NCA ECC-2:2024 vs ECC-1:2018 — what actually changed
Published 31 July 2026
In October 2024 the National Cybersecurity Authority replaced ECC-1:2018 with ECC-2:2024. Most published summaries stop at the headline: fewer controls, tidier structure. That is not much use if you are the person who has to re-baseline an existing ECC-1 programme and explain to an auditor which requirements moved.
This page works through the substantive changes at control and subcontrol level. Everything below is taken from the change log published in the back of the NCA’s own ECC-2:2024 document (classified Public, TLP White), not from secondary summaries — several of which are still circulating ECC-1 control counts on pages dated 2026.
The structure, precisely
ECC-2:2024 comprises 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols. Those four figures are stated directly in the document’s introduction. The four domains are Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience, and Third-Party and Cloud Computing Cybersecurity.
Commonly cited figures for the superseded ECC-1:2018 are 5 domains, 29 subdomains and 114 main controls. If a vendor’s 2026-dated page tells you their platform ships “all 114 ECC controls”, they are describing the framework you are migrating away from.
The consolidation was rationalisation rather than relaxation: overlapping requirements were merged, and several areas were moved out of the ECC entirely because another national authority now owns them (see data privacy, below).
Changes that create new work
These are the ones that add something you probably do not already have evidenced.
Email authentication now goes beyond SPF (subcontrol 2-4-3-5). ECC-1 required validation of the entity’s email service domains, giving SPF as the example. ECC-2 names three mechanisms explicitly: SPF, DKIM and DMARC. If your ECC-1 evidence was an SPF record and nothing else, that is now a gap. DMARC in particular takes time to roll out safely, because moving to an enforcing policy without first monitoring reports will break legitimate mail flows.
DDoS protection is a new subcontrol (2-5-3-9). This did not exist in ECC-1. It requires protection against distributed denial-of-service attacks to limit the risks arising from them, and the NCA’s stated rationale is straightforward cybersecurity enhancement. For most entities this means either an upstream scrubbing service or a CDN-level protection tier, plus evidence that it is actually enabled on the services that matter.
Multi-factor authentication now requires an impact assessment (subcontrols 2-2-3-2 and 2-4-3-2). ECC-1 asked for MFA on remote access, and on remote and webmail access to email. ECC-2 asks you to define which authentication factors, how many, and which techniques — based on the result of an impact assessment of authentication failure and bypass. It also extends the requirement explicitly to privileged accounts. In practice: “we enabled MFA” is no longer sufficient evidence; you need the reasoning behind the factor choice written down.
Cryptography must follow the National Cryptographic Standards (control 2-8-3). ECC-1 required approved cryptographic solutions, key management and encryption at rest and in transit, defined largely by the entity. ECC-2 points at the National Cryptographic Standards published by the NCA and requires the appropriate standard level to be selected based on data sensitivity, the systems and networks being protected, and your own risk assessment. This is a meaningful change of reference point: the yardstick is now national, not internal.
Changes that reduce or move work
Data classification and privacy controls were removed (control 2-7-3). ECC-1 carried requirements for data and information ownership, classification and labelling mechanisms, and data privacy. These are deleted from ECC-2. The NCA’s stated rationale is that entities must refer to the National Data Management Office at the Saudi Data and Artificial Intelligence Authority regarding data privacy. The definition of “Privacy” was removed from the terminology section for the same reason.
Read that carefully before you decommission anything: the requirement has not disappeared from your obligations, it has moved to a different authority. What changes is which framework you evidence it under.
Data protection is now classification-driven (control 2-7-2). ECC-1 required that cybersecurity requirements for protecting and handling data be implemented. ECC-2 requires that they be implemented based on the classification level of the data. This is a tightening in principle and a simplification in practice — it lets you apply proportionate controls rather than a uniform baseline.
Compliance with national law was deleted as a control (1-7-1). ECC-1 required entities to comply with related national cybersecurity laws and regulations. The NCA removed it, citing cybersecurity regulatory maturity and supporting entities’ compliance. You are obviously still bound by the law; it is simply no longer assessed as an ECC control.
International agreements became conditional (control 1-7-2). ECC-1 required compliance with any nationally-approved international agreements and commitments related to cybersecurity. ECC-2 phrases this conditionally: if such agreements or commitments exist that include cybersecurity requirements, the entity shall identify and comply with them. For entities with no such commitments, this stops being an open-ended obligation.
Terminology changes worth knowing
Several definitions were clarified in ways that affect how controls are read. Username-and-password authentication is now named “single-factor authentication” rather than “user authentication” (subcontrol 2-2-3-1) — a wording change that makes the MFA controls above read more sharply. The definitions of Event, Incident, Threat and Cyber Attack were all simplified. The Critical National Infrastructure definition was clarified around integrity and national-level economic and social impact.
What to do with this
If you have an existing ECC-1 baseline, a practical re-baselining sequence:
- Re-map, do not re-start. The great majority of ECC-1 controls survive into ECC-2. Identify the deltas above rather than reassessing from zero.
- Open the four new-work items — DMARC/DKIM, DDoS protection, the MFA impact assessment, and the National Cryptographic Standards alignment — as remediation items with owners and dates. These are the ones that need procurement or engineering time, not documentation time.
- Re-file, do not delete, your data privacy evidence. It now sits under the NDMO’s remit rather than the ECC’s.
- Check your tooling’s control library version. A platform still shipping the ECC-1 library will show you a clean baseline against the wrong framework. Ask the vendor directly which version their content is on and when it was updated.
You can work through your current position across all 28 subdomains with our free NCA ECC self-assessment, which is built on the ECC-2:2024 structure. For platforms that maintain ECC control libraries and evidence continuously, see our guide to NCA ECC compliance software and the compliance software comparison.
Source
National Cybersecurity Authority, Essential Cybersecurity Controls (ECC-2:2024), document classification Public, TLP White. Structural figures are from the document’s introduction; the changes above are from its version change log. This page summarises those changes in plain English — for compliance purposes, always work from the official document.
Part of our NCA ECC framework hub, which covers the structure, scope and assessment mechanism alongside every resource we publish on it.