Back to blog
Checklists

NCA ECC checklist: what to have ready for self-assessment

A practical checklist for the Essential Cybersecurity Controls, organised by the four main domains - with the evidence that turns a "partially implemented" score into "implemented".
GRC Copilot Team
Read in:
NCA ECC checklist: what to have ready for self-assessment

ECC scoring turns on one distinction: a control that is documented versus one that is demonstrated. This checklist follows the four main domains and, for each area, names the artefact that moves you from "partially implemented" to "implemented".

Before you assess anything

  • Confirm scope - which entities, systems and assets are covered.
  • Appoint an accountable cybersecurity owner with authority.
  • Build the asset inventory. Almost every other control depends on it, and assessors check it early.
  • Identify which controls are genuinely not applicable, and write the justification now rather than later.

Domain 1 - Cybersecurity Governance

  • Cybersecurity strategy aligned to organisational objectives, approved.
  • Policy set approved, dated and communicated - evidence of communication, not just the document.
  • Defined roles and responsibilities, with a named cybersecurity function.
  • Risk management methodology plus a populated risk register with owners.
  • Cybersecurity in project management and change processes.
  • Awareness programme with completion records, including new joiners.
  • Periodic compliance review and reporting to management, minuted.

Domain 2 - Cybersecurity Defense

  • Asset register that matches reality, with owners and classification.
  • Identity and access management - unique accounts, MFA, privileged access controls, and access review records showing approver and date.
  • Joiner-mover-leaver process with evidence of timely deactivation.
  • Data protection - classification applied, encryption in transit and at rest, handling rules.
  • Secure configuration and hardening baselines, with evidence of application.
  • Patch and vulnerability management - scan output plus proof of remediation, not just scan reports.
  • Malware protection, email and web security.
  • Network security, segmentation and secure remote access.
  • Logging and monitoring, with evidence that events are reviewed.
  • Backup with restoration test records.
  • Penetration testing on critical systems, with remediation tracked.
  • Incident management - register, sampled records with timelines, lessons learned.

Score every ECC control with evidence attached

GRC Copilot assesses you across all four ECC domains, links each control to real evidence, and keeps your compliance level current between reporting cycles.

Domain 3 - Cybersecurity Resilience

  • Business impact analysis identifying critical services, with RTO and RPO agreed by the business.
  • Cybersecurity requirements embedded in business continuity plans.
  • Disaster recovery procedures for critical systems.
  • Exercise records - date, participants, scenario, what failed and what changed. An untested plan does not score as implemented.

Domain 4 - Third-Party and Cloud Computing

  • Supplier inventory with criticality tiering.
  • Due diligence records for critical suppliers - reviewed, not merely collected.
  • Cybersecurity clauses in contracts, including incident notification.
  • Cloud services inventory with data classification and hosting locations, including backups and support access paths.
  • Responsibility split documented per cloud service - provider versus tenant.
  • Exit and data return arrangements for critical providers.
  • Periodic reassessment on a defined cadence.
This domain is consistently the weakest in first assessments. If time is short, spend it here and on access reviews - together they account for a large share of partial scores.

The evidence pattern

For every control, ask: what record proves this happened, who produced it, and is it dated within the assessment period? If the answer is "we do it but there is no record", the control is partially implemented at best.

Frequently asked questions

How is the ECC scored?

By implementation status per control - not implemented, partially implemented, implemented, or not applicable with documented justification.

Can we mark controls not applicable?

Yes, with genuine justification. "We do not operate industrial control systems" is defensible; "we have not got to it yet" is not - that is not implemented.

Does ISO 27001 evidence transfer?

Substantially - governance, access control, asset management, incident response and continuity all overlap. Map once and reuse.

How often should we reassess?

Continuously in practice, with formal self-assessment and reporting on the NCA's cycle. Compliance drifts as systems change.

Key takeaways

  • Documented is not demonstrated - evidence decides the score.
  • The asset inventory unblocks most other controls.
  • Third-party and cloud is the weakest domain in first assessments.
  • Backups need restoration tests; plans need exercise records.
#nca-ecc #checklist #saudi-arabia #evidence #self-assessment