Back to blog
Saudi & GCC

NCA ECC vs SAMA CSF: which applies to you, and can one programme cover both?

Saudi financial institutions frequently fall under both the NCA Essential Cybersecurity Controls and the SAMA Cyber Security Framework. How the two differ, where they overlap, and how to run a single programme that satisfies both regulators.
GRC Copilot Team
Read in:
NCA ECC vs SAMA CSF: which applies to you, and can one programme cover both?

The NCA Essential Cybersecurity Controls are Saudi Arabia's national cybersecurity baseline across sectors; the SAMA Cyber Security Framework is the sector-specific standard for institutions regulated by the Saudi Central Bank. Many banks, insurers and finance companies are subject to both - and the most common mistake is running them as two separate programmes.

Who issues them, and to whom

  • NCA ECC - issued by the National Cybersecurity Authority. Applies to government entities, operators of Critical National Infrastructure, and organisations serving or mandated through them. It is a national baseline, not sector-specific.
  • SAMA CSF - issued by the Saudi Central Bank. Applies to its regulated entities: banks, insurance and reinsurance companies, finance companies, credit bureaus and financial market infrastructure.

A bank in the Kingdom will typically answer to SAMA for its framework obligations while also falling within the national ECC expectations. The two are complementary rather than alternatives.

The structural difference that matters most

Both organise controls into four main domains, and the subject matter overlaps heavily. The critical difference is how compliance is scored:

  • NCA ECC assesses implementation - is the control not implemented, partially implemented, implemented, or not applicable with justification.
  • SAMA CSF assesses maturity on a six-level scale from 0 (non-existent) to 5 (adaptive), with level 3 the usual minimum expectation and higher levels for critical controls.
This is the trap. A control can be fully "implemented" for ECC purposes and still score only maturity level 2 or 3 under SAMA, because SAMA additionally asks whether the control is formalised, measured and reported. Implementation is not maturity.

Domain comparison

  • Governance. ECC: Cybersecurity Governance. SAMA: Cyber Security Leadership and Governance, plus a separate Risk Management and Compliance domain. SAMA places more explicit weight on board involvement and regulatory reporting.
  • Technical defence. ECC: Cybersecurity Defense. SAMA: Cyber Security Operations and Technology. Substantially the same subject matter - asset management, identity, data protection, hardening, vulnerability and incident management.
  • Resilience. ECC has a dedicated Cybersecurity Resilience domain. SAMA addresses continuity within its operations domain.
  • Third parties. Both treat supplier and cloud risk as a distinct domain - and in both, it is consistently the weakest area in first assessments.

One assessment, both regulators

GRC Copilot maps your controls across the NCA ECC and SAMA CSF at once - scoring implementation for one and maturity for the other from the same evidence base.

Running one programme for both

  1. Build a single control library describing what you actually operate, in your own words.
  2. Map both frameworks onto it - most controls will satisfy a requirement in each.
  3. Collect evidence once and attach it to the control, not to a framework requirement.
  4. Score twice - implementation status for the ECC, maturity level for SAMA - from the same underlying facts.
  5. Close the maturity gap deliberately. To move a control from level 3 to level 4 for SAMA, add measurement: define a KPI, report it periodically, and keep the reports.
  6. Report separately in each regulator's expected format and cycle.

Where organisations get caught out

  • Assuming ECC compliance satisfies SAMA. It covers much of the substance but not the maturity bar or the measurement evidence.
  • No metrics. The single most common reason SAMA maturity stalls at level 3.
  • Policies approved but not communicated - enough for a documentation check, not enough for formalisation.
  • Third-party controls treated as procurement paperwork rather than assessed risk.
  • Separate teams, separate spreadsheets - producing contradictory answers to the same question.

Frequently asked questions

If we comply with SAMA CSF, are we ECC compliant?

Largely in substance, but not automatically. Map the ECC controls explicitly and confirm each is evidenced - the ECC has its own control set and reporting expectations.

Which should we tackle first?

Whichever your regulator is actively requesting. In practice, building the control library and evidence base serves both, so the sequencing matters less than avoiding duplicate programmes.

Does ISO 27001 help with either?

Yes, considerably. An ISO 27001 ISMS supplies the governance, risk and evidence discipline both frameworks expect - though neither is satisfied by certification alone.

What does it take to reach SAMA maturity level 4?

Measurement and reporting. Define KPIs for the control, measure them on a defined cycle, report to management, and retain the evidence. Without that, level 3 is the ceiling.

Key takeaways

  • ECC is a national baseline; SAMA CSF is sector-specific for financial institutions.
  • ECC scores implementation; SAMA scores maturity from 0 to 5.
  • Implemented does not equal mature - measurement is what unlocks level 4.
  • One control library and one evidence base can serve both regulators.
#nca-ecc #sama-csf #comparison #saudi-arabia #maturity