Skip to content
AuditGRC

NCA Essential Cybersecurity Controls (ECC-2:2024)

National Cybersecurity Authority · Saudi Arabia · Updated July 30, 2026

The Essential Cybersecurity Controls are the minimum cybersecurity requirements for national entities in Saudi Arabia, issued by the National Cybersecurity Authority. They are structured around four pillars — strategy, people, process and technology — and aim at the confidentiality, integrity and availability of entities’ information and technology assets.

The current edition, ECC-2:2024, replaced ECC-1:2018 in October 2024. The consolidation reduced the control count and merged overlapping requirements; it did not relax them. Several areas moved out of the ECC entirely because another national authority now owns them.

Structure at a glance

Main domains
4
Subdomains
28
Main controls
108
Subcontrols
92
Current version
ECC-2:2024 (replaced ECC-1:2018)

Structure verified against the NCA's published ECC-2:2024 document (classification Public, TLP White).

Who is in scope

  • Government agencies in Saudi Arabia, including ministries, authorities and establishments
  • Their affiliated companies and entities, inside and outside the Kingdom
  • Private sector entities owning, operating or hosting Critical National Infrastructure
  • All other entities in the Kingdom are strongly encouraged to adopt the controls as best practice

How compliance is assessed

The NCA evaluates compliance through entity self-assessment, periodic reports from its compliance tool, and field audit visits. It issues its own ECC-2:2024 Assessment and Compliance Tool as the authoritative instrument.

Go deeper on NCA ECC

Other frameworks