Back to blog
Saudi & GCC

NCA ECC compliance: how to achieve and maintain it

A practical guide to achieving compliance with the NCA Essential Cybersecurity Controls - scoping, self-assessment, evidence, compliance levels and the reporting the National Cybersecurity Authority expects.
GRC Copilot Team
Read in:
NCA ECC compliance: how to achieve and maintain it

NCA ECC compliance means implementing the Essential Cybersecurity Controls issued by Saudi Arabia's National Cybersecurity Authority, evidencing them, and reporting your compliance level. The ECC is a national baseline: it applies across sectors and is assessed on how completely each control is implemented, not merely whether a policy exists.

Who is in scope?

  • Government entities, their companies and subsidiaries
  • Owners and operators of Critical National Infrastructure (CNI)
  • Private-sector organisations that serve or are mandated by in-scope entities

Many organisations outside these categories adopt the ECC voluntarily because customers, partners or regulators expect it.

The four main domains

  1. Cybersecurity Governance - strategy, policies, roles, risk management, awareness and compliance.
  2. Cybersecurity Defense - asset management, identity and access, data protection, network and system hardening, vulnerability and threat management.
  3. Cybersecurity Resilience - cybersecurity built into business continuity so critical services survive disruption.
  4. Third-Party and Cloud Computing Cybersecurity - supplier and cloud provider risk.

How ECC compliance is scored

Each control is assessed by how far it is implemented. In practice organisations report against states such as:

  • Not implemented - no meaningful activity.
  • Partially implemented - some elements in place, gaps remain.
  • Implemented - the control operates as required, with evidence.
  • Not applicable - with documented justification.

The distinction that catches most organisations out is between a documented control and a demonstrated one. A written policy with no configuration, logs or records behind it will not score as implemented.

The path to compliance

  1. Confirm scope and ownership. Identify in-scope entities, systems and assets, and appoint an accountable cybersecurity owner.
  2. Inventory your assets. Almost every other control depends on knowing what you have.
  3. Run a self-assessment against every control, scoring honestly.
  4. Prioritise by risk rather than working through the controls in numerical order.
  5. Implement and evidence. Collect policies, configurations, logs and records as you go.
  6. Report your compliance level to the NCA as required.
  7. Monitor continuously and reassess as systems and controls change.

Score every ECC control automatically

GRC Copilot assesses your organisation against all four ECC domains, links each control to real evidence, and keeps your compliance level current between reporting cycles.

Evidence the assessors look for

  • Approved, dated and communicated policies - not drafts.
  • An asset register that matches reality.
  • Access review records showing who approved what, and when.
  • Vulnerability scan output and proof of remediation.
  • Backup restoration tests, not just backup job logs.
  • Incident records with timelines and lessons learned.
  • Third-party contracts containing cybersecurity clauses.

Frequently asked questions

Is NCA ECC compliance mandatory?

Yes, for in-scope organisations - government entities, CNI operators, and organisations mandated through them. Others adopt it voluntarily or through contractual obligation.

What is the difference between ECC-1:2018 and ECC-2:2024?

ECC-2:2024 updates the original controls for current threats, cloud adoption, third-party risk and resilience. If you already comply with the 2018 version, treat the update as a delta exercise rather than starting again.

Can ISO 27001 evidence be reused for the ECC?

Yes. The frameworks overlap substantially in governance, access control, asset management and incident response. Map your controls once and reuse the evidence across both.

How often should we reassess?

Continuously in practice, with formal self-assessment and reporting on the cycle the NCA requires. Compliance drifts as systems change, so annual-only assessment tends to understate risk.

Key takeaways

  • The ECC is a national cybersecurity baseline organised into four main domains.
  • Controls are scored on implementation, and evidence is what proves it.
  • Third-party and cloud controls are frequently the weakest area.
  • Reuse ECC evidence across ISO 27001, SAMA CSF and NIST to avoid duplicated effort.
#nca #ecc #saudi-arabia #compliance #cybersecurity