
SAMA Cyber Security Framework: What Regulated Entities Must Evidence
The four domains, the six-level maturity model and why “level 3” is about formalisation, not technology — with a practical view of the evidence reviewers expect.
Who the Essential Cybersecurity Controls apply to, how they are structured, the governance requirements that trip organisations up, and a phased route to demonstrable compliance.

The Essential Cybersecurity Controls (ECC) are the minimum cybersecurity requirements set by the National Cybersecurity Authority (NCA), the Kingdom's lead authority for cybersecurity. First published in 2018, the ECC defines the baseline that other NCA frameworks — for cloud, critical systems, data, telework and operational technology — build upon.
The NCA has updated the ECC since its first edition. Before planning a programme, confirm which edition applies and assess against the current published version; control numbering and wording can differ between editions.
The ECC is organised into five main domains:
Many organisations focus on technology and underestimate the governance domain. In practice, assessors look closely at whether cybersecurity is properly established as a function. Expect to demonstrate:
These requirements take time to satisfy — particularly recruitment. Start them early.
Compliance must be demonstrable. For each control, assessors expect evidence that it is:
| Phase | Focus | Typical duration |
|---|---|---|
| 1. Assess | Gap assessment against the current ECC edition, evidence review, prioritised findings | 4–6 weeks |
| 2. Govern | Cybersecurity function, strategy, policies, committee and ownership | 6–10 weeks |
| 3. Remediate | Technical and process controls, prioritised by risk | 3–9 months |
| 4. Evidence | Evidence library mapped to each control | Ongoing |
| 5. Sustain | Periodic self-assessment, monitoring and continuous improvement | Ongoing |
The ECC is the foundation. Depending on your environment, other NCA frameworks may also apply — the Cloud Cybersecurity Controls (CCC), Critical Systems Cybersecurity Controls (CSCC), Data Cybersecurity Controls (DCC), Telework Cybersecurity Controls (TCC) and Operational Technology Cybersecurity Controls (OTCC). A single mapped control framework avoids duplicating effort across them, and across SAMA, PDPL and ISO requirements.
Assessments go smoothly when the organisation can show not just compliance, but a working system for staying compliant.

The four domains, the six-level maturity model and why “level 3” is about formalisation, not technology — with a practical view of the evidence reviewers expect.

The Personal Data Protection Law has been fully enforceable since September 2024. A practical checklist of what controllers must have in place — and evidence.

A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.
Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.
We respond to every enquiry within one business day.