 was deleted. The Industrial Control Systems controls moved to the Operational Technology Cybersecurity Controls, a separate NCA instrument. This is what takes the framework from 5 domains to 4.
Data localisation left the ECC. Sub-control 4-2-3-3 in the previous version required the entity's information hosting and storage to be inside the Kingdom of Saudi Arabia. It was deleted, and the NCA's stated rationale is that data localisation controls have been transferred to the National Data Management Office at the Saudi Data and Artificial Intelligence Authority. Entities must refer to the NDMO on localisation before taking any action. Guidance that still cites the ECC as the source of a Saudi data residency rule is citing a deleted sub-control.
The Saudi nationals requirement got broader. ECC-1 required the head of the cybersecurity function and related supervisory and critical positions to be filled by full-time experienced Saudi professionals. Control 1-2-2 in ECC-2:2024 reads that all cybersecurity positions shall be filled out with full-time and qualified Saudi cybersecurity professionals.
Scope now follows affiliates abroad. The ECC Scope of Work was modified to cover government agencies and their affiliated companies and entities inside and outside the Kingdom.
Data privacy moved out too. Control 2-7-3, which had required data ownership, classification and privacy requirements, was deleted for the same NDMO reason, and the definition of Privacy was removed from the terms and definitions. Cryptography under 2-8-3 now points at the National Cryptographic Standards published by the NCA, and a new sub-control 2-5-3-9 adds protection against distributed denial of service attacks.
Who must comply with the ECC?
The Scope of Work names three groups and then adds a fourth by encouragement.
Government agencies in the Kingdom, including ministries, authorities, establishments and others. Their affiliated companies and entities, inside and outside the Kingdom, which is the clause that reaches a subsidiary operating in another country. And all private sector entities owning, operating or hosting Critical National Infrastructure. The document refers to these collectively as "the entity".
Everyone else in the Kingdom is strongly encouraged to leverage the Controls to implement best practices. That is not a mandate, and it is worth being precise about the difference. In practice many private companies still implement the ECC because a government or CNI customer requires it contractually, but that obligation comes from the contract rather than from the ECC's own scope.
Which ECC requirements cannot be met by writing a document?
Four, and they set the critical path on most programmes because each one needs a hiring decision, an organisational change or an independent party.
An independent cybersecurity department. Control 1-2-1 requires a cybersecurity department to be established within the entity, independent from the Information Technology and Communications Department, as per High Order No. 37140 dated 14/08/1438H. Reporting directly to the head of the entity or their delegate is recommended rather than required, while avoiding a conflict of interests.
Full-time qualified Saudi professionals. Control 1-2-2 requires all cybersecurity positions to be filled with full-time and qualified Saudi cybersecurity professionals. This is a recruitment constraint on the whole function, not just its head, and it is not compressible by effort or budget.
A cybersecurity supervisory committee. Control 1-2-3 requires a committee established at the instruction of the entity's Authorized Official, with members, responsibilities and a governance framework identified, documented and approved, and it must include the head of the cybersecurity department as a member.
Review and audit by someone else. Control 1-8-1 requires the cybersecurity department to review implementation periodically. Control 1-8-2 then requires the implementation of controls to be reviewed and audited by parties other than the cybersecurity department, conducted independently and considering conflict of interest, as per the Generally Accepted Auditing Standards. Under 1-8-3 the results go to the supervisory committee and the Authorized Official, with scope, observations, recommendations, corrective actions and remediation plans.
What the other results get wrong
Four errors, in the order they cause damage.
Quoting 114 controls across 5 domains and 29 subdomains. That is ECC-1:2018. The current document states 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols in its own introduction. A gap assessment built on the old count will include an entire ICS domain that is no longer part of the ECC and will miscount everything downstream.
Presenting Saudi data localisation as an ECC requirement. Sub-control 4-2-3-3 was deleted in 2024 and the subject was transferred to the National Data Management Office. There may well still be a localisation obligation on you; the ECC is no longer the place to read it.
Describing the ECC as a certification. There is no ECC certificate. The NCA evaluates compliance through self-assessment, periodic reports of its compliance tool and field auditing visits, in whichever combination it considers appropriate.
