Skip to content
AuditGRC

NCA ECC to ISO 27001 mapping — and where the two genuinely diverge

Published 31 July 2026

Most Saudi organisations running the NCA’s Essential Cybersecurity Controls are also certified to, or heading towards, ISO 27001. Maintaining two separate control libraries for overlapping requirements is the largest avoidable cost in a GCC compliance function.

This page maps ECC-2:2024’s 28 subdomains onto ISO/IEC 27001:2022 Annex A, and — more usefully — sets out where the two frameworks do not line up, because that is where a naive one-to-one mapping quietly loses requirements.

What this is. An editorial mapping produced by AuditGRC for planning purposes, built from the published structure of both frameworks. It is not an official crosswalk; neither the NCA nor ISO publishes one. Use it to scope work and find overlap, then validate against your own control implementations before relying on it as audit evidence.

The two structures

ECC-2:2024 comprises 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols. ISO/IEC 27001:2022 Annex A comprises 93 controls in four themes: Organizational (5.1–5.37), People (6.1–6.8), Physical (7.1–7.14) and Technological (8.1–8.34).

The shapes differ in a way that matters. ISO 27001 is a management system standard: Annex A is only the control set, while clauses 4–10 define the ISMS itself — context, leadership, planning, support, operation, performance evaluation and improvement. The ECC has no equivalent management-system layer. It specifies controls, not the system that governs them.

Domain 1 — Cybersecurity Governance

ECC subdomainClosest ISO 27001:2022 equivalents
1-1 Cybersecurity StrategyClauses 4.1–4.2, 5.2; A.5.1
1-2 Cybersecurity ManagementClause 5; A.5.2
1-3 Cybersecurity Policies and ProceduresA.5.1, A.5.37
1-4 Cybersecurity Roles and ResponsibilitiesA.5.2, A.5.3, A.5.4
1-5 Cybersecurity Risk ManagementClauses 6.1, 8.2, 8.3
1-6 Cybersecurity in Information and Technology Project ManagementA.5.8, A.8.25
1-7 Compliance with Cybersecurity Standards, Laws and RegulationsA.5.31, A.5.32, A.5.34
1-8 Periodical Cybersecurity Review and AuditClause 9.2; A.5.35, A.5.36
1-9 Cybersecurity in Human ResourcesA.6.1–A.6.6
1-10 Cybersecurity Awareness and Training ProgramA.6.3

Note how much of this domain maps to ISO clauses rather than Annex A controls. If you scope your mapping to Annex A alone — which is what most control libraries do — governance coverage will look thinner than it actually is.

Domain 2 — Cybersecurity Defense

ECC subdomainClosest ISO 27001:2022 equivalents
2-1 Asset ManagementA.5.9, A.5.10, A.5.11, A.5.12, A.5.13
2-2 Identity and Access ManagementA.5.15–A.5.18, A.8.2, A.8.3, A.8.5
2-3 Information Systems and Processing Facilities ProtectionA.8.1, A.8.7, A.8.19, A.8.31
2-4 Email ProtectionA.5.14, A.8.7, A.8.20, A.8.23
2-5 Network Security ManagementA.8.20, A.8.21, A.8.22, A.8.23
2-6 Mobile Devices SecurityA.8.1, A.6.7, A.7.9
2-7 Data and Information ProtectionA.5.12, A.5.13, A.5.33, A.5.34, A.8.10–A.8.12
2-8 CryptographyA.8.24
2-9 Backup and Recovery ManagementA.8.13, A.8.14
2-10 Vulnerability ManagementA.8.8, A.8.9
2-11 Penetration TestingA.8.8, A.8.29
2-12 Cybersecurity Event Logs and Monitoring ManagementA.8.15, A.8.16, A.8.17
2-13 Cybersecurity Incident and Threat ManagementA.5.7, A.5.24–A.5.28
2-14 Physical SecurityA.7.1–A.7.14
2-15 Web Application SecurityA.8.25–A.8.29

Domains 3 and 4 — Resilience, Third-Party and Cloud

ECC subdomainClosest ISO 27001:2022 equivalents
3-1 Cybersecurity Resilience Aspects of BCMA.5.29, A.5.30, A.8.14
4-1 Third-Party CybersecurityA.5.19, A.5.20, A.5.21, A.5.22
4-2 Cloud Computing and Hosting CybersecurityA.5.23

Where the mapping breaks down

This is the part a control library will not tell you.

