NCA ECC self-assessment (ECC-2:2024)
Rate your implementation across all 28 subdomains of Saudi Arabia's Essential Cybersecurity Controls and get a readiness score per domain, plus an exportable gap list. Runs entirely in your browser — no signup, and nothing is transmitted anywhere.
—
Overall readiness
—
1. Cybersecurity Governance
—
2. Cybersecurity Defense
—
3. Cybersecurity Resilience
—
4. Third-Party and Cloud Computing Cybersecurity
0 of 28 rated · 0 gaps
1. Cybersecurity Governance
- 1-1 Cybersecurity Strategy
- 1-2 Cybersecurity Management
- 1-3 Cybersecurity Policies and Procedures
- 1-4 Cybersecurity Roles and Responsibilities
- 1-5 Cybersecurity Risk Management
- 1-6 Cybersecurity in Information and Technology Project Management
- 1-7 Compliance with Cybersecurity Standards, Laws and Regulations
- 1-8 Periodical Cybersecurity Review and Audit
- 1-9 Cybersecurity in Human Resources
- 1-10 Cybersecurity Awareness and Training Program
2. Cybersecurity Defense
- 2-1 Asset Management
- 2-2 Identity and Access Management
- 2-3 Information Systems and Information Processing Facilities Protection
- 2-4 Email Protection
- 2-5 Network Security Management
- 2-6 Mobile Devices Security
- 2-7 Data and Information Protection
- 2-8 Cryptography
- 2-9 Backup and Recovery Management
- 2-10 Vulnerability Management
- 2-11 Penetration Testing
- 2-12 Cybersecurity Event Logs and Monitoring Management
- 2-13 Cybersecurity Incident and Threat Management
- 2-14 Physical Security
- 2-15 Web Application Security
3. Cybersecurity Resilience
- 3-1 Cybersecurity Resilience Aspects of Business Continuity Management (BCM)
4. Third-Party and Cloud Computing Cybersecurity
- 4-1 Third-Party Cybersecurity
- 4-2 Cloud Computing and Hosting Cybersecurity
About this assessment
The Essential Cybersecurity Controls (ECC-2:2024) are Saudi Arabia's minimum national cybersecurity requirements, issued by the National Cybersecurity Authority. The framework comprises 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols. It applies to government agencies and their affiliates, and to private sector entities owning, operating or hosting Critical National Infrastructure; the NCA encourages all other entities in the Kingdom to adopt it.
This is not an official NCA instrument. The NCA issues its own ECC-2:2024 Assessment and Compliance Tool, which is the authoritative means of measuring and reporting compliance. This page is an independent readiness check to help you find gaps at subdomain level before a formal assessment — the maturity scale used here is ours, not the NCA's. Always work from the official controls document for compliance purposes.
What to do with your results
- Export the gap list and assign an owner and target date to each subdomain scoring below "Implemented"
- Map gaps you already cover under ISO 27001 — the overlap is usually substantial and reduces duplicated work
- Where gaps cluster in one domain, that is usually a resourcing or ownership problem, not a tooling one
For tooling that maintains ECC control libraries and evidence continuously, see our guide to NCA ECC compliance software and the compliance software comparison.