Riyadh | +966‑557400202 | hello@nazztec.com
Compliance & Regulation

NCA ECC Compliance in Saudi Arabia: A Practical Guide for 2026

Who the Essential Cybersecurity Controls apply to, how they are structured, the governance requirements that trip organisations up, and a phased route to demonstrable compliance.

22 September 20269 min readNAZZTEC Editorial Team
NCA ECC Compliance in Saudi Arabia: A Practical Guide for 2026 — cover illustration

Key takeaways

  • The ECC sets the national minimum cybersecurity baseline issued by the National Cybersecurity Authority.
  • It applies to government organisations and to private entities that own, operate or host critical national infrastructure.
  • Governance requirements — an independent cybersecurity function led by Saudi professionals — are as important as technical controls.
  • Always assess against the current published edition; the NCA updates its frameworks.

What the ECC is

The Essential Cybersecurity Controls (ECC) are the minimum cybersecurity requirements set by the National Cybersecurity Authority (NCA), the Kingdom's lead authority for cybersecurity. First published in 2018, the ECC defines the baseline that other NCA frameworks — for cloud, critical systems, data, telework and operational technology — build upon.

The NCA has updated the ECC since its first edition. Before planning a programme, confirm which edition applies and assess against the current published version; control numbering and wording can differ between editions.

Who must comply

  • Government organisations in the Kingdom — ministries, authorities, establishments and others — and the companies and entities they own.
  • Private sector organisations that own, operate or host critical national infrastructure.
  • Other organisations are strongly encouraged to adopt the ECC as good practice, and many customers now ask their suppliers to evidence alignment.

How the controls are structured

The ECC is organised into five main domains:

  • Cybersecurity Governance — strategy, the cybersecurity function, policies, roles, risk management, compliance, human resources and awareness.
  • Cybersecurity Defence — asset management, identity and access, protection of systems, email, networks, mobile devices, data and cryptography, backup, vulnerability management, penetration testing, logging and monitoring, incident management, physical security and web application security.
  • Cybersecurity Resilience — cybersecurity aspects of business continuity.
  • Third-Party and Cloud Computing Cybersecurity — managing supplier and cloud risk.
  • Industrial Control Systems Cybersecurity — for organisations operating OT environments.

The governance requirements that trip organisations up

Many organisations focus on technology and underestimate the governance domain. In practice, assessors look closely at whether cybersecurity is properly established as a function. Expect to demonstrate:

  • A cybersecurity function independent of IT, reporting directly to the head of the organisation or a delegate.
  • That the head of the cybersecurity function and critical cybersecurity roles are filled by full-time, qualified Saudi professionals.
  • An approved cybersecurity strategy, policies and procedures, reviewed periodically.
  • A cybersecurity steering committee with clear authority.
  • Cybersecurity requirements embedded in HR processes and project management.

These requirements take time to satisfy — particularly recruitment. Start them early.

What good evidence looks like

Compliance must be demonstrable. For each control, assessors expect evidence that it is:

  • Documented — in an approved policy, standard or procedure
  • Implemented — configurations, records and screenshots showing it operates
  • Owned — a named responsible person or team
  • Reviewed — periodic review records and follow-up of findings

A phased roadmap

PhaseFocusTypical duration
1. AssessGap assessment against the current ECC edition, evidence review, prioritised findings4–6 weeks
2. GovernCybersecurity function, strategy, policies, committee and ownership6–10 weeks
3. RemediateTechnical and process controls, prioritised by risk3–9 months
4. EvidenceEvidence library mapped to each controlOngoing
5. SustainPeriodic self-assessment, monitoring and continuous improvementOngoing

Common findings

  • Policies approved but not implemented, or implemented but never approved.
  • Incomplete asset inventories, which undermine every downstream control.
  • Privileged access not managed or reviewed.
  • Logging enabled but not monitored.
  • Third-party cybersecurity requirements missing from contracts.
  • Penetration testing performed without tracking remediation to closure.

Beyond the ECC

The ECC is the foundation. Depending on your environment, other NCA frameworks may also apply — the Cloud Cybersecurity Controls (CCC), Critical Systems Cybersecurity Controls (CSCC), Data Cybersecurity Controls (DCC), Telework Cybersecurity Controls (TCC) and Operational Technology Cybersecurity Controls (OTCC). A single mapped control framework avoids duplicating effort across them, and across SAMA, PDPL and ISO requirements.

Preparing for an assessment

  • Nominate a single coordinator who owns the evidence library and assessment timetable.
  • Map each control to an owner, its evidence items and where they are stored.
  • Refresh evidence so that it is recent, dated and clearly linked to the control it supports.
  • Run an internal pre-assessment and close quick wins before the formal review.
  • Prepare a short narrative for any control not fully met, with the remediation plan and target date.
  • Brief control owners so they can explain how their controls operate.

Assessments go smoothly when the organisation can show not just compliance, but a working system for staying compliant.

Frequently asked questions

Is NCA ECC compliance mandatory for private companies?
It is mandatory for private organisations that own, operate or host critical national infrastructure. For others it is recommended, and it is increasingly requested by government and enterprise customers.
How is ECC compliance assessed?
Organisations are expected to assess themselves periodically and report as required by the NCA, and the NCA may assess compliance directly. Evidence must support every claim.
How long does ECC compliance take?
It depends heavily on the starting point. Governance foundations often take two to three months; technical remediation across the full control set commonly takes six to twelve months.
Keep reading

More insights

PDPL Compliance Checklist for Saudi Organisations — cover illustration
Compliance & Regulation

PDPL Compliance Checklist for Saudi Organisations

The Personal Data Protection Law has been fully enforceable since September 2024. A practical checklist of what controllers must have in place — and evidence.

8 September 20269 min read

Talk to the team behind this briefing

Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.

We respond to every enquiry within one business day.