ECC names things ISO folds in. Penetration testing (2-11) and email protection (2-4) are dedicated ECC subdomains with their own control expectations. ISO disperses both across several controls, and treats penetration testing largely as a means of satisfying A.8.8 rather than a requirement in its own right. An ISO-certified organisation can therefore be genuinely compliant with A.8.8 while lacking the discrete, scheduled, scoped penetration testing programme the ECC expects.

ISO expects a management system the ECC does not describe. Clauses 4–10 — scope definition, an ISMS policy, competence and awareness planning, internal audit, management review, nonconformity and continual improvement — have no direct ECC counterpart. Coming from ECC to ISO, this is the bulk of the new work, and it is governance and documentation rather than technical control.

Cryptography now points somewhere else. ECC-2:2024 requires cryptography to follow the National Cryptographic Standards published by the NCA, with the level chosen by data sensitivity. ISO A.8.24 requires rules on the effective use of cryptography but sets no national standard. Satisfying A.8.24 does not satisfy ECC 2-8 unless you are using the NCA’s standards specifically — the mapping is directional, not equivalent. See our ECC-2:2024 change guide for why this changed.

Data privacy has left the ECC. ECC-2:2024 deleted its data classification and privacy controls (2-7-3), directing entities to the National Data Management Office at SDAIA. ISO retains A.5.34 for privacy and PII protection. So an ISO control now maps to an obligation sitting outside the ECC entirely — when you re-baseline, re-file that evidence rather than deleting it.

Email authentication is more specific in ECC. ECC-2:2024 names SPF, DKIM and DMARC at subcontrol level. No ISO Annex A control names them. Mapping ECC 2-4 to A.8.20 and A.5.14 will pass a mapping review and still leave you short at an ECC assessment.

ISO has no maturity model. ISO 27001 is certified or not. The SAMA CSF assesses on a six-level maturity scale, and the ECC on implementation status. If you are in scope for all three, you need one control set with three assessment overlays — not three control sets.

How to use this practically

  1. Build one control set, not three. Implement to the strictest requirement across the frameworks you are in scope for — usually the ECC on technical specifics, ISO on management system, SAMA on demonstrated maturity.
  2. Map evidence, not just controls. The saving comes from one access review satisfying ECC 2-2, ISO A.5.18 and SAMA 3.3.5 at once. That only works if the evidence is filed against all three.
  3. Track the divergences explicitly. The five gaps above are where a single-library approach leaks. Keep them as named exceptions rather than assuming the mapping covers them.
  4. Check your platform’s mapping depth. Vendors advertise “cross-framework mapping” freely. Ask whether it maps at control or subdomain level, which ECC version the content is on, and whether ISO clauses 4–10 are included or only Annex A.

Work through your ECC position with our free NCA ECC self-assessment, or your SAMA maturity with the SAMA CSF assessment. To compare platforms on cross-framework mapping specifically, see the compliance software comparison.

Sources and limitations

Structure of ECC-2:2024 from the National Cybersecurity Authority’s published document (classification Public, TLP White). ISO/IEC 27001:2022 Annex A structure — 93 controls across Organizational, People, Physical and Technological themes — from the published standard’s control numbering. Control text is not reproduced here.

The mapping is AuditGRC’s editorial judgement. It is directional (ECC → ISO), at subdomain rather than individual control level, and makes no claim of completeness in reverse: many ISO controls have no ECC counterpart. Validate against your own implementation before using it as audit evidence.


Part of our NCA ECC framework hub, which covers the structure, scope and assessment mechanism alongside every resource we publish on it.