The Essential Cybersecurity Controls (ECC) are the Kingdom of Saudi Arabia's baseline for protecting the information and technology assets of national organisations. Published by the National Cybersecurity Authority (NCA), the ECC set the minimum cybersecurity requirements that in-scope organisations are expected to meet - and ECC-2:2024 is the latest revision.
What is the ECC?
The ECC is a cybersecurity framework issued by the NCA. It translates national cybersecurity objectives into concrete, auditable controls covering governance, technical defence, resilience, and the risks introduced by third parties and cloud services. The goal is straightforward: raise the cybersecurity baseline across the Kingdom and reduce the likelihood and impact of cyber incidents.
Who needs to comply?
The ECC applies to a broad set of organisations, including:
- Government entities together with their companies and subsidiaries.
- Organisations that own or operate Critical National Infrastructure (CNI).
- Private-sector organisations that provide services to, or are mandated by, in-scope entities.
Many other organisations adopt the ECC voluntarily, or because a customer or regulator requires it.
How ECC-2:2024 is structured
The controls are organised as a hierarchy of main domains, subdomains and individual controls. ECC-2:2024 is built around four main domains:
- Cybersecurity Governance - strategy, policies, roles and responsibilities, risk management, awareness and compliance.
- Cybersecurity Defense - asset management, identity and access, data protection, network and system hardening, and threat and vulnerability management.
- Cybersecurity Resilience - embedding cybersecurity into business continuity so critical services survive disruption.
- Third-Party and Cloud Computing Cybersecurity - managing the risk that suppliers and cloud providers introduce.
Each domain breaks down into subdomains, and each subdomain into the specific controls an organisation must implement and evidence.
What changed from ECC-1:2018?
ECC-2:2024 refreshes the original 2018 controls to reflect how threats, technology and regulation have evolved, with sharper expectations around cloud adoption, third-party risk and operational resilience. If you already comply with ECC-1:2018, treat the new version as a delta exercise: map your existing controls forward, then close the gaps the update introduces.
The path to compliance
- Confirm scope and ownership. Identify which entities, systems and assets fall under the ECC, and assign a cybersecurity owner.
- Build an asset inventory. You cannot protect what you have not catalogued.
- Run a gap assessment. Score each control as implemented, partially implemented or not implemented.
- Prioritise by risk. Close the highest-risk gaps first rather than working strictly top to bottom.
- Implement controls and collect evidence. Policies, configurations, logs and records are what an assessor checks.
- Self-assess and report. Measure your compliance level and report to the NCA as required.
- Monitor continuously. Compliance is a living state - reassess as your systems and the controls evolve.
The ECC deliberately overlaps with international standards such as ISO/IEC 27001 and NIST. Evidence you gather for one framework can usually be reused for another, so avoid building siloed compliance programmes.
Common pitfalls to avoid
- Treating the ECC as a one-off audit rather than an ongoing programme.
- Documenting policies without implementing or enforcing them.
- Overlooking third-party and cloud controls, which are frequently the weakest link.
- Leaving evidence collection until the assessment is already underway.
Getting started this week
Begin with two artefacts: a clear scope statement and an honest self-assessment of where you stand against each domain. Together they turn "we need to comply with the ECC" into a prioritised roadmap - and an evidence-driven GRC platform can then automate the mapping, evidence collection and reporting as you close the gaps.