Treating the ECC as the only NCA control set. It sits alongside the Operational Technology Cybersecurity Controls and other NCA instruments, and the 2024 deletion of domain 5 means operational technology now has to be scoped separately rather than assumed to be covered.
Check your own position, domain by domain
Fill this in. Any row you cannot answer is a scoping question rather than a tooling one.
| Question | Your answer | What it decides |
|---|---|---|
| Are you a government agency, an affiliate of one, or a CNI owner, operator or host? | These are the three mandated groups. Everyone else is encouraged rather than required, unless a contract says otherwise. | |
| Are you assessing against ECC-2:2024 or a 114 control list? | A 114 control list is ECC-1:2018 and still contains the deleted ICS domain. | |
| Do you operate industrial or operational technology? | Those controls left the ECC in 2024 and now sit in the OTCC, which has to be scoped as a separate exercise. | |
| Is your cybersecurity department independent of IT? | Control 1-2-1 requires the separation. Reporting to the head of the entity is recommended, not mandated. | |
| Are all cybersecurity positions filled by full-time qualified Saudi professionals? | Control 1-2-2 applies to every position in the function, and it is usually the longest lead time in the programme. | |
| Who performs the independent review under 1-8-2? | It cannot be the cybersecurity department, and it has to follow Generally Accepted Auditing Standards. | |
| Do you use or plan to use cloud or hosting services? | That turns on subdomain 4-2, which also pulls domains 1, 2, 3 and subdomain 4-1 into the cloud environment. | |
| Where do you now read your data localisation obligation? | Not in the ECC. The NCA transferred it to the NDMO at SDAIA in 2024. |
If most rows are blank, start with a gap assessment rather than a tool selection. A free compliance check gives you a starting position, our Saudi NCA ECC compliance software holds the controls and their evidence in the structure the NCA assesses against, and the NCA ECC software comparison covers what to check before buying anything. If you are also supervised by the central bank, the SAMA CSF requirements run on a separate maturity model and overlap only partly.
Frequently asked questions
How many controls are in the Saudi NCA ECC?
108 main controls and 92 subcontrols, across 4 main domains and 28 subdomains, as stated in the introduction to ECC-2:2024. The figure of 114 controls across 5 domains that appears in most guidance is from ECC-1:2018.
What happened to the industrial control systems domain?
It was deleted. Appendix C records that main domain 5, Industrial Control Systems Cybersecurity, was removed and its controls moved to the Operational Technology Cybersecurity Controls, a separate NCA document.
Does the ECC still require data to be hosted in Saudi Arabia?
Not as an ECC requirement. Sub-control 4-2-3-3, which required hosting and storage inside the Kingdom, was deleted in ECC-2:2024 and the subject transferred to the National Data Management Office at the Saudi Data and Artificial Intelligence Authority. Entities are directed to refer to the NDMO before acting on localisation.
Is the ECC mandatory for private companies?
Only for private sector entities owning, operating or hosting Critical National Infrastructure, and for companies affiliated with government agencies. All other entities in the Kingdom are strongly encouraged to leverage the Controls. Many implement it anyway because a government or CNI customer requires it contractually.
Is there an ECC certificate?
No. The NCA evaluates compliance through means such as self-assessment by the entity, periodic reports of the ECC-2:2024 Assessment and Compliance Tool, and field auditing visits, in accordance with the mechanism it considers appropriate.
Do all cybersecurity staff have to be Saudi nationals?
Control 1-2-2 states that all cybersecurity positions shall be filled out with full-time and qualified Saudi cybersecurity professionals. This was broadened in 2024 from the previous version, which named the head of the function and related supervisory and critical positions.
Primary sources
The structure, scope, applicability, implementation and compliance provisions, subdomain names, the governance controls in 1-2 and 1-8, the cloud controls in 4-2 and the list of updates in Appendix C are taken from the Essential Cybersecurity Controls (ECC-2:2024), published by the National Cybersecurity Authority among its regulatory documents. The document states that the Arabic version is the binding language for all matters relating to its meaning or interpretation, and directs readers to the NCA website for the latest version. Confirm the current text before relying on a control reference.




