Skip to main content
All answers

What is NCA ECC?

NCA ECC (Essential Cybersecurity Controls) is the Saudi Arabian National Cybersecurity Authority's framework for government, critical national infrastructure, and many private-sector organizations. The current edition, ECC-2:2024, replaced ECC-1:2018 in October 2024 and organizes 108 main controls across four domains and 28 subdomains. Compliance is mandatory for in-scope entities. CIS benchmarks satisfy the technical configuration controls within ECC; process-only controls require organizational evidence.

The longer answer.

The Essential Cybersecurity Controls were issued by Saudi Arabia's National Cybersecurity Authority to establish a mandatory minimum bar for the kingdom's most important organizations. Rather than being aspirational guidance, the ECC is enforceable for in-scope entities, and its structure spans cybersecurity governance, defense, resilience, and third-party and cloud computing cybersecurity, reflecting a national interest in protecting both government functions and critical infrastructure.

Within that structure the controls split roughly into two kinds. Technical configuration requirements, such as hardening systems, enforcing access control, and logging, can be evidenced by scanning infrastructure against a recognized benchmark. Governance and process controls, like appointing responsibilities or maintaining policies, need organizational documentation instead. A configuration scanner therefore addresses the automatable slice of the ECC and leaves the procedural controls to be evidenced separately.

More questions on Frameworks?

Our compliance engineers can show you exactly how CISGuard handles Frameworks in a briefing scoped to your environment.